Skip to main content

Tightening every bolt

UB4.132 | Day 1 | 11:00 - 11:30 | Speakers: Daniel Stenberg

Tightening every bolt
A picture of a devroom at FOSDEM 2024
Open in browser

Notes

Abstract

Things to do in order to sleep well while having your C code in twenty billion installations. A talk about what the curl project does to minimize security risks: Security, Safety, Reproducibility, Vulnerability handling and the processes and tooling around it.

As BDFL of the curl project, Daniel talks about what this project does to avoid it causing the world to burn. From code style, reviews and tests to signings, reproducibility, running a bug-bounty and becoming a CNA to filter bogus CVEs. curl aims to be top of the class in (Open Source) software security. Here's your chance to point finger and tell us what we should do better.

Speakers

Daniel Stenberg

Notice: The placeholder video image is licensed under CC BY-SA 4.0. The original image can be found hereChanges made to the image are: Cropped the image to a new ratio, part of the image was cut off.