Open source software is the public infrastructure that powers modern everyday life, and four out of five developers will rely on curated open source technologies by 2025, according to Google Cloud VP of Infrastructure Eric Brewer.
Curated open source is focused on improving supply chain security with an additional level of accountability. Brewer wrote in a blog post that this is required "to run the applications that will power our future." He cited government regulations like the Federal Risk and Authorization Management Program (FedRAMP) and President Biden's Executive Order on Cybersecurity.
The concept of curated open source hinges on an individual or team of curators who vet packages of open source software to identify and remediate vulnerabilities. For example, curators update old dependencies, track new ones, and deploy automated testing that simplifies open source security.
Open source curation exists on a smaller scale today via packages tied to a supported version of Linux or paid versions of open source systems like Apache Spark. But right now "most of the packages we depend on are not curated," Brewer wrote. "Given the widespread risk, this will have to change."
To that point, he touted Google Cloud's Software Delivery Shield managed security service for its capability to protect an enterprise's software supply chain from source to deployment. The hyperscaler's Assured OSS curated open source package scans, analyzes, and fuzz-tests more than 500 open source packages in Java and Python for security vulnerabilities. The curation service then attempts to resolve any issues before making those software packages available to cloud developers.
Google Cloud's curated open source packages "enable organizations to benefit from the same end-to-security capabilities and practices that we apply to our own OSS portfolio at Google Cloud," Brewer noted. That open availability carves a pathway for developers to access the same software the hyperscaler has invested in and depends on for its own business, he added.
Comments