Skip to Main Content
Talk Beginner Apache-2.0 (software), CC BY-SA 4.0 (open data), CC BY-SA 4.0 (presentation)

A plan to sort out this CVE mess

Proposal status is Approved
Session Description

Be it in India, Europe or the US, vulnerability management for open source packages is an imperative. And right when we need it most, the CVE ecosystem is falling apart, a problem made ever more critical with AI-mediated attacks on the open source software supply chain. Let’s look at the problems, the solutions elements and walk through a concrete plan towards making vulnerability management a straight forward process because we feed it with correct, open, current, quality data about open source package security bugs, and their fixes, beyond CVE.

Key Takeaways

The CERT-in, the EU Cyber Resilience Act, and similar regulation across the world are emerging and making vulnerability management a mandatory practice, with key processing deadlines (like within 24h). These processes are only possible with correct, current data about which of the thousand packages used in a software product may be vulnerable, and if this vulnerability is reachable or exploitable. The traditional CVE ecosystem is falling apart and no longer able to solely provide the much needed data input. The takeaway is an understanding of the vulnerability data landscape, its strengths and weaknesses and a plan on how to help fix the data problem, the open source way, together with an overview of existing FOSS tools that will benefit from this initiative.

References

Session Categories

Community
Story of a FOSS project - from inception to growth
Knowledge Commons (Open Hardware, Open Science, Open Data etc.)
Talk License: Apache-2.0 (software), CC BY-SA 4.0 (open data), CC BY-SA 4.0 (presentation)

Which track are you applying for?

Security

Speakers

Philippe Ombredanne AboutCode maintainer | AboutCode

AboutCode Foundation - ScanCode - Package-URL - ClearlyDefined

Philippe Ombredanne is a FOSS hacker on a mission to enable easier and safer reuse of healthy open source code. He is the lead maintainer of the AboutCode stack of open source tools for Software Composition Analysis, license and security compliance, including the industry-leading ScanCode, DejaCode, PurlDB, VulnerableCode, and ClearlyDefined. Philippe is leading the Package-URL (PURL) global standard for package identification in the software supply chains in SBOMs, VEX, and vulnerabilities (ECMA-427), co-founded SPDX and ClearlyDefined, and is a core contributor to CycloneDX. Philippe contributes to other open source projects, including the Linux kernel SPDX-ification, nix, Apache, Rust, strace, ORT, and several Python tools.

Philippe Ombredanne
https://linkedin.com/ pombredanne