The Alpha-Omega initiative aimed at enhancing the security of 10,000 open projects

The OpenSSF (Open Source Security Foundation) has presented the Alpha-Omega project aimed at enhancing the security of open-source software. Initial investment of $5 million and personnel to launch the initiative will be provided by Google and Microsoft. Other organizations are also invited to participate, either by providing engineering staff or funding, which will help expand the number of open projects that the initiative will cover. Additionally, at the end of last year, $10 million was allocated to the OpenSSF fund, but it remains unclear whether these funds will be used for the Alpha-Omega initiative.

The Alpha-Omega project consists of two components:

  • The Alpha component involves conducting a manual security audit of 200 widely used open projects, particularly those that are popular as dependencies or as parts of infrastructure. The work will be carried out in collaboration with maintainers and will include a systematic code analysis to identify new vulnerabilities and address them promptly.
  • The Omega component focuses on conducting automated testing of the 10,000 most popular open projects. A dedicated team of engineers will be created to carry out testing, improve the methods used, analyze the results, communicate findings to project developers, and coordinate collaborative efforts to address critical issues. The main task of this team will be to filter out false positives and identify real vulnerabilities in automated reports.

The necessity for a manual audit in the Alpha phase is due to the need to uncover hidden problems that are challenging to detect through automated testing. Recent critical vulnerabilities in Log4j, which threatened the infrastructure of many major companies, are cited as examples of such issues. Projects for the audit will be selected based on recommendations from the expert community and data from previously established ratings such as Critically Score and Census.

It is worth noting that the OpenSSF Fund was created under the auspices of the Linux Foundation and focuses on areas such as coordinated vulnerability disclosure, patch distribution, the development of security tools, the publication of best practices for secure software development, the identification of security-related threats in open-source software, conducting audits, and enhancing the security of critically important open projects, as well as creating means for verifying developer identities. OpenSSF continues to develop initiatives such as the Core Infrastructure Initiative and the Open Source Security Coalition, and combines various other related security efforts undertaken by participating companies. Founding members of OpenSSF include Google, Microsoft, Amazon, Cisco, Dell Technologies, Ericsson, Facebook, Fidelity, GitHub, IBM, Intel, JPMorgan Chase, Morgan Stanley, Oracle, Red Hat, Snyk, and VMware.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster