OpenChain
OpenChain
  • 315
  • 10 795

Відео

OpenChain Project - Main Monthly North America and Europe Call - 2024-11-05
Переглядів 18День тому
OpenChain Project - Main Monthly North America and Europe Call - 2024-11-05
OpenChain AI Study Group - Monthly Workshop for North America and Europe - 2024-11-05
Переглядів 26День тому
OpenChain AI Study Group - Monthly Workshop for North America and Europe - 2024-11-05
OpenChain Webinar- SBOM Visualization - An Alternative Approach to Reviewing SBOMs - 2024-10-23
Переглядів 7314 днів тому
OpenChain Webinar- SBOM Visualization - An Alternative Approach to Reviewing SBOMs - 2024-10-23
OpenChain SBOM Study Group - October - 2024-10-23
Переглядів 5914 днів тому
OpenChain SBOM Study Group - October - 2024-10-23
Education Work Group - Special Briefing on 2024-10-14
Переглядів 4421 день тому
Education Work Group - Special Briefing on 2024-10-14
OpenChain Webinar- The Role of Data in the Supply Chain of AI - 2024-10-10
Переглядів 76Місяць тому
OpenChain Webinar- The Role of Data in the Supply Chain of AI - 2024-10-10
OpenChain AI Study Group Call - Asia Sync Call - 2024-10-10
Переглядів 21Місяць тому
OpenChain AI Study Group Call - Asia Sync Call - 2024-10-10
OpenChain Automotive Work Group - 2024-10-08
Переглядів 25Місяць тому
OpenChain Automotive Work Group - 2024-10-08
OpenChain AI Study Group - Monthly Workshop for North America and Europe - 2024-10-01
Переглядів 41Місяць тому
OpenChain AI Study Group - Monthly Workshop for North America and Europe - 2024-10-01
OpenChain Project - Main Monthly North America and Europe Call - 2024-10-01
Переглядів 12Місяць тому
OpenChain Project - Main Monthly North America and Europe Call - 2024-10-01
OpenChain Monthly Meeting for North America and Europe - 2024-09-03
Переглядів 19Місяць тому
OpenChain Monthly Meeting for North America and Europe - 2024-09-03
OpenChain Webinar - AI - The Current Legal Landscape
Переглядів 108Місяць тому
OpenChain Webinar - AI - The Current Legal Landscape
OpenChain SBOM Study Group - 2024-09-25
Переглядів 38Місяць тому
OpenChain SBOM Study Group - 2024-09-25
OpenChain Education Work Group Meeting - 2024-08-07
Переглядів 183 місяці тому
OpenChain Education Work Group Meeting - 2024-08-07
Webinar: Implementing OpenChain ISO 5230 at endjin + Further Research on OpenChain ISO 18974
Переглядів 703 місяці тому
Webinar: Implementing OpenChain ISO 5230 at endjin Further Research on OpenChain ISO 18974
OpenChain Webinar - Update on the OSI Definition for Open Source AI - 2024-08-01
Переглядів 1873 місяці тому
OpenChain Webinar - Update on the OSI Definition for Open Source AI - 2024-08-01
OpenChain India Work Group - 2024-08-01
Переглядів 603 місяці тому
OpenChain India Work Group - 2024-08-01
OpenChain SBOM Study Group Kick-Off Call - 2024-07-30
Переглядів 493 місяці тому
OpenChain SBOM Study Group Kick-Off Call - 2024-07-30
OpenChain Japan Work Group All Member Meeting #31 - 2024-06-27
Переглядів 473 місяці тому
OpenChain Japan Work Group All Member Meeting #31 - 2024-06-27
Education Sync Call for Asia - Deep Dive into Maturity Models 2024-07-25
Переглядів 193 місяці тому
Education Sync Call for Asia - Deep Dive into Maturity Models 2024-07-25
OpenChain Explainer for Sales and Marketing - Beta
Переглядів 433 місяці тому
OpenChain Explainer for Sales and Marketing - Beta
OpenChain Webinar: IAV, TimeToAct + ISO-IEC 5230 - 3rd-Party Certification Case Study - 2024-07-16
Переглядів 643 місяці тому
OpenChain Webinar: IAV, TimeToAct ISO-IEC 5230 - 3rd-Party Certification Case Study - 2024-07-16
OpenChain Education Work Group - 2024-07-03
Переглядів 263 місяці тому
OpenChain Education Work Group - 2024-07-03
OpenChain AI Study Group Call - Asia Sync Call - 2024-07-11
Переглядів 343 місяці тому
OpenChain AI Study Group Call - Asia Sync Call - 2024-07-11
OpenChain Project - Main Monthly North America and Asia Call - 2024-07-16
Переглядів 133 місяці тому
OpenChain Project - Main Monthly North America and Asia Call - 2024-07-16
OpenChain Telco Work Group Meetings - 2024-07-04
Переглядів 493 місяці тому
OpenChain Telco Work Group Meetings - 2024-07-04
OpenChain Japan All Member Meeting 30 - 2024-02-28
Переглядів 553 місяці тому
OpenChain Japan All Member Meeting 30 - 2024-02-28
OpenChain October 5: Quiz 2 - A brief test of open source compliance knowledge.
Переглядів 44 місяці тому
OpenChain October 5: Quiz 2 - A brief test of open source compliance knowledge.
OpenChain October 4: Learn more about the OpenChain UK Work Group with Andrew Katz, Chair.
Переглядів 174 місяці тому
OpenChain October 4: Learn more about the OpenChain UK Work Group with Andrew Katz, Chair.

