Security

Reviewing the CVE process and the CNA rules 4.0

Tuesday, August 20, 2024 - 03:49 by Marta Rybczynska

The Eclipse Foundation is a CNA (CVE Numbering Authority), responsible for assigning vulnerability identification numbers, known as CVE (Common Vulnerability Enumerations), to our projects. This August, a new set of rules for CNAs comes into force.

Securing the Future: 2FA Now Mandatory for Eclipse Foundation Committers

Friday, June 7, 2024 - 11:46 by Jacob Harris

This initiative, aimed at bolstering the security of our source code repositories, mandates that all users with write access to an Eclipse Project repository (commonly known as committers) on GitHub and the Eclipse Foundation GitLab instance must use 2FA.

FOSS Security Campus Trainings

FOSS Security Campus Trainings are in-depth training courses by distinguished experts on the topics of open source and security, to empower developers, dev ops engineers, managers and others in the field of software development to make their products more secure. The trainings being offered are: DevSecOps and Software factory included by Thomas Fricke (Freelancer), A Game of Cat and Mouse by Stefan Grönke (Radically Open Security) and Automated Security Testing by Peter Mosmans (Radically Open Security).

FOSS Security Campus

FOSS Security Campus, is a new event focusing on IT security in the FOSS and open source sector. The conference will take place for the first time on September 28-29th, 2023. Topics include Open Source Supply Chains, Security Processes, Vulnerability Disclosure, Bug Bounties, Security by Design, Risk Mitigation and much more. The conference will be kicked off with a keynote by Melanie Rieback on "How business models are conflicting with a cybersecure world" and on the second conference day a keynote will be held by Thijs Ebbers and Jan Vogel on Zero Privilege Architectures.

Effortless Jakarta EE Application Monitoring With Payara Monitoring Console

In this session, we will explore how Payara Monitoring Console helps you streamline your Jakarta EE and MicroProfile application monitoring, troubleshooting, and management. Whether you are a DevOps engineer, system administrator, or Jakarta EE developer, this webinar is a must-attend event. Discover how the Payara Monitoring Console streamlines monitoring workflows, improves application performance, and enables faster incident response for your organisation.

Security for all - OpenHW Group leads the charge towards a secure future

Tuesday, March 7, 2023 - 14:05 by Olivier Goulet

Security has become a critical issue for the entire IoT supply chain in recent years, as the number of connected devices continues to grow and our reliance on them increases. With more devices connected to the internet, the potential for security breaches and data theft also increases.

Alpha-Omega Project First Year In Review, Plus New Funding Pledge

Friday, December 16, 2022 - 12:33 by Jacob Harris
With funding from the Alpha-Omega Project, the Eclipse Foundation ran Scorecards against all its projects, analyzed the results, and created a prioritized list of activities that they’ll focus on to achieve the best and broadest impact.