The tech world has had more than its fair share of interesting acronyms over the years and is now adding another one to the list – GUAC. No, this GUAC is not a tasty avocado-based dip for nachos. The graph for understanding artifact composition (GUAC) is all about improving software supply chain security.
GUAC is celebrating a major milestone today, joining the Linux Foundation's Open Source Security Foundation (OpenSSF) as an incubating project. GUAC actually got its start in October 2022 as an effort by Google, Kusari, Purdue University and Citi, with the first beta released in May 2023.
GUAC aggregates software security metadata from various sources into a high-fidelity graph database. With GUAC, users can recognize connections and compliance in a software catalog and potentially identify gaps in software supply chain data, and enable threat detection and response.
“GUAC provides an integrated method for organizations to understand their software supply chain across first-party, third-party and open-source components,” OpenSSF GM Omkhar Arasaratnam told SDxCentral.
How GUAC expands OpenSSF's tools for software securityThe OpenSSF is no stranger to the world of software security with multiple tools already part of its project roster.
Among the projects hosted by OpenSSF is the supply chain levels for software artifacts (SLSA) project, which also was originally created by Google. The OpenSSF has also been active in multiple software bill of materials (SBOM) efforts, including software package data exchange (SPDX), which is designed to provide an ingredients list of what is inside a given application.
GUAC will now add some new flavor to the mix.
“It is complementary to existing OpenSSF technologies,” Arasaratnam said. “GUAC can consume SPDX SBOMs, SLSA attestation or even scorecard information about project dependencies. It allows organizations to analyze their dependencies easily, leading to more secure software.”
As to why GUAC is now coming into the OpenSSF, he noted that GUAC adoption and maturity have increased significantly over the last year. Arasaratnam explained that all OpenSSF projects conform to a published project lifecycle.
How GUAC fits into the software supply chain landscapeThere are many challenges organizations face when it comes to securing the software supply chain. In recent years, there has been a race to enable SBOM capabilities as a way to help improve security, but that's not all that's needed.
“GUAC can be used to retrieve dependency and software composition information to generate SBOMs, but we believe it provides more value by taking that information and extracting additional insights through joining against additional data sets and performing graph analysis,” Bob Callaway, engineering manager at Google, told SDxCentral.
He added, “GUAC can be used to highlight fleet-wide risks and provide aggregated data to help organizations focus their investments on improving the security of their applications and dependencies.”
Michael Lieberman, cofounder and CTO at Kusari, noted that GUAC can do a lot of things, and it's on the roadmap to have GUAC generate new SBOMs out of data in GUAC, but it's not the primary use case.
“The primary use case is to take all sorts of metadata and documents across a project, department or organization's supply chain and be able to provide insights and answer questions about it,” Lieberman told SDxCentral.
For example, Lieberman said that GUAC an ingest SBOMs, SLSA attestations, VEX (Vulnerability Exploitability eXchange) statements, OSV vulnerability data and more to understand the connections between the data described in those documents, as well as to better understand the risks in the software supply chain.
The future of GUACWhile GUAC has lots of possibilities, it's still at the beta release stage.
Callaway noted that currently, GUAC is usable for experimentation and for users to understand their security posture or reacting to events. As the project moves forward, he said that GUAC is looking to create built-in dashboards with prioritized actionable items, which will help organizations bootstrap their journey in taking advantage of a software supply chain knowledge graph
“GUAC is aiming to reach its 1.0 release this year, and this will mark a level of API stability that allows integration with other components,” he said. “We believe these integrations will unlock the underlying potential of GUAC across a number of use cases.”
Comments