Class Central is learner-supported. When you buy through links on our site, we may earn an affiliate commission.

YouTube

Eclipse Foundation Security Training - How We Manage Vulnerability Reports

Eclipse Foundation via YouTube

Overview

Coursera Flash Sale
40% Off Coursera Plus for 3 Months!
Grab it
Learn the comprehensive vulnerability management process used by the Eclipse Foundation in this 27-minute security training session. Discover the step-by-step procedures for reporting security vulnerabilities, understand how the security team collaborates with project maintainers, and explore the tools utilized across GitHub and GitLab platforms. Master private issue management and disclosure best practices, including the use of GitHub Private Advisories for reporting and maintaining visibility. Examine how the foundation handles end-of-life versions and unsupported releases, while understanding the support mechanisms provided by the security team to projects. Gain insights into CVSS scoring methodologies and severity determination processes, including the distinction between business impact and technical scores. Participate in interactive quizzes and live Q&A sessions to reinforce your understanding of vulnerability coordination practices. Access practical knowledge about mailing lists, process improvements, and available resources to enhance your security management capabilities within the Eclipse ecosystem.

Syllabus

00:00 Introduction & Format
00:48 Vulnerability Reporting at Eclipse Foundation
03:10 Process for Handling Reports GitLab & GitHub
06:05 Private Issue Management & Disclosure Best Practices
09:41 GitHub Private Advisories: Reporting & Visibility
11:02 Mailing Lists and Process Improvements
12:07 Handling End-of-Life Versions and Unsupported Releases
13:04 How the Security Team Supports Projects
14:05 Quiz & Live Questions
17:05 CVSS Scoring and Severity Determination
19:01 Business Impact vs. Technical Scores
22:17 Quiz Results & Recap
24:00 Resources, Badge Survey & Final Reminders

Taught by

Eclipse Foundation

Reviews

Start your review of Eclipse Foundation Security Training - How We Manage Vulnerability Reports

Never Stop Learning.

Get personalized course recommendations, track subjects and courses with reminders, and more.

Someone learning on their laptop while sitting on the floor.