The OpenSSF project has been established, focused on enhancing the security of open source software

Linux Foundation Organization announced on the formation of a new joint project OpenSSF (Open Source Security Foundation), aimed at bringing together the efforts of leading industry players to enhance the security of open source software. OpenSSF will continue the development of initiatives such as Infrastructure Initiative and Open Source Security Coalition, and will also combine other security-related efforts undertaken by project participants.

The founders of OpenSSF include companies such as GitHub, Google, IBM, JPMorgan Chase, by Microsoft, NCC Group, OWASP Foundation, and Red Hat. Participants include GitLab, HackerOne, Intel, Uber, VMware, ElevenPaths, Okta, Purdue, SAFECode, StackHawk, and Trail of Bits.

It is noted that in the modern world, open source software is widely demanded in many areas of industry, but due to the specifics of its development, the security is influenced by chains of dependencies and developers involved. Therefore, verifying the security of open projects requires verification of not only the main code but also the dependencies, as well as identifying developers whose code is accepted into the project, and reliable authentication during reviews and commits. Additionally, ensuring security requires the use of secure build systems and build verification.

OpenSSF's work will focus on areas such as coordinated disclosure information about vulnerabilities and the dissemination of fixes, development security tools, publication best practices for secure development organization, the discovery of security-related threats in open source software, conducting audit work and the strengthening of security for critically important open projects, creating means for verifying developers' identities.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster