Linux Foundation Raises $10 Million to Expand Open Source Security Foundation
The Linux Foundation, a nonprofit organization dedicated to empowering open source innovation, has announced a significant investment of $10 million to support the Open Source Security Foundation (OpenSSF). This cross-industry collaboration aims to strengthen the security of open source software, develop improved tooling, and promote best practices for vulnerability disclosure. Brian Behlendorf, a renowned open source luminary, will serve as the General Manager of the OpenSSF community.
The OpenSSF has garnered significant support from Premier members, including tech giants such as Amazon, Cisco, Google, and Microsoft, as well as General members like Aiven and GitLab. This investment is crucial, given the alarming increase in software supply chain attacks, which have risen by 650 percent over the past year (Sonatype, 2021 State of the Software Supply Chain). As open source software makes up at least 70 percent of all software (Synopsys, 2020 Open Source Security and Risk Analysis Report), the OpenSSF serves as a vital platform for accelerating the security of the software supply chain.
The OpenSSF has been instrumental in developing various initiatives to enhance the security of open source software. Some notable examples include:
- **Security Scorecard**: A comprehensive tool for assessing software security through automated checks.
- **Best Practices Badge**: A set of core best practices for producing high-quality, secure software.
- **Security Policies**: Allstar's security policies help enforce security policies on repositories or organizations.
- **Framework**: Supply-chain levels for software artifacts (SLSA) provides a security framework for increasing levels of software supply chain integrity.
- **Training**: Free secure software development fundamentals courses educate community members on secure software development.
- **Vulnerability Disclosures**: A guide for coordinated vulnerability disclosure for OSS projects.
- **Package Analysis**: Look for malicious software in OSS packages.
- **Security Reviews**: Public collection of security reviews of OSS.
- **Research**: Studies on open source software and critical security vulnerabilities conducted in association with the Laboratory for Innovation Science at Harvard (LISH).
The OpenSSF's efforts are more crucial than ever, as the rise in software supply chain attacks and ransomware attacks tied to open source software has sparked calls for private and public collaboration. The OpenSSF provides a natural, neutral, and pan-industry forum to accelerate the hardening and security of the software supply chain.
Statistics:
- Software supply chain attacks have increased by 650 percent (Sonatype, 2021 State of the Software Supply Chain)
- Open source software makes up at least 70 percent of all software (Synopsys, 2020 Open Source Security and Risk Analysis Report)
- Premier members of the OpenSSF include Amazon, Cisco, Google, and Microsoft
- General members of the OpenSSF include Aiven, GitLab, and many others
Sources:
- Sonatype, 2021 State of the Software Supply Chain
- Synopsys, 2020 Open Source Security and Risk Analysis Report
- pivotalsources.com
- Syndigate.info