<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: Kristina Kaldenbach</title>
    <description>The latest articles on DEV Community by Kristina Kaldenbach (@kristinatidelift).</description>
    <link>https://dev.to/kristinatidelift</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F858164%2Fb4e1b5d6-1fed-4627-9601-c9ce09e8285b.jpg</url>
      <title>DEV Community: Kristina Kaldenbach</title>
      <link>https://dev.to/kristinatidelift</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/kristinatidelift"/>
    <language>en</language>
    <item>
      <title>Upstream preview: Government carrot, government stick: Exploring two contrasting approaches to improving open source security</title>
      <dc:creator>Kristina Kaldenbach</dc:creator>
      <pubDate>Tue, 04 Jun 2024 21:15:03 +0000</pubDate>
      <link>https://dev.to/tidelift/upstream-preview-government-carrot-government-stick-exploring-two-contrasting-approaches-to-improving-open-source-security-3g16</link>
      <guid>https://dev.to/tidelift/upstream-preview-government-carrot-government-stick-exploring-two-contrasting-approaches-to-improving-open-source-security-3g16</guid>
      <description>&lt;p&gt;&lt;em&gt;Upstream is &lt;/em&gt;&lt;strong&gt;&lt;em&gt;tomorrow&lt;/em&gt;&lt;/strong&gt;&lt;em&gt; on June 5, and wow, our schedule is brillant. We’re giving you a sneak preview into some of the talks and the speakers giving them via posts like these. RSVP &lt;/em&gt;&lt;a href="https://upstream.live/register?__hstc=23643813.d1ddc767e9f4955f3bdd2f1c64c72f8c.1654699542897.1716388421586.1716392544277.1287&amp;amp;__hssc=23643813.2.1716392544277&amp;amp;__hsfp=1649118565" rel="noopener"&gt;&lt;em&gt;&lt;span&gt;now&lt;/span&gt;&lt;/em&gt;&lt;/a&gt;&lt;em&gt;!&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;Governments are starting to believe that their traditional hands-off approach to open source no longer makes sense. But what then? Europe is providing examples of both “carrot” and “stick”: providing incentives to people and organizations to do more security work (i.e. the carrot) or penalizing them for not doing the work or after security incidents happen (i.e. the stick).&lt;/p&gt;

&lt;p&gt;In this fireside chat, Tidelift co-founder and Upstream host Luis Villa sits down with &lt;a href="https://upstream.live/speaker-2024/fiona-krakenbuerger" rel="noopener"&gt;&lt;span&gt;Fiona Krakenbürger&lt;/span&gt;&lt;/a&gt; from the Sovereign Tech Fund and &lt;a href="https://upstream.live/speaker-2024/mirko-boehm?hsLang=en" rel="noopener"&gt;&lt;span&gt;Mirko Boehm&lt;/span&gt;&lt;/a&gt; from the Linux Foundation Europe to discuss the impending CRA legislation in the EU (the biggest government stick to date) and the Sovereign Tech Fund’s “carrot” approach to funding open security.&lt;/p&gt;

&lt;p&gt;If this conversation about the contrast to “carrot” and “stick” of support and regulation peaks your interest, be sure to join us at &lt;a href="https://upstream.live/"&gt;&lt;span&gt;Upstream&lt;/span&gt;&lt;/a&gt; on June 5! &lt;/p&gt;

&lt;p&gt;&lt;a href="https://upstream.live/" rel="noopener"&gt;RSVP now&lt;/a&gt;&lt;/p&gt;

&lt;h4&gt;About the speakers&lt;/h4&gt;

&lt;p&gt;Mirko Boehm is a free and open source software contributor, community manager, licensing expert and researcher, with contributions to major open source projects like the KDE Desktop (since 1997, including several years on the KDE e.V. board), the Open Invention Network, the Open Source Initiative and others. He is a visiting lecturer and researcher on free and open source software at the Technical University of Berlin. He joined the Linux Foundation in June 2023 as senior director for community development for Linux Foundation Europe, where he focuses on driving engagement and collaboration between all European open source stakeholders. &lt;/p&gt;

&lt;p&gt;Fiona Krakenbürger is the co-founder of the Sovereign Tech Fund, an initiative funded by the German Federal Ministry of Economic Affairs and Climate Action, to support Open Source Infrastructure in the Public Interest. Fiona has a background in Open Source Funding and has helped bootstrap and implement programs in Germany and the US. Besides her career in Open Source Funding, Fiona supported and founded various initiatives for more diversity in tech communities. She serves as a member on several boards and committees in the open source and technology ecosystem.&lt;/p&gt;

