Google Pledges $1 Million to Secure Open Source Program
Google last week pledged $1 million in financial support to the Secure Open Source (SOS) rewards program run by the Linux Foundation.
Stay updated with breaking news from Open Source Security. Get real-time updates on events, politics, business, and more. Visit us for reliable news and exclusive interviews.
Google last week pledged $1 million in financial support to the Secure Open Source (SOS) rewards program run by the Linux Foundation.
The OSV schema aims to precisely describe vulnerabilities in a way tailored to the open source use case, "with the goal of automating and improving vulnerability triage for developers and users of open source software," Google stated in a blog post published on June 24. The project could allow various developer tools to natively handle vulnerability information and make it easier for users of open source components to know whether particular vulnerabilities affect their applications. The aim is to reduce the effort required to document vulnerabilities in open source projects, to make the is...
US Supreme Court Rules on Key Software Development Practice Each year for the annual Open Source Security and Risk Analysis report, the authors highlight key aspects around open source that you likely wouldn’t expect. In the 2020 edition, we gave some coverage to the Google LLC v Oracle America, Inc. case before the US Supreme Court. In case you missed it, Oracle sued Google over Google’s use of Java SE API signatures in Android. Android is open source, but a ruling against Google could have had ramifications for the entire development community – not jus...
2021 State of Open-Source Security Report 2021 State of Open-Source Security Report Open-source libraries help software developers meet aggressive deadlines. As a result, these libraries and their classes continue to proliferate and grow in complexityâincreasing the risk they pose while making it more difficult to secure modern applications. The 2021 State of Open-source Security Report uses telemetry from actual applications protected by Contrast OSS and Contrast Assess to reveal key trends about library usage, vulnerabilities, and best practices. Key findings include: While the average...
Contrast Security Study Exposes Significant Time and Resource Drain in Software Supply Chain Security 2021 State of Open-source Security Report From Contrast Labs Reveals That Less Than 10% of Application Code is Active Third-Party Library Code News provided by Share this article Share this article LOS ALTOS, Calif., April 8, 2021 /PRNewswire/ -- A new study by Contrast Security reveals that 62% of libraries found in applications are inactive — that is, are not used at all by the software. Additionally, in libraries that are active, 69% of library classes are not invoked by applications. V...