Linux Foundation Organization on the formation of a new joint project (Open Source Security Foundation), aimed at bringing together the efforts of leading industry players to enhance the security of open source software. OpenSSF will continue the development of initiatives such as and , and will also combine other security-related efforts undertaken by project participants.
The founders of OpenSSF include companies such as , , IBM, JPMorgan Chase, , NCC Group, OWASP Foundation, and Red Hat. Participants include GitLab, HackerOne, Intel, Uber, VMware, ElevenPaths, Okta, Purdue, SAFECode, StackHawk, and Trail of Bits.
It is noted that in the modern world, open source software is widely demanded in many areas of industry, but due to the specifics of its development, the security is influenced by chains of dependencies and developers involved. Therefore, verifying the security of open projects requires verification of not only the main code but also the dependencies, as well as identifying developers whose code is accepted into the project, and reliable authentication during reviews and commits. Additionally, ensuring security requires the use of secure build systems and build verification.
OpenSSF's work will focus on areas such as coordinated information about vulnerabilities and the dissemination of fixes, security tools, best practices for secure development organization, security-related threats in open source software, audit work and the strengthening of security for critically important open projects, creating means for verifying .
Source: opennet.ru