</description>
      <category>upstream</category>
      <category>opensource</category>
      <category>government</category>
      <category>security</category>
    </item>
    <item>
      <title>Upstream preview: Life after the xz utils backdoor hack</title>
      <dc:creator>Kristina Kaldenbach</dc:creator>
      <pubDate>Fri, 31 May 2024 21:25:21 +0000</pubDate>
      <link>https://dev.to/tidelift/upstream-preview-life-after-the-xz-utils-backdoor-hack-3m3l</link>
      <guid>https://dev.to/tidelift/upstream-preview-life-after-the-xz-utils-backdoor-hack-3m3l</guid>
      <description>&lt;p&gt;&lt;em&gt;Upstream is next week on June 5, and wow, our schedule is shaping up brilliantly. For the rest of this week, we’ll be giving you a sneak preview into some of the talks and the speakers giving them via posts like these. RSVP &lt;/em&gt;&lt;a href="https://upstream.live/register?__hstc=23643813.d1ddc767e9f4955f3bdd2f1c64c72f8c.1654699542897.1716388421586.1716392544277.1287&amp;amp;__hssc=23643813.2.1716392544277&amp;amp;__hsfp=1649118565" rel="noopener"&gt;&lt;em&gt;&lt;span&gt;now&lt;/span&gt;&lt;/em&gt;&lt;/a&gt;&lt;em&gt;!&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;In late March, our industry dealt with yet another attack on a popular open source project; this time, in the Linux-level package used for file compression called &lt;a href="https://tidelift.com/resources/xz-backdoor-hack" rel="noopener"&gt;&lt;span&gt;xz utils&lt;/span&gt;&lt;/a&gt;. &lt;/p&gt;

&lt;p&gt;What was most sinister about this attack, though, was how deeply it impacted trust within the open source community. The attacker spent years engineering multiple sock puppet accounts to gain the trust of the volunteer xz utils maintainer. The reality is that life for those who create and use open source after xz is going to get tougher. &lt;/p&gt;

&lt;p&gt;In this panel moderated by Tidelift VP of product Lauren Hanford, we’ll talk to Josh Bressers of Anchore; Jordan Harband, prolific Javascript maintainer; Rachel Stephens from RedMonk; Shaun Martin, IT and security management consulting principal from BlackIce; and Terrence Fletcher from Boeing to get a diverse mix of perspectives on how this changes the landscape of open source software supply chain security.&lt;/p&gt;

&lt;p&gt;If this conversation peaks your interest, be sure to join us at &lt;a href="https://upstream.live/" rel="noopener"&gt;&lt;span&gt;Upstream&lt;/span&gt;&lt;/a&gt; on June 5!&lt;/p&gt;

&lt;p&gt;&lt;a href="https://upstream.live/" rel="noopener"&gt;RSVP now&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;About the panelists &lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Rachel Stephens is a senior analyst with RedMonk, a developer-focused industry analyst firm. She focuses on helping clients understand and contextualize technology adoption trends, particularly from the lens of the practitioner. Her research covers a broad range of developer and infrastructure products.&lt;/li&gt;
&lt;li&gt;Shaun Martin is the IT and security management consulting principal at BlackIce. She has more than 23 years of experience in the IT security, risk, and compliance operations space. Her goal is to build and cultivate inclusive work environments where people can grow and thrive equally. &lt;/li&gt;
&lt;li&gt;Josh Bressers is vice president of security at Anchore where he guides security feature development for the company’s commercial and open source solutions. He is a co-lead of the OpenSSF SBOM Everywhere project, and is a co-founder of the Global Security Database project at the Cloud Security Alliance.&lt;/li&gt;
&lt;li&gt;Jordan Harband is an open source maintainer, specifically in JavaScript, and the principal open source architect at HeroDevs. He's also a web application developer, database administrator, network engineer, teacher, childcare—he wears many hats. His focus is JavaScript, standards, frontend web development, full stack (frontend + backend + db) architecture design, and overall object oriented code optimization. &lt;/li&gt;
&lt;li&gt;Terrence Fletcher is a product security engineer at the Boeing Company where he specializes in vulnerability management, attack surface profiling, and threat intelligence integration. He has over two decades of experience in IT and security, with a strong focus on the defense and intelligence sectors.&lt;/li&gt;
&lt;/ul&gt;

</description>
      <category>upstream</category>
      <category>opensource</category>
      <category>security</category>
      <category>xz</category>
    </item>
    <item>
      <title>Upstream 2024 agenda is live!</title>
      <dc:creator>Kristina Kaldenbach</dc:creator>
      <pubDate>Tue, 28 May 2024 15:01:22 +0000</pubDate>
      <link>https://dev.to/tidelift/upstream-2024-agenda-is-live-4dl5</link>
      <guid>https://dev.to/tidelift/upstream-2024-agenda-is-live-4dl5</guid>
      <description>&lt;p&gt;If you were waiting to sign up to attend Upstream, our one-day, virtual event bringing together open source maintainers and those who use their creations, until the speakers were announced, today’s the day. &lt;a href="https://upstream.live/schedule"&gt;The Upstream agenda&lt;/a&gt; is live. 🎉 If you haven't already marked June 5, 2024 on your calendars, you should do it now! &lt;a href="https://upstream.live/"&gt;RSVP here&lt;/a&gt;. ✅&lt;/p&gt;

