Master Production-Ready Machine Learning, Step by Step
You’re only 3 weeks away from a new language
Overview
AI, Data Science & Cloud Certificates from Google, IBM & Meta — 40% Off
One plan covers every Professional Certificate on Coursera. 40% off Coursera Plus Annual.
Unlock All Certificates
Explore comprehensive open source software security beyond traditional vulnerability scanning in this conference talk that examines the hidden risks lurking beneath zero-CVE container images. Discover how open source projects can pose threats through improper governance structures vulnerable to hostile takeovers, malicious licensing containing legal pitfalls, end-of-life status with no maintenance path, poor documentation requiring code reading for understanding, inadequate testing creating scalability bugs, and insecure release processes exposing supply chains. Learn about emerging tools and methodologies from CNCF projects and Linux Foundation initiatives that leverage OpenSSF's Security Scorecards, SLSA framework, Security Baseline standards, and updated 2025 TAG Security guidance on supply chain security to surface critical metadata enabling safer open source adoption decisions. Understand how to move beyond paralyzing uncertainty when evaluating open source components by utilizing new generation tools that provide transparency around trust, maintainability, and comprehensive security posture assessment.
Syllabus
Safely Sourcing OSS - Beyond 0 CVEs - John Kjell, ControlPlane
Taught by
CNCF [Cloud Native Computing Foundation]