• Cryptocurrency
  • Earnings
  • Enterprise
  • About TechBooky
  • Submit Article
  • Advertise Here
  • Contact Us
TechBooky
  • African
  • AI
  • Metaverse
  • Gadgets
Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
  • African
  • AI
  • Metaverse
  • Gadgets
Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
TechBooky
Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
Home Cloud

Google To Start Distributing Secured Open-Source Software Libraries

Olagoke Ajibola by Olagoke Ajibola
May 17, 2022
in Cloud, Enterprise
Share on FacebookShare on Twitter

Is The Use of Open Source Software Putting Your Business at Risk? | Global IP & Technology Law Blog

Today, Google launches a new security feature. The new initiative is aimed at securing the open-source software supply chain by curating and distributing a security-vetted collection of open-source packages to Google Cloud customers. 

The new service introduced in a blog post has been branded Assured Open Source Software. In the blog post, Andy Chang, group product manager for security and privacy at Google Cloud, highlighted some of the challenges faced by securing open-source software and also stressed Google’s continuous commitment to securing open source.

In the blog post, Chang wrote that “There has been an increasing awareness in the developer community, enterprises, and governments of software supply chain risks.” Chang cites a major vulnerability – log4j from last year as an example. He further wrote that “Google continues to be one of the largest maintainers, contributors, and users of open source and is deeply involved in helping make the open-source software ecosystem more secure.”

Google has disclosed that the Assured Open Source Software service will give enterprises and government users access to the same vetted open-source packages that Google itself uses in its projects. According to the company, these packages are regularly scanned, analyzed, and fuzz-tested for vulnerabilities and built with Google Cloud’s Cloud Build service with evidence of SLSA-compliance (that’s ‘Supply-chain Levels for Software Artifacts,’ a framework for safeguarding artifact integrity across software supply chains). 

A list of the 550 major open-source libraries reviewed by Google is available on GitHub, the list will continue to be reviewed. While these libraries can all be downloaded independently, the Assured OSS program will see to the distribution of audited versions through Google Cloud — to mitigate incidents where developers intentionally or unintentionally corrupt widely used open-source libraries. At the moment, this service remains in the early access mode and is expected to be available to a wider customer range for testing by Q3 2022.

The new service announcement comes at a time when there is a wide industry drive to see to the improvement of the security of the open-source software supply chain. This drive has also enjoyed the support of the Biden administration.

Earlier in the year 2022, a handful of the nation’s largest tech companies held a meeting with representatives of the US federal agencies, this includes the Department of Homeland Security and the Cybersecurity and Infrastructure Security Agency. The meeting focused on a discussion around open-source software security in the wake of the log4j bug. A recent meeting of the companies involved also resulted in a pledge of more than $30 million in funding to boost open-source software security. Asides from the provision of funds, Google has also committed to putting engineering hours to work towards ensuring the supply chain is secure. Google recently announced the formation of an “Open Source Maintenance Crew” that would work with the maintainers of popular libraries for improved security.

Related Posts:

  • New-lock-tech-security-303570139
    Open Source Security Needs Automation As Usage Increases
  • OUXSPAPPUVK27H6RHKQWKLT4VI
    OpenAI Is Developing A New Language Model Open Source AI
  • google-intel-confidential-computing-more-s.max-2000×2000
    Google Cloud Reported More Than 10 Bugs On Intel’s…
  • Circle-droid_1@2x
    Google Develops Android OS Privately Amid Strategy Shift
  • images (2)
    The Untold Story of WordPress and WP Engine's Clash
  • meta-and-spotify-ceos-unite-against-eu-ai-data-restrictions
    CEOs of Meta and Spotify Lament Over AI Regulations…
  • what-is-supply-chain-iot
    The Effects of IOT on Supply Chains
  • Google Is Developing The Play Store Security System To Purge Bots.
    Google Is Developing The Play Store Security System…

Discover more from TechBooky

Subscribe to get the latest posts sent to your email.

Tags: businessChainenterprisegoogleOpenopen-sourceSecuresecurityServicesoftwaresourceSupply
Olagoke Ajibola

Olagoke Ajibola

Olagoke Ajibola is a creative writer and content producer with an eye for details and excellence. He has a demonstrated history of telling stories for TV, Film and Online. Aside from being fascinated by the power of imagination, his other interest are travel, sport, reading and meeting people.

BROWSE BY CATEGORIES

Select Category

    Receive top tech news directly in your inbox

    subscription from
    Loading

    Freshly Squeezed

    • Microsoft Reveals Rejected Start Menu Redesigns May 13, 2025
    • SeerBit & Spectranet Launch ExpressPay for Internet Subscriptions May 13, 2025
    • Truecaller Filters Verified Business Messages May 12, 2025
    • ChatGPT Deep Research Now Links to GitHub Repos May 12, 2025
    • Microsoft Offers Guide to Fix Windows Blue Screen Errors May 12, 2025
    • We’ve Invested $10b in Nigeria so Far – MTN May 12, 2025

    Browse Archives

    May 2025
    MTWTFSS
     1234
    567891011
    12131415161718
    19202122232425
    262728293031 
    « Apr    

    Quick Links

    • About TechBooky
    • Advertise Here
    • Contact us
    • Submit Article
    • Privacy Policy

    Recent News

    Microsoft Reveals Rejected Start Menu Redesigns

    Microsoft Reveals Rejected Start Menu Redesigns

    May 13, 2025
    SeerBit & Spectranet Launch ExpressPay for Internet Subscriptions

    SeerBit & Spectranet Launch ExpressPay for Internet Subscriptions

    May 13, 2025
    Truecaller Filters Verified Business Messages

    Truecaller Filters Verified Business Messages

    May 12, 2025
    ChatGPT Deep Research Now Links to GitHub Repos

    ChatGPT Deep Research Now Links to GitHub Repos

    May 12, 2025
    Microsoft Offers Guide to Fix Windows Blue Screen Errors

    Microsoft Offers Guide to Fix Windows Blue Screen Errors

    May 12, 2025
    The NCC Commissioned MTNN To Lease Spectrums From NTEL And Renew Its 3G Spectrum

    We’ve Invested $10b in Nigeria so Far – MTN

    May 12, 2025
    • Login

    © 2021 Design By Tech Booky Elite

    Generic selectors
    Exact matches only
    Search in title
    Search in content
    Post Type Selectors
    • African
    • Artificial Intelligence
    • Gadgets
    • Metaverse
    • Tips
    • About TechBooky
    • Advertise Here
    • Submit Article
    • Contact us

    © 2021 Design By Tech Booky Elite

    Discover more from TechBooky

    Subscribe now to keep reading and get access to the full archive.

    Continue reading

    We use cookies to ensure that we give you the best experience on our website. If you continue to use this site we will assume that you are happy with it.Ok