The most seamless way to upgrade the security of open source software is for security vendors to assume responsibility for intelligent security tooling, according to a new report from Snyk and The Linux Foundation.
The report, which surveyed contributors, maintainers, and developers of open source software, found 59% of individuals agree vendors need to "add increased intelligence to, and to be responsible for, security tooling" to improve the state of open source security more broadly.
End-user organizations see the vendor community as a "force multiplier," rendering this scenario a win-win for practitioners and vendors alike. Increasingly automated and intelligent security tools will, in exchange for licensing fees, lessen the burden on security professionals in a competitive market, the report explains.
Alternatively, this finding can be interpreted as end-user organizations recognizing their lack of ability to address security issues and welcoming the expertise of vendors and service providers.
And for organizations that typically have scarce resources, intelligent open source security tools are expected to offer value in a transparent way without impacting developer productivity, according to the report.
Identify Security Certifications, Best PracticesThe second most important action to improve the state of open source security is to gather comprehensive best practices and certifications for secure software development.
"The strong interest by end-user organizations in best practices for secure software development is exciting to see," the report reads. This indicates greater organizational investment in fully addressing open source security.
Many programs, certifications, and best practices for evaluating open source projects already exist, like Google’s Supply chain Levels for Software Artifacts (SLSA) project and the Open Source Security Foundation (OpenSSF) Best Practices badge and Scorecards project. The OpenSSF also offers courses on developing secure software with certification for individuals who successfully complete training.
Open Source Automation and AuditsThe third most popular way survey respondents say they can improve open source security was a tie between increasing security automation and security audits, both cited by 49% of organizations.
With automation tools like infrastructure-as-code (IaC) and policy-as-code (PaC), machines interpret a security policy the same way each time, allowing for continuous evaluation of cloud infrastructure on a larger scale “than any army of humans could ever hope to do,” Snyk's Chief Architect Josh Stella said in an earlier interview.
Security audits are another impactful way for organizations to evaluate their security stature, but maintainers valued audits less highly than other survey respondents.
"While security audits can be invaluable at comprehensively assessing an organization’s security risks, the organization must be positioned to act upon the findings of that audit — which seems a bridge too far for organizations without a security policy," the report explained. More than 40% of organizations said they do not have confidence in their open source security, according to the report.
Comments