Login to view this video
On demand catalog
Select a session below to watch.
Keeping score: Deploying OpenSSF Scorecard and GitHub Advanced Security at enterprise scale
Nobody likes getting a bad report card, and as adults in the workplace, not much has changed since our early school days! So, how do we square human nature—and our enthusiasm to adopt the latest technology—with the need to secure open source software and ensure developers thoroughly understand requirements?
Join Lelia Bray-Musso, open source architect from Cisco's Open Source Program Office (OSPO), on her journey through introducing Open SFF Scorecard and GitHub Advanced Security solutions to hundreds of GitHub Enterprise Cloud repositories. She'll discuss tactics for deploying tools that maintainers might not realize they need, and the importance of clear communication when enforcing new policy. By the end of this talk, you'll be proud to hang your security report card on the fridge!
, Open Source Architect, Independent
Session Type: Breakout Session
Key Takeaway 1: Learn the do's and don'ts of deploying new security tools at a broad scale.
Key Takeaway 2: Discover how to strike a balance between technology adoption and clear communication to maximize success.
Key Takeaway 3: Understand the importance of involving your open source community when developing new policy.
Topic: DevSecOps, Open Source, Security, Supply Chain Security, Software Engineering, Vulnerability Detection, Collaboration
Target Audience: Enterprise - Engineering Leadership, Open Source Developers or Maintainers, Security Professionals, Security Leadership
Industry: Computers & Electronics, Software & Internet, Telecommunications
Level: Level 200: Intermediate
GitHub Product: Actions, Advanced Security, Supply Chain Security, Enterprise/Admin
Delivery Format: In-person, Recorded, On-demand