Class Central is learner-supported. When you buy through links on our site, we may earn an affiliate commission.

YouTube

ONAP's Recipe for Managing CVEs and Securing Open Source Software

LF Networking via YouTube

Overview

Save Big on Coursera Plus. 7,000+ courses at $160 off. Limited Time Only!
Learn about ONAP's successful vulnerability management strategy in this conference talk that explores how the Open Network Automation Platform became the leading LFN Project for fixing vulnerabilities. Discover the comprehensive CVE process integration implemented to reduce supply chain vulnerabilities, including the community's systematic approach to upgrading packages in each release. Explore how the security subcommittee developed an effective process over ten releases, incorporating software composition analysis in build pipelines and detailed package upgrade tasks. Gain insights into the project's successful response to the log4j zero-day vulnerability and their ongoing efforts to improve code quality. Understand practical strategies for automating package upgrade analysis, simplifying complex upgrade recommendations, and collaborating with vendors and other Linux Foundation projects on vulnerability management. Follow the journey from initial security decisions to current automated processes, learning valuable lessons for managing open source software security at scale.

Syllabus

Introduction
Agenda
What is ONAP
How ONAP manages dependencies
Log4J vulnerability
Whats next
Message to projects

Taught by

LF Networking

Reviews

Start your review of ONAP's Recipe for Managing CVEs and Securing Open Source Software

Never Stop Learning.

Get personalized course recommendations, track subjects and courses with reminders, and more.

Someone learning on their laptop while sitting on the floor.