Priorities from the OpenSSF Secure Open Source Software Summit 2023

Artikel von:
Dan Appelquist
wordpress-sync/feature-open-source

October 4, 2023

0 Min. Lesezeit

Snyk has been a long-time active participant in and sponsor of the Open Source Security Foundation (OpenSSF). We’re there because we believe in supporting its mission of securing the open source ecosystem.

A recent summit meeting convened by the OpenSSF with the White House brought together various US Government departments for a chat about open source security. The background here is that the US government understands the importance of securing the open source ecosystem, because they understand that “open-source software is a critical tool used to shift power towards the stewards of democracy and demonstrate our values,” as Kemba Walden, acting National Cyber Director for the White House put it. 

The top three priorities that came out of this summit meeting were:

  1. Providing Security Education to OSS Maintainers, Contributors, and Consumers

  2. Securing OSS Repositories

  3. Enabling Cross-Industry OSS Incident Response (IR) Capabilities

I’ve been working, along side other OpenSSF members, to help publish a set of guidelines to help address point two on this list: Securing OSS Repositories.

SCM platforms are used for developer collaboration, community engagement, and as a part of the build and release process for many key open source software components and tools. It’s no wonder that SCM repositories would emerge from this discussion as one of the key leverage points for making open source software more secure.

The Source Code Management Best Practices Guide, launched earlier this month, gives developers, maintainers, and organizations that make use of the GitHub and GitLab SCM platforms a set of clear guidelines on how to set up and maintain security. Used together with OpenSSF Scorecard, this gives developers a comprehensive checklist and gives organizations that manage multiple open source repositories with some guidance on how they can set up permissions, workflows and policies for better security.

It’s been great collaborating with the co-leads on this work, Christine Abernathy from F5 and Noam Dotan from Legit Security. And we’re not done. This is the first release of these guidelines. We’re looking forward to incorporating additional SCM platforms and incorporating community feedback, since the guide itself is, of course, managed in an open source repository.

For more info on what’s going on in the OpenSSF, follow @openssf@social.lfx.dev on Mastodon.

Patch Logo SegmentPatch Logo SegmentPatch Logo SegmentPatch Logo SegmentPatch Logo SegmentPatch Logo SegmentPatch Logo SegmentPatch Logo SegmentPatch Logo SegmentPatch Logo SegmentPatch Logo SegmentPatch Logo SegmentPatch Logo Segment

Snyk ist eine Developer Security Plattform. Integrieren Sie Snyk in Ihre Tools, Workflows und Pipelines im Dev-Prozess – und Ihre Teams identifizieren, priorisieren und beheben Schwachstellen in Code, Abhängigkeiten, Containern, Cloud-Ressourcen und IaC nahtlos. Snyk bringt branchenführende Application & Security Intelligence in jede IDE.

Kostenlos startenLive-Demo buchen

© 2024 Snyk Limited
Alle Rechte vorbehalten

logo-devseccon