Open source software should soon be more secure than ever

(Image credit: Shutterstock / fatmawati achmad zaenuri)

The Linux Foundation has launched a new collaborative project designed to address security vulnerabilities in open source software, bringing together some of the most influential players in technology.

The Open Source Security Foundation (OpenSSF) will see founding members - including Microsoft, Github, Google, IBM, Red Hat and JPMorgan - combine resources to tackle various security challenges specific to the open source ecosystem.

The new entity will fold together a few different overlapping initiatives, including the Open Source Security Coalition (OSSC) and the Core Infrastructure Initiative (CII), which will now operate under the umbrella of the OpenSSF.

The CII already enjoys the backing of AWS, Cisco, Qualcomm, Intel and more (on top of the support of founding members of the OpenSSF). The main difference, under the new model, is that the project will not rely exclusively on grants, but will also be funded in part by Linux Foundation membership subs.

Open source software security

According to Mark Russinovich, Microsoft Azure CTO, the new project will allow its members to better navigate the security considerations unique to the open source ecosystem.

“Open source software is inherently community-driven and as such, there is no central authority responsible for quality and maintenance. Because open source code can be copied and cloned, versioning and dependencies are particularly complex,” he wrote in a blog post.

“Open source software is also vulnerable to attacks against the very nature of the community, such as attackers becoming maintainers of projects and introducing malware. Given the complexity and communal nature of open source software, building better security must also be a community-driven process.”

In light of this complexity, the new initiative is split into five working groups, each of which is responsible for a distinct aspect of open source security:

  • Vulnerability disclosures
  • Security tooling
  • Identifying threats to open source projects
  • Security best practices
  • Securing critical projects

Operating underneath the governing board of the new foundation, there exists a technical advisory committee and separate technical committees that oversee each working group.

The overarching hope is that, by consolidating various disparate projects and pooling resources, the OpenSSF will be able to address issues with open source security that could not otherwise be resolved.

Via The Register

TOPICS
Joel Khalili
News and Features Editor

Joel Khalili is the News and Features Editor at TechRadar Pro, covering cybersecurity, data privacy, cloud, AI, blockchain, internet infrastructure, 5G, data storage and computing. He's responsible for curating our news content, as well as commissioning and producing features on the technologies that are transforming the way the world does business.

Latest in Security
Hacker silhouette working on a laptop with North Korean flag on the background
North Korea unveils new military unit targeting AI attacks
An image of network security icons for a network encircling a digital blue earth.
US government warns agencies to make sure their backups are safe from NAKIVO security issue
Laptop computer displaying logo of WordPress, a free and open-source content management system (CMS)
This top WordPress plugin could be hiding a worrying security flaw, so be on your guard
Computer Hacked, System Error, Virus, Cyber attack, Malware Concept. Danger Symbol
Veeam urges users to patch security issues which could allow backup hacks
UK Prime Minister Sir Kier Starmer
The UK releases timeline for migration to post-quantum cryptography
Representational image depecting cybersecurity protection
Cisco smart licensing system sees critical security flaws exploited
Latest in News
Quordle on a smartphone held in a hand
Quordle hints and answers for Sunday, March 23 (game #1154)
NYT Strands homescreen on a mobile phone screen, on a light blue background
NYT Strands hints and answers for Sunday, March 23 (game #385)
NYT Connections homescreen on a phone, on a purple background
NYT Connections hints and answers for Sunday, March 23 (game #651)
Google Pixel 9 Pro Fold main display opened
Apple is rumored to be prioritizing battery life on the foldable iPhone – which could also feature a liquid metal hinge for added durability
Google Pixel 9
The Google Pixel 10 just showed up in Android code – and may come with a useful speed boost
L-mount alliance
Sirui joins L-Mount Alliance to deliver its superb budget lenses for Leica, DJI, Sigma and Panasonic cameras