OpenJS Foundation’s Leader Details the Threats to Open Source
After the XZ Utils backdoor vulnerability was uncovered in March, the OpenJS Foundation saw a surge in inquiries from potential open source JavaScript contributors. Robin Ginn, executive director of the foundation, noted that volunteer-led JavaScript communities often face challenges in managing these contributions. The discovery that a single contributor, "Jia Tan," planted the backdoor heightened vigilance, especially when new contributors requested admin privileges. Ginn emphasized that trust is not synonymous with security, especially in open source projects where maintainers must be vigilant about who can access their repositories.
The XZ vulnerability highlighted broader concerns about the security of open source software, particularly in projects with only a single maintainer. Despite receiving a significant grant from Germany's Sovereign Tech Fund, the foundation remains under-resourced, with just two full-time staffers supporting 35 projects. Ginn urged companies that rely on open source software to invest in it by hiring maintainers, ensuring these critical projects are properly supported.
Learn more from The New Stack about open source vulnerability
Linux xz Backdoor Damage Could Be Greater Than Feared
Unzipping the XZ Backdoor and Its Lessons for Open Source
Linux xz and the Great Flaws in Open Source
Join our community of newsletter subscribers to stay on top of the news and at the top of your game.
Adventures in Javascriptlandia
You can read more about Javascriptlandia here. It is part of larger conversation happening on Google's Open Source Blog and through initiatives like Github allowing corporations into their Sponsors program.
For a delightfully old school and interactive website about Myles, click here. For his Twitter, go here.
You can find Jory's website here and her Twitter presence here.
This week's lifeboat badge goes to Marijn van Vliet for answering the question: How do I return a char array from a function?
See Privacy Policy at https://art19.com/privacy and California Privacy Notice at https://art19.com/privacy#do-not-sell-my-info.
Chatting with Robin Ginn, executive director of the OpenJS Foundation
You can learn more about today's event and all the livestream broadcasts here.
If you want to learn more about Robin, you can get in touch here.
See Privacy Policy at https://art19.com/privacy and California Privacy Notice at https://art19.com/privacy#do-not-sell-my-info.
Real JavaScript, not too much, stage three and above
KBall and Nick meet up with Jory Burson and Amal Hussein at Node+JS Interactive. Together we open up the black box of the JavaScript standards process, talk about how to get involved, and then dig into the use of ASTs to transform and analyze JavaScript.
Join the discussion
Changelog++ members support our work, get closer to the metal, and make the ads disappear. Join today!
Sponsors:
Rollbar – We catch our errors before our users do because of Rollbar. Resolve errors in minutes, and deploy your code with confidence. Learn more at rollbar.com/changelog.
Algolia – Our search partner. Algolia’s full suite search APIs enable teams to develop unique search and discovery experiences across all platforms and devices. We’re using Algolia to power our site search here at Changelog.com. Get started for free and learn more at algolia.com.
OneMonth.com – One of the best places to learn how to code…in just one month. If you’re interested in taking your career to the next level head to OneMonth.com/jsparty and get 10% off any coding course.
Fastly – Our bandwidth partner. Fastly powers fast, secure, and scalable digital experiences. Move beyond your content delivery network to their powerful edge cloud platform. Learn more at fastly.com.
Featuring:
Jory Burson – Website, GitHub, X
Amal Hussein – GitHub, X
Kevin Ball – Website, GitHub, LinkedIn, X
Nick Nisi – Website, GitHub, Mastodon, X
Show Notes:
Standards & Opening the Black Box
TC39 on GitHub
Myles Borins
Daniel Ehrenberg
Maggie Pint
TC39 proposals
The TC39 Process
How to join ECMA
Jory’s talk on Standardizing JavaScript
On the distribution of stakeholders
Representing Web Developers in W3C
On testing the JavaScript spec with JavaScript
Official ECMAScript Conformance Test Suite
Contributing to the Conformance Test Suite
On the Boundaries of the Spec
JS Party episode covering error messages
On using JavaScript Proposals in Production
ASTs
Amal’s talk on ASTs for Refactoring
Esprima
Babel parser
Acorn
Dojo upgrade tool (using ASTs)
Awesome AST
Other
Bocoup
Something missing or broken? PRs welcome!