Class Central is learner-supported. When you buy through links on our site, we may earn an affiliate commission.

CNCF [Cloud Native Computing Foundation]

Safely Sourcing OSS - Beyond 0 CVEs

CNCF [Cloud Native Computing Foundation] via YouTube

Overview

Coursera Spring Sale
40% Off Coursera Plus Annual!
Grab it
Explore comprehensive open source software security beyond traditional vulnerability scanning in this conference talk that examines the hidden risks lurking beneath zero-CVE container images. Discover how open source projects can pose threats through improper governance structures vulnerable to hostile takeovers, malicious licensing containing legal pitfalls, end-of-life status with no maintenance path, poor documentation requiring code reading for understanding, inadequate testing creating scalability bugs, and insecure release processes exposing supply chains. Learn about emerging tools and methodologies from CNCF projects and Linux Foundation initiatives that leverage OpenSSF's Security Scorecards, SLSA framework, Security Baseline standards, and updated 2025 TAG Security guidance on supply chain security to surface critical metadata enabling safer open source adoption decisions. Understand how to move beyond paralyzing uncertainty when evaluating open source components by utilizing new generation tools that provide transparency around trust, maintainability, and comprehensive security posture assessment.

Syllabus

Safely Sourcing OSS - Beyond 0 CVEs - John Kjell, ControlPlane

Taught by

CNCF [Cloud Native Computing Foundation]

Reviews

Start your review of Safely Sourcing OSS - Beyond 0 CVEs

Never Stop Learning.

Get personalized course recommendations, track subjects and courses with reminders, and more.

Someone learning on their laptop while sitting on the floor.