Linux Foundation Raises $10 Million to Expand Open Source Security Foundation

The Linux Foundation, a nonprofit organization promoting open-source innovation, has raised $10 million in new investments to support the Open Source Security Foundation (OpenSSF), a cross-industry collaboration to identify and fix cybersecurity vulnerabilities in open source software. The OpenSSF will focus on developing improved tooling, training, research, best practices, and vulnerability disclosure practices. Brian Behlendorf, a well-known open-source luminary, will serve as the General Manager of the OpenSSF. The investment comes from leading companies such as Amazon, Cisco, Dell Technologies, Facebook, Google, IBM, and Microsoft, among others.

Key Takeaways:

  • The Linux Foundation has raised $10 million in new investments to expand and support the OpenSSF, a cross-industry collaboration to improve open-source software security.
  • The OpenSSF will focus on developing improved tooling, training, research, best practices, and vulnerability disclosure practices to address cybersecurity vulnerabilities in open-source software.
  • Brian Behlendorf, a renowned open-source luminary, will serve as the General Manager of the OpenSSF.
  • The investment comes from 23 companies, including Premier members like Amazon, Cisco, Dell Technologies, and Google, as well as General members such as Aiven, Anchore, and Apiiro.
  • The OpenSSF is home to a variety of open-source software, open standards, and other open content work for improving security, including the Security Scorecard, Best Practices Badge, Security Policies, Framework, Training, Vulnerability Disclosures, Package Analysis, Security Reviews, and Research.
  • According to industry reports, software supply chain attacks have increased 650% and are having a severe impact on business operations, highlighting the need for improved cybersecurity practices.
  • The OpenSSF offers a natural, neutral, and pan-industry forum to accelerate the hardening and security of the software supply chain, given open-source software makes up at least 70% of all software.

Statistics:

  • $10 million: the amount of new investments raised by the Linux Foundation to support the OpenSSF.
  • 650%: the increase in software supply chain attacks as reported in the 2021 State of the Software Supply Chain, by Sonatype.
  • 70%: the percentage of all software that is open source, as reported in the 2020 Open Source Security and Risk Analysis Report by Synopsys.
  • 23: the number of companies committed to supporting the OpenSSF, including Premier and General members.

Sources:

  • "The Linux Foundation Raises $10 Million to Expand Open Source Security Foundation" (Al Bawaba (Albawaba.com), 2021)
  • "2021 State of the Software Supply Chain" (Sonatype, 2021)
  • "2020 Open Source Security and Risk Analysis Report" (Synopsys, 2020)
  • https://openssf.org/