Loading…
September 13-16, 2022
Dublin, Ireland + Virtual
View More Details & Registration
Note: The schedule is subject to change.

The Sched app allows you to build your schedule but is not a substitute for your event registration. You must be registered for Open Source Summit Europe 2022 to participate in the sessions. If you have not registered but would like to join us, please go to the event registration page to purchase a registration.

This schedule is automatically displayed in Irish Standard Time (UTC +1). To see the schedule in your preferred timezone, please select from the drop-down menu to the right, above "Filter by Date."

IMPORTANT NOTE: Timing of sessions and room locations are subject to change.

Tuesday, September 13 • 09:55 - 10:35
Improving Package Repository Security – From White Papers to Practice - Jussi Kukkonen, Google

Sign up or log in to save this to your schedule, view media, leave feedback and see who's attending!

Feedback form is now closed.
Community package repositories (like PyPI or NPM) struggle to keep up with modern security demands. In this talk Jussi will cover how the repositories - and the security expectations - have changed over time. He is going to focus on the obstacles: what is preventing faster integration of modern security practices? Are community repositories more problematic than software projects in general? Some practical examples will be covered, most importantly PyPIs goal of integrating The Update Framework (TUF) into their workflows: why has even a more minimal integration taken so long and what is preventing PyPI from leveraging TUF fully, when the potential advantages seem so obvious? Finally a collaboration project, Repository Playground, is proposed: A way for the various community repository projects and the independent security projects, such as the TUF community or the SLSA community, to work together to define Best Practices and workflows in a way that goes further than white papers. https://github.com/jku/repository-playground

Speakers
avatar for Jussi Kukkonen

Jussi Kukkonen

Open Source Software Engineer, Google
Jussi is an experienced developer with a long Open Source background and an interest on build automation and supply chain security. He currently works on various upstream projects related to software supply chain security and is a maintainer of Python-TUF, the reference implementation... Read More →



Tuesday September 13, 2022 09:55 - 10:35 IST
Liffey B Part 2 (Level 1)