Inbound FOSS Security Policies
Thankfully, it’s becoming a lot more common to see companies creating and enforcing security policies for inbound FOSS software. I say “thankfully” not because FOSS is inherently insecure—you learned in Chapter 5, Strengthen Your Business Through FOSS, that it’s not—but because people’s handling of FOSS is. You’ll learn a lot more about this in Chapter 11, Know the Links in Your Software Supply Chain, but here are the basics.
All software has bugs, and some of those bugs may have implications for security. This is a fact of software, and one that many people prefer to ignore. Updating (patching) software to have the latest and most secure version can be an inconvenience, but it’s not nearly as inconvenient ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access