HNHacker News
TopNewBestAskShowJobs

kimsterv

64 karma · joined October 7, 2008

submissionscomments
kimsterv··on A toolbox for a secure software supply chain
Def check out the gitsign project mentioned in the post: https://github.com/sigstore/gitsign
kimsterv··on Open Source Security Foundation
Honk! I represent Google on the OpenSSF, and help lead our Google Open Source Security Team. We've kicked off several projects inside the OpenSSF, and contribute to several other related efforts.

Here's a non-exhaustive list: Security Scorecards (https://github.com/ossf/scorecard): auto-generated security checks for OSS, Criticality Score (https://github.com/ossf/criticality_score): auto-generated criticality score for OSS, Package Feeds (https://github.com/ossf/package-feeds): watches package registries for updates, malware analysis tools, SLSA (https://github.com/slsa-framework/slsa): proposal for a supply chain integrity framework, Sigstore/Cosign (https://sigstore.dev/): code signing made easy!

We are also investing and exploring different efforts for improving security of critical OSS projects, and making it sustainable! If any of these projects sound interesting, come join us in the OpenSSF Working Groups!

*edited formatting

kimsterv··on Mitigating Memory Safety Issues in Open Source Software
Unfortunately, the openssf members haven’t come to consensus on the process for handling funding requests and the process. We’ll get there (hopefully!) but it’s looking like it’s going to take more time. -Sincerely, Google’s OpenSSF governing board rep
kimsterv··on How .NET container images are maintained
Dan’s the best. We work together, and we’re hiring. I’m biased but I think we have the most fun at Google. :)
kimsterv··on Security scorecards for open source projects
there's an open issue related to this: https://github.com/ossf/scorecard/issues/27