Security: Git, Tor, and Fake (Monopolised, Centralised) 'Security' From Linux Foundation


-
"git clone" Hit By Vulnerability That Could Lead To Code Execution
Disclosed today is CVE-2021-21300 as a security vulnerability affecting git clone that could lead to specially crafted repositories being able to execute code during the Git clone process.
Git versions back to v2.15 are affected by this security vulnerability. Specially crafted repositories could execute code during the git clone process on case-insensitive file-systems supporting symbolic links. The vulnerability stems from clean/smudge filters being abused like those used by Git LFS.
-
The Tor Software Has Two Potential Denial Of Service Vulnerabilities, Fix Is Coming Next Week
Current and previous versions for the Tor Onion Router software have two undisclosed Denial Of Service vulnerabilities with the potential to cause problems for the Tor networks authority servers. The Torproject will release a new version with a fix "early next week". Everyone who is using Tor Browser or running a Tor node should upgrade when it becomes available.
-
Linux Foundation Announces Free sigstore Signing Service to Confirm Origin and Authenticity of Software
The Linux Foundation, the nonprofit organization enabling mass innovation through open source, today announced the sigstore project. sigstore improves the security of the software supply chain by enabling the easy adoption of cryptographic software signing backed by transparency log technologies.
sigstore will empower software developers to securely sign software artifacts such as release files, container images and binaries. Signing materials are then stored in a tamper-proof public log. The service will be free to use for all developers and software providers, with the sigstore code and operation tooling developed by the sigstore community. Founding members include Red Hat, Google and Purdue University.
“sigstore enables all open source communities to sign their software and combines provenance, integrity and discoverability to create a transparent and auditable software supply chain,” said Luke Hinds, Security Engineering Lead, Red Hat office of the CTO. “By hosting this collaboration at the Linux Foundation, we can accelerate our work in sigstore and support the ongoing adoption and impact of open source software and development.”
-
Industry-Wide Initiative to Support Open Source Security Gains New Commitments
OpenSSF, a cross-industry collaboration to secure the open source ecosystem, today announced new membership commitments to advance open source security education and best practices. New members include Citi, Comcast, DevSamurai, Hewlett Packard Enterprise (HPE), Mirantis, and Snyk.
Open source software (OSS) has become pervasive in data centers, consumer devices and services, representing its value among technologists and businesses alike. Because of its development process, open source has a chain of contributors and dependencies before it ultimately reaches its end users. It is important that those responsible for their user or organization’s security are able to understand and verify the security of this dependency supply chain.
-

- Login or register to post comments
Printer-friendly version- 16065 reads
PDF version
More in Tux Machines
- Highlights
- Front Page
- Latest Headlines
- Archive
- Recent comments
- All-Time Popular Stories
- Hot Topics
- New Members
digiKam 7.7.0 is released
After three months of active maintenance and another bug triage, the digiKam team is proud to present version 7.7.0 of its open source digital photo manager. See below the list of most important features coming with this release.
|
Dilution and Misuse of the "Linux" Brand
|
Samsung, Red Hat to Work on Linux Drivers for Future Tech
The metaverse is expected to uproot system design as we know it, and Samsung is one of many hardware vendors re-imagining data center infrastructure in preparation for a parallel 3D world.
Samsung is working on new memory technologies that provide faster bandwidth inside hardware for data to travel between CPUs, storage and other computing resources. The company also announced it was partnering with Red Hat to ensure these technologies have Linux compatibility.
|
today's howtos
|








.svg_.png)
Content (where original) is available under CC-BY-SA, copyrighted by original author/s.

'This vulnerability affects platforms with case-insensitive..."
git: malicious repositories can execute remote code while cloning
Windows issue (mostly)
A Git security release
"Linux Foundation serves up free code-signing service"
Sign of the primes: Linux Foundation serves up free code-signing service • The Register
Linux Foundation announces new open-source software signing service | ZDNet
Monopolists trying to centralise application trust
Sigstore is a Let’s Encrypt Like Software Signing Service for Open Source Software
IBM and Google are centralising and monopolising trust
Linux Foundation Debuts Sigstore Project for Software Signing
Linux Foundation Debuts Sigstore Project for Software Signing
Linux Foundation Project Secures Software Supply Chains - DevOps.com
Linux Foundation is making it easier to verify the authenticity of software
Linux Foundation launches free service to verify software authenticity
Linux Foundation launches software signing service
NSA-connected spy companies promise us "tamper-proof encryption"
The Linux Foundation's "sigstore" project
The Linux Foundation Launches sigstore, a New Software Signing Service
Outsourcing Linux trust to monopolies with terrible record
Sigstore is a Linux Foundation project developed by Google and Red Hat for code signing
Another puff piece
Google and Red Hat team up with Linux Foundation for software-signing service
Trusting NSA enablers for supply chain checks
Linux Foundation boosts security with crypto signing and ID credentialing groups
Microsoft boosters support centralisation and monopolisation...
Linux Foundation unveils Sigstore — a Let's Encrypt for code signing
Linux Foundation PR/media partner TechRepublic
A new Linux Foundation open source signing tool could make secure software supply chains universal [Ed: Linux Foundation PR/media partner TechRepublic the latest to promote fake security]
Sigstore Project Aims to Monopolise Software Supply Chain
Sigstore Project Aims to Secure Software Supply Chain
More puff pieces
Linux community project aims to tackle dependency confusion attacks with easy code signing, verification [Ed: Linux Foundation pushing fake security (monopoly disguised as "security") with help from paid-for media partners]
How Open Source is responding to IT's Pearl Harbor.
How Open Source is responding to IT's Pearl Harbor.
Free sigstore signing service confirms software origin....
Free sigstore signing service confirms software origin and authenticity
Sigstore Is A New And Free Code Signing Service By Linux Fdn.
Sigstore Is A New And Free Code Signing Service By Linux Foundation
Still shilling monopoly disguised as 'security'
Linux Foundation Sigstore Aims to Be the Let's Encrypt of Code Signing