Artwork

内容由The New Stack Podcast and The New Stack提供。所有播客内容(包括剧集、图形和播客描述)均由 The New Stack Podcast and The New Stack 或其播客平台合作伙伴直接上传和提供。如果您认为有人在未经您许可的情况下使用您的受版权保护的作品,您可以按照此处概述的流程进行操作https://zh.player.fm/legal
Player FM -播客应用
使用Player FM应用程序离线!

Are We Thinking About Supply Chain Security All Wrong?

43:48
 
分享
 

Manage episode 443373425 series 75006
内容由The New Stack Podcast and The New Stack提供。所有播客内容(包括剧集、图形和播客描述)均由 The New Stack Podcast and The New Stack 或其播客平台合作伙伴直接上传和提供。如果您认为有人在未经您许可的情况下使用您的受版权保护的作品,您可以按照此处概述的流程进行操作https://zh.player.fm/legal

In a New Stack Makers episode, Ashley Williams, founder and CEO of axo, highlights how the software world depends on open-source code, which is largely maintained by unpaid volunteers. She likens this to a CVS relying on volunteer-run shipping companies, pointing out how unsettling that might be for customers. The conversation focuses on open-source maintainers’ reluctance to be seen as "suppliers" of software, an idea explored in a 2022 blog post by Thomas Depierre. Many maintainers reject the label, as there is no contractual obligation to support the software they provide.

Williams critiques the industry's response to this, noting that instead of involving maintainers in software supply chain security, companies have relied on third-party vendors. However, these vendors have no relationship with the maintainers, leading to increased vulnerabilities. Williams advocates for better engagement with maintainers, especially at build time, to improve security. She also reflects on the growing pressures on maintainers and the underappreciation of release teams.

Learn more from The New Stack about open source software supply chain

2023: The Year Open Source Security Supply Chain Grew Up

Fortifying the Software Supply Chain

The Challenges of Securing the Open Source Supply Chain

Join our community of newsletter subscribers to stay on top of the news and at the top of your game.

  continue reading

872集单集

Artwork
icon分享
 
Manage episode 443373425 series 75006
内容由The New Stack Podcast and The New Stack提供。所有播客内容(包括剧集、图形和播客描述)均由 The New Stack Podcast and The New Stack 或其播客平台合作伙伴直接上传和提供。如果您认为有人在未经您许可的情况下使用您的受版权保护的作品,您可以按照此处概述的流程进行操作https://zh.player.fm/legal

In a New Stack Makers episode, Ashley Williams, founder and CEO of axo, highlights how the software world depends on open-source code, which is largely maintained by unpaid volunteers. She likens this to a CVS relying on volunteer-run shipping companies, pointing out how unsettling that might be for customers. The conversation focuses on open-source maintainers’ reluctance to be seen as "suppliers" of software, an idea explored in a 2022 blog post by Thomas Depierre. Many maintainers reject the label, as there is no contractual obligation to support the software they provide.

Williams critiques the industry's response to this, noting that instead of involving maintainers in software supply chain security, companies have relied on third-party vendors. However, these vendors have no relationship with the maintainers, leading to increased vulnerabilities. Williams advocates for better engagement with maintainers, especially at build time, to improve security. She also reflects on the growing pressures on maintainers and the underappreciation of release teams.

Learn more from The New Stack about open source software supply chain

2023: The Year Open Source Security Supply Chain Grew Up

Fortifying the Software Supply Chain

The Challenges of Securing the Open Source Supply Chain

Join our community of newsletter subscribers to stay on top of the news and at the top of your game.

  continue reading

872集单集

所有剧集

×
 
Loading …

欢迎使用Player FM

Player FM正在网上搜索高质量的播客,以便您现在享受。它是最好的播客应用程序,适用于安卓、iPhone和网络。注册以跨设备同步订阅。

 

快速参考指南