Learn Excel and Financial Modeling the Way Finance Teams Actually Use Them
You’re only 3 weeks away from a new language
Overview
Google, IBM & Meta Certificates – 40% Off
One Coursera Plus subscription covers most Professional Certificates on Coursera.
Unlock All Certificates
Explore common misconceptions about open source security in this 12-minute conference talk that challenges fundamental assumptions developers hold about package management and vulnerability tracking. Debunk myths surrounding immutable tags, dependency graphs, and lock files while gaining practical insights into real-world security challenges. Learn why package URLs (purls) can map to multiple different packages and discover the complexities of maintaining consistency across different ecosystem names and identifiers. Understand how a single package can generate multiple dependency graphs depending on build flags and operating systems, making vulnerability reporting more complex than commonly believed. Examine the fundamental principles of open source security by questioning widely-accepted assumptions to develop a more coherent understanding of the open source ecosystem's security landscape.
Syllabus
Myths Developers Believe About Open Source Security - Jess Lowe & Tim Zhang, Google
Taught by
OpenSSF