Organizations from Fortune 100 enterprises to small businesses rely on open source software to develop their applications. Yet, over half of open source maintainers, whose work is critical to the health of software supply chains, work for free. As reliance on open source software grows, Donald Fischer, co-founder and CEO of Tidelift, and Brian Fox, CTO and co-founder at Sonatype, will discuss the threat created by ignoring the needs of overworked and underpaid maintainers against the backdrop of the rapidly-scaling open source ecosystem and increased attacks on the software supply chain.
In this session, Kanish Sharma, head of product marketing at Tidelift, will share brand new data from a recent state of the open source maintainer survey, including how the xz utils attack affected maintainers, what are challenges and consequences of not incentivizing maintainers, and what he has learned about supporting maintainers while providing examples of success stories when maintainers are paid for their work to ensure their projects remain secure and healthy.
Lauren Hanford, VP of product at Tidelift, will share maintainer perspective on xz and how it has affected the way they approach their work in her session, Unpaid Maintainers: The Security Threat No One Is Talking About (yet). She'll also discuss a set of tips security-conscious leaders can take away to decrease their security risk from under-maintained open source packages. Finally, she'll look at some benefits that downstream consumers receive when maintainers are paid to ensure their projects remain secure and healthy. Check it out on Wednesday October 23, from 2:20pm - 2:50pm EDT.
In their session, The Unseen, Underappreciated Security Work Your Maintainers May (or may not) Already Be Doing, Lauren Hanford, VP of product at Tidelift, and Seth Michael Larson, lead maintainer of urllib3, will discuss all of the security work happening in the best maintained projects that you can’t observe or measure, including avoiding leaked environment variables from their toolchain, limiting API token access, streamlining automated release processes, and more. Audience members will learn how they can do their part to ensure the projects they rely on follow these top practices. Happening Monday, October 28 at 1:45 p.m. ET.