今回のMeetupでは、5月18日-20日に米国ミネアポリスで開催されたOpoen Source Summit North America (OSSNA) および5月21日に併設イベントとして開催されたOpenSSF Community Day North Americaのイベントレポートと、OpenSSF JapanのメンバーがOSSNAでセキュリティフレームワーク「SLSA (サルサ: Supply-chain Levels for Software Artifacts)」の発表を日本語でお届けします。また、EU Cyber Resilience Act (EU CRA) 関連の最新情報も併せてお届けします。
本Meetupは、OpenSSFメンバーに限らず、OSSセキュリティに興味がある方はどなたでも歓迎します。本Meetupは、OSSセキュリティに関する同じ問題意識や課題を持つ仲間が集まり、主に日本語で情報を共有して、一緒に前進していける場を目指します。
現代社会を支えるITシステムは、OSSに広く依存しています。企業の製品やサービスに含まれているソフトウェアのうち70%〜90%はOSSであると言われています。企業は多くの場合、OSSの活用を通して開発スピードと品質を高め、技術革新を目指します。OSS採用により、産業全体でOSSのメリットを共有する一方で、脆弱性が見つかればその影響は広範囲に及びます。このためOSSセキュリティを確保することは非常に重要であり、国や組織を超えた協力的な取り組みが求められています。
We are thrilled to announce that the members of the Open Source Security Foundation (OpenSSF), a cross-industry initiative that brings together the industry's most important open source security initiatives and the individuals and companies that support them, will host the OSS Security Meetup on Thursday,July 2nd at Renesas Electronics.
In this Meetup, we will provide an event report on the Open Source Summit North America (OSSNA), held in Minneapolis, USA, from May 18–20, as well as the OpenSSF Community Day North America, which was held as a co-located event on May 21. We will also present, in Japanese, a session by the member of OpenSSF Japan on the security framework “SLSA (Supply-chain Levels for Software Artifacts)” delivered at OSSNA. In addition, we will share the latest information related to the EU Cyber Resilience Act (EU CRA).
We aim to create a place where people with the same awareness and challenges related to OSS security can gather, share information mainly in Japanese, and move forward together. We welcome anyone interested in OSS security, not only OpenSSF members.
Date: Julyl 2nd (Thursday)
Time: 18:30 to 20:30, Japanese Standard Time (JST)
Venue: Renesas Electronics Headquarters (11F Conference Room, Toyosu FORESIA) + Online
Registration: Register here by July 1st (18:00 pm JST)
(Note: All sessions will be presented in Japanese)
OSSNA / OpenSSF Community Day North America Event Report
Munehiro Ikeda, Cybertrust Japan
Verification Toward Applying SLSA in Automotive IVI Software Development
Yuta Kiyomi, Honda
Update on EU Cyber Resilience Act Information
Tsukasa Yobo, Renesas Electronics
The IT systems that support modern society are widely dependent on OSS. It is estimated that 70% to 90% of the software included in a company’s products and services is OSS.Organizations often use OSS to improve development speed and quality and aim for technological innovation. By adopting OSS, the benefits of OSS
can be shared across industries, but if vulnerabilities are found, the impact will be widespread. Ensuring OSS security is of the utmost importance, and for that purpose, cooperative efforts across countries and organizations are required.