Red Hat is expanding it capabilities targeted at open source software supply chain security in a move to “provide organizations increased resilience to vulnerabilities across every stage of their software development lifecycle,” Red Hat VP and GM for cloud services Sarwar Raza told a group of reporters ahead of Red Hat Summit.

A majority of enterprise applications depend on hundreds of open source projects, but that software exists in a world with few guardrails – and open source software vulnerability exploits are on the rise. “Something's not quite right here,” Raza pointed out.

Within Red Hat, however, the vendor has developed processes, technologies and best practices for “making sure the open source bits are safe to consume. . . . We can tell you where they've been [and] where they've come from” because “we build them ourselves,” he said, touting the company's 30-year history of offering secure hardware and open source software.

To that point, Red Hat's Trusted Software Supply Chain services, which include a trusted Application continuous integration/continuous delivery (ci/cd) pipeline and a verified packages library, “provide customers with assurance that the bits they're deploying are, in fact, safe and secure,” Raza explained. “And if a vulnerability does show up later on, we can point them to the best sources of content, remediation and intelligence to fix those issues,” he added.

Red Hat Trusted Content, while not technically considered a repository, is built on the foundation of Red Hat's “security-enhanced system software” that's already available through the vendor's other Application development offerings.

The Trusted Content service does recommend “the trusted content we build, ... but the other leg of that stool is really the knowledge about the open source packages that are in that trusted content stream,” he noted. For each piece of content in its library, for example, Red Hat provides software bill of materials (SBOMs) and provenance information that helps meet audit and regulatory requirements.

“We're basically making explicit the proof points of trust for all of the content, which is thousands and thousands and thousands of open source packages that you can get from Red Hat,” Raza said.

Building a software supply chain of custody

Since not all bits of open source code originate from Red Hat, the vendor aims to provide a “chain of custody” for that software to ensure its security.

The supply chain of custody should be created “with respect to when we built it, where we built it and you can then use that information – which is stored in an immutable ledger using a technology called Sigstore that was developed at Red Hat – to make sure the bits did not change in transit or that the bits were not tampered with,” he explained.

The Sigstore secure cloud-native signing framework allows Red Hat to look at the information and metadata associated with a certain software package's security knowledge, and “that starts to form the basis of knowing where the bits came from,” Raza said. But there's also “rocket science, crazy math, even [artificial intelligence (AI)] and [machine learning (ML)] in the background to make sense of the data,” he added.

Even though Red Hat's Insights product “already does this,” Raza noted, “extending that over now to a broader set of open source packages is natural for us.”

The next step is Red Hat's trusted Application platform, which makes the vendor's internally developed knowledge and tools available to customers. “Now you, as a customer, can build your own software to a specific Enterprise contract, generate SBOMs” and “provide provenance information to your customers about the software you just built in the same way we do,” Raza explained.

These moves take advantage of “what we do great, which is taking the best of open source innovation,” curating a package, and making it usable for enterprises. “In this case, we're tackling the secure CI/CD space along with the content space to round this out,” he noted.