{"id":90638,"date":"2020-08-04T01:42:20","date_gmt":"2020-08-03T23:42:20","guid":{"rendered":"https:\/\/prohoster.info\/blog\/novosti-interneta\/uchrezhdyon-proekt-openssf-sfokusirovannyj-na-povyshenii-bezopasnosti-otkrytogo-po"},"modified":"2020-08-04T01:42:20","modified_gmt":"2020-08-03T23:42:20","slug":"uchrezhdyon-proekt-openssf-sfokusirovannyj-na-povyshenii-bezopasnosti-otkrytogo-po","status":"publish","type":"post","link":"https:\/\/prohoster.info\/de\/blog\/news\/uchrezhdyon-proekt-openssf-sfokusirovannyj-na-povyshenii-bezopasnosti-otkrytogo-po","title":{"rendered":"Das Projekt OpenSSF wurde ins Leben gerufen, um die Sicherheit von Open Source Software zu erh\u00f6hen.","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>Linux Foundation <noindex><a rel=\"nofollow\" href=\"https:\/\/www.linuxfoundation.org\/press-release\/2020\/08\/technology-and-enterprise-leaders-combine-efforts-to-improve-open-source-security\/\">k\u00fcndigte an<\/a><\/noindex> \u00fcber die Schaffung eines neuen gemeinsamen Projekts <noindex><a rel=\"nofollow\" href=\"https:\/\/openssf.org\/\">OpenSSF<\/a><\/noindex> (Open Source Security Foundation), das darauf abzielt, die Arbeit f\u00fchrender Vertreter der Industrie im Bereich der Sicherheit von Open Source-Software zu b\u00fcndeln. OpenSSF wird die Entwicklung von Initiativen wie  <noindex><a rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=39635Core\">Infrastructure Initiative<\/a><\/noindex> und <noindex><a rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=51867\">Open Source Security Coalition<\/a><\/noindex>, sowie andere sicherheitsrelevante Arbeiten, die von den Projektteilnehmern unternommen werden, zusammenf\u00fchren.<\/p>\n<p>Zu den Gr\u00fcndern von OpenSSF geh\u00f6ren Unternehmen wie <noindex><a rel=\"nofollow\" href=\"https:\/\/github.blog\/2020-08-03-github-joins-the-open-source-security-foundation\/\">GitHub<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/opensource.googleblog.com\/2020\/08\/google-joins-open-source-security.html\">Google<\/a><\/noindex>, IBM, JPMorgan Chase, <noindex><a rel=\"nofollow\" href=\"https:\/\/www.microsoft.com\/security\/blog\/2020\/08\/03\/microsoft-open-source-security-foundation-founding-member-securing-open-source-software\/\">von Microsoft<\/a><\/noindex>, NCC Group, OWASP Foundation und Red Hat. Als Teilnehmer haben sich Unternehmen wie GitLab, HackerOne, Intel, Uber, VMware, ElevenPaths, Okta, Purdue, SAFECode, StackHawk und Trail of Bits angeschlossen.<\/p>\n<p>Es wird erw\u00e4hnt, dass Open Source-Software in der heutigen Welt in vielen Bereichen der Industrie stark nachgefragt wird, aber aufgrund der Entwicklungsspezifika die Sicherheit von Abh\u00e4ngigkeiten und Mitwirkenden beeinflusst wird. Daher ist es f\u00fcr die Best\u00e4tigung der Sicherheit von Open-Source-Projekten wichtig, nicht nur den Hauptcode, sondern auch die Abh\u00e4ngigkeiten zu \u00fcberpr\u00fcfen und die Identifizierung von Entwicklern, deren Code in das Projekt aufgenommen wird, sowie eine zuverl\u00e4ssige Authentifizierung bei Reviews und Commits sicherzustellen. Dar\u00fcber hinaus ist der Einsatz sicherer Build-Systeme und die \u00dcberpr\u00fcfung von Builds zur Gew\u00e4hrleistung der Sicherheit erforderlich. <\/p>\n<p>Die Arbeit von OpenSSF wird sich auf Bereiche wie koordiniertes <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/ossf\/wg-vulnerability-disclosures\">Offenlegung<\/a><\/noindex> von Informationen zu Schwachstellen und die Verbreitung von Patches, <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/ossf\/wg-security-tooling\">Entwicklung<\/a><\/noindex> Werkzeuge zur Sicherstellung der Sicherheit, <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/ossf\/wg-best-practices-os-developers\">Ver\u00f6ffentlichung<\/a><\/noindex> beste Praktiken f\u00fcr eine sichere Organisation der Softwareentwicklung, <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/ossf\/wg-identifying-security-threats\">Erkennung<\/a><\/noindex> sicherheitsrelevanter Bedrohungen in Open Source-Software,  <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/ossf\/wg-securing-critical-projects\">Durchf\u00fchrung<\/a><\/noindex> Auditarbeiten und die St\u00e4rkung der Sicherheit kritischer Open Source-Projekte, sowie die Schaffung von Mitteln zur \u00dcberpr\u00fcfung der <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/ossf\/wg-developer-identity\">Identit\u00e4t der Entwickler<\/a><\/noindex>.