Google Created ‘Open-Source Maintenance Crew’ to Help Secure Critical Projects

News

Google on Thursday announced the creation of a new “Open Source Maintenance Crew” to focus on bolstering the security of critical open source projects.

Additionally, the tech giant pointed out Open Source Insights as a tool for analyzing packages and their dependency graphs, using it to determine “whether a vulnerability in a dependency might affect your code.”

“With this information, developers can understand how their software is put together and the consequences to changes in their dependencies,” the company said.

The development comes as security and trust in the open source software ecosystem has been increasingly thrown into question in the aftermath of a string of supply chain attacks designed to compromise developer workflows.

CyberSecurity

In December 2021, a critical flaw in the ubiquitous open source Log4j logging library left several companies scrambling to patch their systems against potential abuse.

The announcement also comes less than two weeks after the Open Source Security Foundation (OpenSSF) announced what’s called the Package Analysis project to carry out dynamic analysis of all packages uploaded to popular open source repositories.

Products You May Like

Articles You May Like

Akira Ransomware Group Rakes in $42m, 250 Organizations Impacted
Palo Alto Networks Discloses More Details on Critical PAN-OS Flaw Under Attack
Bitcoin scams, hacks and heists – and how to avoid them
US Imposes Visa Restrictions on Alleged Spyware Figures
Russia’s Sandworm Upgraded to APT44 by Google’s Mandiant

Leave a Reply

Your email address will not be published. Required fields are marked *