{"id":67477,"date":"2022-09-26T09:01:35","date_gmt":"2022-09-26T09:01:35","guid":{"rendered":"https:\/\/www.cryptocabaret.com\/?p=67477"},"modified":"2022-09-26T09:01:35","modified_gmt":"2022-09-26T09:01:35","slug":"openssf-on-a-mission-to-improve-security-of-open-source-software","status":"publish","type":"post","link":"https:\/\/www.cryptocabaret.com\/?p=67477","title":{"rendered":"OpenSSF: on a mission to improve security of open source software"},"content":{"rendered":"<p><span class=\"field field--name-title field--type-string field--label-hidden\">OpenSSF: on a mission to improve security of open source software<\/span><br \/>\n<span class=\"field field--name-uid field--type-entity-reference field--label-hidden\"><a title=\"View user profile.\" href=\"https:\/\/opensource.com\/users\/gkamathe\" class=\"username\">Gaurav Kamathe<\/a><\/span><br \/>\n<span class=\"field field--name-created field--type-created field--label-hidden\">Mon, 09\/26\/2022 &#8211; 03:00<\/span><\/p>\n<div class=\"clearfix text-formatted field field--name-body field--type-text-with-summary field--label-hidden field__item\">\n<p>Open source software (OSS), once a niche segment of the development landscape, is now ubiquitous. This growth is fantastic for the open source community. However, as the usage of OSS increases, so do concerns about security. Especially in mission-critical applications\u2014 think medical devices, automobiles, space flight, and nuclear facilities\u2014securing open source technology is of the utmost priority. No individual entity, whether developers, organizations, or governments, can single-handedly solve this problem. The best outcome is possible when all of them come together to collaborate.<\/p>\n<p>The <a href=\"https:\/\/openssf.org\/\" target=\"_blank\" rel=\"noopener\">Open Source Security Foundation<\/a> (OpenSSF) formed to facilitate this collaboration. OpenSSF is best described in its own words:<\/p>\n<blockquote>\n<p>The OpenSSF is a cross-industry collaboration that brings together leaders to improve the security of open source software by building a broader community with targeted initiatives and best practices.<\/p>\n<\/blockquote>\n<h2>Vision<\/h2>\n<p>The technical vision of OpenSSF is to handle security proactively, by default. Developers are rightly at the center of this vision. OpenSSF seeks to empower developers to learn secure development practices and automatically receive guidance on them through the day-to-day tools they use. Researchers who identify security issues can send this information backward through the supply chain to someone who can rapidly address the issue. Auditors and regulators are encouraged to devise security policies that can be easily enforced via tooling, and community members provide information on the components they use and test regularly.<\/p>\n<h2>Mobilization plan<\/h2>\n<p>OpenSSF drafted a mobilization plan based on input from open source developers and leaders from US federal agencies. The result is a set of high-impact actions aimed at improving the resiliency and security of open source software. Based on this plan, 10 streams of investments have been identified, including security education, risk assessment, memory safety, and supply chain improvement. While discussion of these issues is widespread, OpenSSF is the platform that has collected and prioritized these concerns over others to ensure a secure open source ecosystem.<\/p>\n<h2>Working groups<\/h2>\n<p>Because the 10 streams of investments are quite diverse, OpenSSF is divided into multiple working groups. This strategy allows individual teams to focus on a specific area of expertise and move forward without getting bogged down with more general concerns. The working groups have something for everyone: Developers can contribute to security tooling, maintainers can handle software repositories, and others can contribute by educating developers on best practices, identifying metrics for open source projects, or identifying and securing the critical projects that form the core of the OSS ecosystem.<\/p>\n<\/p>\n<div class=\"embedded-resource-list callout-float-right\">\n<div class=\"field field--name-title field--type-string field--label-hidden field__item\">More on security<\/div>\n<div class=\"field field--name-links field--type-link field--label-hidden field__items\">\n<div class=\"field__item\"><a href=\"https:\/\/developers.redhat.com\/articles\/defensive-coding-guide\/?intcmp=7016000000127cYAAQ\">The defensive coding guide<\/a><\/div>\n<div class=\"field__item\"><a href=\"https:\/\/www.redhat.com\/en\/resources\/container-security-openshift-cloud-devops-whitepaper?intcmp=7016000000127cYAAQ\">10 layers of Linux container security<\/a><\/div>\n<div class=\"field__item\"><a href=\"https:\/\/developers.redhat.com\/books\/selinux-coloring-book?intcmp=7016000000127cYAAQ\">SELinux coloring book<\/a><\/div>\n<div class=\"field__item\"><a href=\"https:\/\/opensource.com\/tags\/security?intcmp=7016000000127cYAAQ\">More security articles<\/a><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<h2>Industry participation<\/h2>\n<p>Multiple software vendors have become members of OpenSSF in their own capacity. These vendors are important players in the IT ecosystem, ranging from cloud service providers and operating system vendors to companies hosting OSS repositories, creating security tooling, creating computing hardware, and more. The benefit is getting inputs from a variety of sources that others might not be aware of and then collaboratively working on those issues.<\/p>\n<h2>Getting involved<\/h2>\n<p>There are a variety of ways to participate in the OpenSSF initiative based on your expertise and the amount of time you can set aside for it:<\/p>\n<ul>\n<li>Sign up for their <a href=\"https:\/\/lists.openssf.org\/g\/openssf-announcements\/\" target=\"_blank\" rel=\"noopener\">mailing list<\/a> to follow the latest updates and discussions and update your calendar with OpenSSF meetings.