It’s Dangerous to Build It Alone, Take This. - Jeremy Rickard & Ashna Mehrotra, Microsoft
Abstract
You’ve got high and critical CVEs in open source software packages that are critical to your platform or business. Time is almost up to patch them, and the upstream project hasn’t fixed things. If you don’t patch, your accreditation might be at risk. You’re going to have to do it yourself! But where do you start? Fork the projects? Can you just patch in place? In this session, you’ll learn about tools and strategies that can help you respond to CVEs in your container images faster, starting with patching existing images in place with Copacetic and moving on to patching and building projects from scratch. We’ll look at challenges to building and testing upstream projects using existing tools and learn from emerging practices in industry. We’ll also talk about how to inform your teams to stop using bad images! After this session, you’ll have best practices and tools at your disposal, understand some of the pitfalls of owning your entire open source software supply chain.