The OpenSSF project is established, focused on improving the security of open source software

Linux Foundation Organization announced on the formation of a new joint project OpenSSF (Open Source Security Foundation), designed to unite the work of leading industry representatives in the field of improving the security of open source software. OpenSSF will continue to develop initiatives such as Infrastructure Initiative ΠΈ Open Source Security Coalition, as well as integrate other safety-related work undertaken by the project participants.

The founding members of OpenSSF include companies such as GitHub, Google, IBM, JPMorgan Chase, Microsoft, NCC Group, OWASP Foundation and Red Hat. GitLab, HackerOne, Intel, Uber, VMware, ElevenPaths, Okta, Purdue, SAFECode, StackHawk, and Trail of Bits have joined as members.

It is noted that in the modern world, open source software is widely in demand in many areas of the industry, but due to the specifics of development, its security is influenced by a chain of dependencies and development participants. Therefore, to confirm the security of open projects, it is important to verify not only the main code, but also dependencies, as well as the identification of developers whose code is accepted into the project, and reliable authentication during reviews and commits. In addition, security requires the use of secure assembly systems and assembly verification.

OpenSSF's work will focus on areas such as coordinated disclosure information about vulnerabilities and distribution of patches, development security tools, publication best practices for secure organization of development, revealing security-related threats in open source software, holding work on auditing and strengthening the security of critical open projects, creating tools for checking developer identities.

Source: opennet.ru

Add a comment