<\/p>\n<p><noindex><a rel=\"nofollow\" name=\"link\"><\/a><\/noindex><\/p>\n<p>Quelle: <a \ncontent=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=53482\">opennet.ru<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u041e\u0440\u0433\u0430\u043d\u0438\u0437\u0430\u0446\u0438\u044f Linux Foundation \u043e\u0431\u044a\u044f\u0432\u0438\u043b\u0430 \u043e \u0444\u043e\u0440\u043c\u0438\u0440\u043e\u0432\u0430\u043d\u0438\u0438 \u043d\u043e\u0432\u043e\u0433\u043e \u0441\u043e\u0432\u043c\u0435\u0441\u0442\u043d\u043e\u0433\u043e \u043f\u0440\u043e\u0435\u043a\u0442\u0430 OpenSSF (Open Source Security Foundation), \u043f\u0440\u0438\u0437\u0432\u0430\u043d\u043d\u043e\u0433\u043e \u043e\u0431\u044a\u0435\u0434\u0438\u043d\u0438\u0442\u044c \u0440\u0430\u0431\u043e\u0442\u0443 \u0432\u0435\u0434\u0443\u0449\u0438\u0445 \u043f\u0440\u0435\u0434\u0441\u0442\u0430\u0432\u0438\u0442\u0435\u043b\u0435\u0439 \u0438\u043d\u0434\u0443\u0441\u0442\u0440\u0438\u0438 \u0432 \u043e\u0431\u043b\u0430\u0441\u0442\u0438 \u043f\u043e\u0432\u044b\u0448\u0435\u043d\u0438\u044f \u0431\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u0438 \u043e\u0442\u043a\u0440\u044b\u0442\u043e\u0433\u043e \u041f\u041e. OpenSSF \u043f\u0440\u043e\u0434\u043e\u043b\u0436\u0438\u0442 \u0440\u0430\u0437\u0432\u0438\u0442\u0438\u0435 \u0442\u0430\u043a\u0438\u0445 \u0438\u043d\u0438\u0446\u0438\u0430\u0442\u0438\u0432, \u043a\u0430\u043a Infrastructure Initiative \u0438 Open Source Security Coalition, \u0430 \u0442\u0430\u043a\u0436\u0435 \u043e\u0431\u044a\u0435\u0434\u0438\u043d\u0438\u0442 \u0438 \u0434\u0440\u0443\u0433\u0438\u0435 \u0441\u0432\u044f\u0437\u0430\u043d\u043d\u044b\u0435 \u0441 \u0431\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u044c\u044e \u0440\u0430\u0431\u043e\u0442\u044b, \u043f\u0440\u0435\u0434\u043f\u0440\u0438\u043d\u0438\u043c\u0430\u0435\u043c\u044b\u0435 \u0443\u0447\u0430\u0441\u0442\u043d\u0438\u043a\u0430\u043c\u0438 \u043f\u0440\u043e\u0435\u043a\u0442\u0430. \u0412 \u0447\u0438\u0441\u043b\u043e \u0443\u0447\u0440\u0435\u0434\u0438\u0442\u0435\u043b\u0435\u0439 OpenSSF [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-90638","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.1.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u041e\u0440\u0433\u0430\u043d\u0438\u0437\u0430\u0446\u0438\u044f Linux Foundation\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/de\/blog\/news\/uchrezhdyon-proekt-openssf-sfokusirovannyj-na-povyshenii-bezopasnosti-otkrytogo-po\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.1.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"de_DE\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0423\u0447\u0440\u0435\u0436\u0434\u0451\u043d \u043f\u0440\u043e\u0435\u043a\u0442 OpenSSF, \u0441\u0444\u043e\u043a\u0443\u0441\u0438\u0440\u043e\u0432\u0430\u043d\u043d\u044b\u0439 \u043d\u0430 \u043f\u043e\u0432\u044b\u0448\u0435\u043d\u0438\u0438 \u0431\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u0438 \u043e\u0442\u043a\u0440\u044b\u0442\u043e\u0433\u043e \u041f\u041e | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u041e\u0440\u0433\u0430\u043d\u0438\u0437\u0430\u0446\u0438\u044f Linux Foundation\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/de\/blog\/news\/uchrezhdyon-proekt-openssf-sfokusirovannyj-na-povyshenii-bezopasnosti-otkrytogo-po\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2020-08-03T23:42:20+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2020-08-03T23:42:20+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Das Projekt OpenSSF wurde ins Leben gerufen, um die Sicherheit von Open Source-Software zu erh\u00f6hen | ProHoster","description":"Linux Foundation","canonical_url":"https:\/\/prohoster.info\/de\/blog\/news\/uchrezhdyon-proekt-openssf-sfokusirovannyj-na-povyshenii-bezopasnosti-otkrytogo-po","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"de_DE","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0423\u0447\u0440\u0435\u0436\u0434\u0451\u043d \u043f\u0440\u043e\u0435\u043a\u0442 OpenSSF, \u0441\u0444\u043e\u043a\u0443\u0441\u0438\u0440\u043e\u0432\u0430\u043d\u043d\u044b\u0439 \u043d\u0430 \u043f\u043e\u0432\u044b\u0448\u0435\u043d\u0438\u0438 \u0431\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u0438 \u043e\u0442\u043a\u0440\u044b\u0442\u043e\u0433\u043e \u041f\u041e | ProHoster","og:description":"\u041e\u0440\u0433\u0430\u043d\u0438\u0437\u0430\u0446\u0438\u044f Linux Foundation","og:url":"https:\/\/prohoster.info\/de\/blog\/news\/uchrezhdyon-proekt-openssf-sfokusirovannyj-na-povyshenii-bezopasnosti-otkrytogo-po","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2020-08-03T23:42:20+00:00","article:modified_time":"2020-08-03T23:42:20+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"90638","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":null,"breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-02-28 12:45:33","updated":"2022-09-30 11:51:44","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/posts\/90638","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/comments?post=90638"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/posts\/90638\/revisions"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/media?parent=90638"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/categories?post=90638"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/tags?post=90638"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}