&lt;p&gt;This year our theme is &lt;a href="https://blog.tidelift.com/upstream-is-june-5-2024"&gt;unusual ideas to solve the usual problems&lt;/a&gt;. By “the usual problems,” we mean the health and security of open source, which last we checked was still not a solved problem. By “unusual ideas,” we mean who are the people out there exploring the most interesting and unusual ways to make the open source software we all rely on more healthy, secure, and resilient?&lt;/p&gt;

&lt;p&gt;Come prepared to hear some exciting new ideas, because we have them lined up for you. Here’s a taste:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Luis Villa&lt;/strong&gt;, Tidelift co-founder and general counsel, will use his opening talk to set up this year’s theme. He’ll make the case that our current way of "fixing" open source health and security is simply not working, and he’ll introduce some of the new ideas we’ll be hearing more about through the course of the day.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Frank Nagle&lt;/strong&gt;, assistant professor at Harvard Business School, will sit down with &lt;strong&gt;Luis&lt;/strong&gt;, in our first fireside chat of the day, to discuss a recent paper Frank co-authored where he estimated the value of the world’s open source infrastructure at $8.8 trillion dollars.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Aeva Black&lt;/strong&gt; and &lt;strong&gt;Jack Cable&lt;/strong&gt;, from CISA (the U.S. Cybersecurity Infrastructure and Security Agency; and the only government agency that cares so much about security they put it in their name twice!), will sit down with Tidelift CEO and co-founder &lt;strong&gt;Donald Fischer&lt;/strong&gt; to discuss the industry-wide effort they are leading to make security by design a core business requirement in products versus an aftermarket technical feature.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Vincent Danen&lt;/strong&gt;, VP of Product Security at Red Hat, will join &lt;strong&gt;Donald&lt;/strong&gt; to make the case that our current system of patch management is in desperate need of a revolution (and he’ll share what a better approach focused on risk mitigation might look like).&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Aisha Gautreau&lt;/strong&gt;, OSPO lead at a large Canadian telecommunications company, will sit down with Tidelift VP of product, &lt;strong&gt;Lauren Hanford&lt;/strong&gt;, to share the journey of building an open source program office and what advantages it has created for them so far.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Tosha Ellison&lt;/strong&gt; and &lt;strong&gt;Gabriele Columbro&lt;/strong&gt; of FINOS (the Fintech Open Source Foundation) will join &lt;strong&gt;John Mark Walker&lt;/strong&gt;, director of the OSPO at Fannie Mae, and &lt;strong&gt;Donald Fischer&lt;/strong&gt; to chat about what financial services organizations are doing to improve open source security and invest in the open source they depend on, while sharing advice and strategies that all organizations in all industries can use to inform their own work.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Fiona Krakenbürger&lt;/strong&gt; from the Sovereign Tech Fund and &lt;strong&gt;Mirko Boehm&lt;/strong&gt; from the Linux Foundation Europe will sit down with &lt;strong&gt;Luis Villa&lt;/strong&gt; to discuss the impending CRA legislation in the EU (the biggest government proverbial "stick" to date) and the Sovereign Tech Fund’s "carrot" approach to funding open security.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;James Berthoty&lt;/strong&gt;, CEO of Latio Tech and security engineer at PagerDuty, will go over how to get CVEs out of GitHub Issues and why it’s frustrating for compliance teams and maintainers both. &lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Tatu Saloranta&lt;/strong&gt; of jackson-databind, &lt;strong&gt;Wesley Beary&lt;/strong&gt;, who maintains popular Ruby projects fog and excon, &lt;strong&gt;Irina Nazarova&lt;/strong&gt; of Evil Martians, and &lt;strong&gt;Valeri Karpov&lt;/strong&gt;, from Mongoose, make up our maintainer panel this year and will discuss the state of life as an open source maintainer in 2024. &lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Andrey Sitnik&lt;/strong&gt;, front-end principal at Evil Martians, will give insights on how to make your open source project popular from his 15 years of making open source tools, some a success with others a failure. &lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Rachel Stephens&lt;/strong&gt;, senior industry analyst at RedMonk, &lt;strong&gt;Shaun Martin&lt;/strong&gt;, IT and security management consulting principal at BlackIce, &lt;strong&gt;Josh Bressers&lt;/strong&gt;, VP of security at Anchore, &lt;strong&gt;Jordan Harband&lt;/strong&gt;, principal open source architect at HeroDevs, and &lt;strong&gt;Terrence Fletcher&lt;/strong&gt;, product security engineer at Boeing, will join Tidelift VP of product, &lt;strong&gt;Lauren Hanford&lt;/strong&gt;, to discuss how &lt;a href="https://tidelift.com/resources/xz-backdoor-hack"&gt;the xz utils backdoor hack&lt;/a&gt; has changed the landscape of open source software supply chain security. &lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;This agenda is 🔥 You don't want to miss out. Register for this free, one-day virtual event &lt;a href="https://upstream.live/register"&gt;here&lt;/a&gt;. &lt;/p&gt;

</description>
      <category>upstream</category>
      <category>tidelift</category>
      <category>opensource</category>
      <category>maintainers</category>
    </item>
  </channel>
</rss>