<\/li>\n<li>If you are looking for more interactive communication, consider joining their <a href=\"https:\/\/slack.openssf.org\/\" target=\"_blank\" rel=\"noopener\">Slack channel<\/a>.<\/li>\n<li>Browse through their past meetings on their <a href=\"https:\/\/www.youtube.com\/c\/OpenSSF\/videos\" target=\"_blank\" rel=\"noopener\">YouTube channel<\/a>.<\/li>\n<li>Organizations can consider becoming a <a href=\"https:\/\/openssf.org\/join\/\" target=\"_blank\" rel=\"noopener\">member<\/a> of OpenSSF.<\/li>\n<li>Developers can quickly look up the <a href=\"https:\/\/github.com\/orgs\/ossf\/repositories\" target=\"_blank\" rel=\"noopener\">GitHub repo<\/a> for the software projects they are working on.<\/li>\n<li>Most important, consider joining a working group of your choice and make a difference.<\/li>\n<\/ul>\n<h2>Conclusion<\/h2>\n<p>The security industry is growing and needs active participation from the open source community. If you are starting out or wish to specialize in security, OpenSSF provides a platform to work on the right problems in the security space under the guidance of experienced peers in security.<\/p>\n<\/div>\n<div class=\"clearfix text-formatted field field--name-field-article-subhead field--type-text-long field--label-hidden field__item\">\n<p>Developers, businesses, and government agencies are working together to ensure the security of open source software, and you can join them.<\/p>\n<\/div>\n<div class=\"field field--name-field-lead-image field--type-entity-reference field--label-hidden field__item\">\n<article class=\"media media--type-image media--view-mode-caption\">\n<div class=\"field field--name-field-media-image field--type-image field--label-hidden field__item\">  <img decoding=\"async\" loading=\"lazy\" src=\"https:\/\/www.cryptocabaret.com\/wp-content\/uploads\/2022\/09\/security-lock-cloud-safe.png\" width=\"520\" height=\"292\" alt=\"lock on world map\" title=\"lock on world map\"><\/div>\n<div class=\"field field--name-field-caption field--type-text-long field--label-hidden caption field__item\"><span class=\"caption__byline\">Image by: <\/span><\/p>\n<p><a href=\"https:\/\/pixabay.com\/en\/safety-encryption-ssl-world-2890768\/\" target=\"_blank\" rel=\"ugc noopener\">Tumisu<\/a>. <a href=\"https:\/\/creativecommons.org\/share-your-work\/public-domain\/cc0\/\" target=\"_blank\" rel=\"ugc noopener\">CC0<\/a><\/p>\n<\/div>\n<\/article>\n<\/div>\n<div class=\"field field--name-field-tags field--type-entity-reference field--label-hidden field__items\">\n<div class=\"field__item\"><a href=\"https:\/\/opensource.com\/tags\/security\" hreflang=\"en\">Security and privacy<\/a><\/div>\n<\/p><\/div>\n<div class=\"hidden field field--name-field-listicle-title field--type-string field--label-hidden field__item\">What to read next<\/div>\n<div class=\"field field--name-field-default-license field--type-list-string field--label-hidden field__item\"><a rel=\"license\" href=\"http:\/\/creativecommons.org\/licenses\/by-sa\/4.0\/\"><br \/>\n        <img decoding=\"async\" alt=\"Creative Commons License\" src=\"https:\/\/www.cryptocabaret.com\/wp-content\/uploads\/2022\/09\/cc-by-sa--34.png\" title=\"This work is licensed under a Creative Commons Attribution-Share Alike 4.0 International License.\"><\/a>This work is licensed under a Creative Commons Attribution-Share Alike 4.0 International License.<\/div>\n<section class=\"field field--name-field-comments field--type-comment field--label-hidden comment-wrapper\">\n<div class=\"comments__count\">\n<div class=\"login\"><a href=\"https:\/\/opensource.com\/user\/register?absolute=1\">Register<\/a> or <a href=\"https:\/\/opensource.com\/user\/login?current=\/rss.xml&amp;absolute=1\">Login<\/a> to post a comment.<\/div>\n<\/p><\/div>\n<\/section>\n<p class=\"wpematico_credit\"><small>Powered by <a href=\"http:\/\/www.wpematico.com\" target=\"_blank\" rel=\"noopener\">WPeMatico<\/a><\/small><\/p>\n","protected":false},"excerpt":{"rendered":"<p>OpenSSF: on a mission to improve security of open source software Gaurav Kamathe Mon, 09\/26\/2022 &#8211; 03:00 Open source software (OSS), once a niche segment of the development landscape, is now ubiquitous. This growth is fantastic for the open source community. However, as the usage of OSS increases, so do concerns about security. Especially in [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":67478,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[307],"tags":[],"class_list":["post-67477","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-open-source"],"_links":{"self":[{"href":"https:\/\/www.cryptocabaret.com\/index.php?rest_route=\/wp\/v2\/posts\/67477","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.cryptocabaret.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.cryptocabaret.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.cryptocabaret.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.cryptocabaret.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=67477"}],"version-history":[{"count":0,"href":"https:\/\/www.cryptocabaret.com\/index.php?rest_route=\/wp\/v2\/posts\/67477\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.cryptocabaret.com\/index.php?rest_route=\/wp\/v2\/media\/67478"}],"wp:attachment":[{"href":"https:\/\/www.cryptocabaret.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=67477"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.cryptocabaret.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=67477"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.cryptocabaret.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=67477"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}