DiscoverWhat's in the SOSS? An OpenSSF PodcastJack Cable of CISA and Zach Steindler of GitHub Dig Into Package Repository Security
Jack Cable of CISA and Zach Steindler of GitHub Dig Into Package Repository Security

Jack Cable of CISA and Zach Steindler of GitHub Dig Into Package Repository Security

Update: 2024-11-26
Share

Description

CRob discusses package repository security with two people who know a lot about the topic. Zach Steindler is a principal engineer at Github, a member of the OpenSSF TAC and co-chairs the OpenSSF Security Packages Repository Working Group. Jack Cable is a senior technical advisor at CISA. Earlier this year, Zach and Jack published a helpful guide of best practices called “Principles for Package Repository Security.”

  • 00:48 - Jack and Zach share their backgrounds
  • 02:59 - What package repositories are and why they’re important to open source users
  • 04:17 - The positive impact package security has on downstream users
  • 07:06 - Jack and Zach offer insight into the "Prinicples for Package Repository Security" document
  • 11:18 - Future endeavors of the Securing Software Repositories Working Group
  • 17:32 - Jack and Zach answer CRob’s rapid-fire questions
  • 19:31 - Advice for those entering the industry
  • 21:28 - Jack and Zach share their calls to action 

Episode links:

Comments 
loading
In Channel
loading
00:00
00:00
1.0x

0.5x

0.8x

1.0x

1.25x

1.5x

2.0x

3.0x

Sleep Timer

Off

End of Episode

5 Minutes

10 Minutes

15 Minutes

30 Minutes

45 Minutes

60 Minutes

120 Minutes

Jack Cable of CISA and Zach Steindler of GitHub Dig Into Package Repository Security

Jack Cable of CISA and Zach Steindler of GitHub Dig Into Package Repository Security

OpenSSF