Search

Items tagged with: OSS


100% agreed that the CVSS scoring system and "assume the worst" guidance makes for scores that do not accurately reflect importance. Especially for very broad-use things.

My take on this is that. like it or not, more open source projects of note need to become "CNA" (certificate numbering authorities) of their own which I understand can given them some control over the content of CVEs filed against their project. cve.org/ProgramOrganization/CN…

#cve #cvss #cna #oss

#oss #cve #cvss #CNA



Very excited to have shared this morning at @fosdem that @osi has joined the Digital Public Goods Alliance ! and is supporting this important initiative's mission of creating a more equitable world through OSIs activities of education, advocacy, and sustained care of the OSD. #oss is treated as digital public goods and is recognized in it's registry. Fantastic way for OSI to kick off its 25 year anniversary! blog.opensource.org/osi-joins-…