КОМЕНТАРІ

  • @MonsterFromTz
    @MonsterFromTz 10 днів тому

    What is this for?

  • @РодионЧаускин
    @РодионЧаускин Місяць тому

    Perez George Clark Karen Hall Betty

  • @SilasPetersen
    @SilasPetersen Місяць тому

    Great analysis! Evidence for later cases, if any.

  • @VictorSalendu
    @VictorSalendu 4 місяці тому

    The visuals complement the content nicely.

  • @GabaSaminu
    @GabaSaminu 4 місяці тому

    I never really watched yt that much until I found your channel

  • @jbmaillet
    @jbmaillet 7 місяців тому

    25:00 end of the FOSDEM context intro 40:20 about "confusion" 51:05 "two competing standards for SBOM... everybody hates that".

  • @jbmaillet
    @jbmaillet 8 місяців тому

    Great talk, as expected. Thank you *so much* for taking the time to explain the difficulty of addressing non-packaged software, typically C/C++ in embedded context. I am one of those cave-men in this primitive ecosystem, and I have the outermost difficulties of *convincing* my discussion partners that this is a very real, unsolved problem. Now I have one more "see? don't take my words for granted" example, and from a highly respected industry leader. (Explaining _why_ this is a problem compared to the "easy" use cases is even more difficult, especially when discussing with non deeply technical people.) (BTW, I have _my_ own solution, inspired by a Debian idea, that works well in _my_ C/C++ embedded contexts, but cannot be generalized. So ad-hoc solution *yes*, general *no*.) It starts with the question at 46:27. I took the liberty to transcribe it all: Question about benchmarking the quality of SCA and SBOM tools... especially in the case without a package management toolchain, such as C, C++? Philippe answer: Yes, there was a big discussion on the topic. I didn't bring that as an insight but more as a cultural action, we'll look at that in a second. But generally speaking... yes, there is a problem... which is: when you have packages which are not on main package repositories and registries, and the practical is "everything you put in an embedded device, and whenever you do C/C++ development... these packages are not there. So most of the effort today on the SBOM bench-marking and review that I've seen are really comparing the somewhat *easy stuff* which is the mist of known package managers so... Javascript, npm, maven java, PyPI... these... I'm not saying these are _easy_, but these are not _super hard_ to get right. And, there is a void, for everything that's off these package registries. So did we discuss that? Yes. Is there a solution? At the moment no. And... one way... is... to... workaround things like curation format where these would become somehow a missing manifest for these packages that are not... that don't have a manifest basically. I know... I for instance curated package URL (pURL), and it's a recurring theme of concern: how do we reference a package that doesn't have a package repository and an ecosystem behind it. So I'm just raising questions, I don't have the solution. I think in the end the solution there is to evolve a convention, probably around using pURL as an identifier may be useful for generic identifiers. And the only way you can really do something that works for these, in term of recognizing the package, is either you put something that is explicit, so say a small file that we do like the do with "about code", "about file" which says "ho! this directory the lib 1.2.13, and it's been patched with this and this modifications" (as an example) *OR* you do code matching where you have a tool that can do the matching against a knowledge base, and it will be accurately recognized that this directory contains the lib 1.2.13 and it's been patched. Today, you don't really have a good solution for the latter. Most of the tools that do matching are not really answering this question. They're raising more questions and returning tons of false positives. I have a side project on that, we could discuss that separately, but.... that's an unsolved problem. And if we... if you think there's a... it's important enough to discuss that separately then let's have a discussion on that. OK. Next one...

  • @daryllawrence9398
    @daryllawrence9398 2 роки тому

    𝓹𝓻𝓸𝓶𝓸𝓼𝓶

  • @arjakstodio2341
    @arjakstodio2341 3 роки тому

    sorry , don't have coin openchain ?

    • @openchain
      @openchain 3 роки тому

      This is the OpenChain Project, a supply chain management project publishing ISO/IEC 5230:2020 :)