Google Cloud is looking to make open source code safer than ever

Hands typing on a keyboard surrounded by security icons
(Image credit: Shutterstock)

Google Cloud has announced a new open source software security tool as it aims to improve safety among software supply chains.

The new Assured Open Source Software (OSS) looks to enable enterprise and public sector users of open source software to incorporate the same security packages that Google uses into its own developer workflows. 

Software supply chains, which often rely on open source code to stay flexible and customizable, have become popular targets for cyberattacks as hackers look to target industries of all kinds.

What’s behind the move?

The move comes after numerous high profile open source security incidents, including vulnerabilities related to Log4j and Spring4shell.

Google joined the OpenSSF and the Linux Foundation for a meeting to advance the open source software security initiatives discussed during the recent White House Summit on Open Source Security.

Google says that the packages curated by the Assured OSS service will be regularly scanned, analyzed, and fuzz-tested for vulnerabilities and will have corresponding enriched metadata that incorporates Google’s Container/Artifact Analysis data.

All packages included in the new tool will be built with Google’s Cloud Build and will include evidence of verifiable SLSA-compliance.

The packages will be distributed from an Artifact Registry secured and protected by Google, with Assured OSS is expected to enter preview in Q3 2022.

Google highlighted that it continuously scans 550 of the most commonly-used open source projects, and says that it has found more than 36,000 vulnerabilities as of January 2022.

In addition, Google also announced a partnership with Israeli developer security platform SNYK that means Assured OSS will be natively integrated into Snyk solutions for joint customers to use wherever they are developing code.

In addition, the partnership also means that Snyk vulnerabilities, triggering actions, and remediation recommendations will become available to joint customers within the Google Cloud security and software development life cycle.

Security issues haven’t stopped open source software attracting interest from developers everywhere.

A poll of application developers by Instacluster found that 45% of respondents acknowledge the potential of open source software in terms of cutting down costs, while 38% acknowledge its potential in terms of being able to port code more easily.

TOPICS

Will McCurdy has been writing about technology for over five years. He has a wide range of specialities including cybersecurity, fintech, cryptocurrencies, blockchain, cloud computing, payments, artificial intelligence, retail technology, and venture capital investment. He has previously written for AltFi, FStech, Retail Systems, and National Technology News and is an experienced podcast and webinar host, as well as an avid long-form feature writer.

Read more
A hand reaching out to touch a futuristic rendering of an AI processor.
Google Cloud unveils new AI Protection security tools, no matter which model you use
Holographic representation of cloud computing over open businessman's hand
Businesses are struggling to address vulnerabilities hidden in phantom dependencies
Security
Removing software supply chain blind spots that put public sector organizations at risk
A developer writing code
Open source software is now a multi-billion dollar industry
Hacking warning on a computer screen.
Open source machine learning systems are highly vulnerable to security threats
Shadowed hands on a digital background reaching for a login prompt.
A flaw in Google OAuth system is exposing millions of users via abandoned accounts
Latest in Pro
cybersecurity
What's the right type of web hosting for me?
Security padlock and circuit board to protect data
Trust in digital services around the world sees a massive drop as security worries continue
Hacker silhouette working on a laptop with North Korean flag on the background
North Korea unveils new military unit targeting AI attacks
An image of network security icons for a network encircling a digital blue earth.
US government warns agencies to make sure their backups are safe from NAKIVO security issue
Laptop computer displaying logo of WordPress, a free and open-source content management system (CMS)
This top WordPress plugin could be hiding a worrying security flaw, so be on your guard
construction
Building in the digital age: why construction’s future depends on scaling jobsite intelligence
Latest in News
L-mount alliance
Sirui joins L-Mount Alliance to deliver its superb budget lenses for Leica, DJI, Sigma and Panasonic cameras
Security padlock and circuit board to protect data
Trust in digital services around the world sees a massive drop as security worries continue
Samuel and Romy standing very close together in A24's Babygirl movie
Everything new on Max in April 2025, including A24's Babygirl and The Last of Us season 2
An AMD Radeon RX 9070 XT made by Sapphire on a table with its retail packaging
AMD’s secret weapon against Nvidia seems to be stock – way more RX 9070 GPUs are rumored to be hitting shelves than RTX 5000 models
Hacker silhouette working on a laptop with North Korean flag on the background
North Korea unveils new military unit targeting AI attacks
Seth Milchick and Kier Eagan's animatronic speaking in Severance season 2 episode 10
Apple TV+ announces Severance has been renewed for season 3 after that devastating finale