Article 5ZB9K Google will start distributing a security-vetted collection of open-source software libraries

Google will start distributing a security-vetted collection of open-source software libraries

by
Corin Faife
from The Verge - All Posts on (#5ZB9K)
acastro_180508_1777_google_IO_0003.0.jpg Illustration by Alex Castro / The Verge

Google announced a new initiative Tuesday aimed at securing the open-source software supply chain by curating and distributing a security-vetted collection of open-source packages to Google Cloud customers.

The new service, branded Assured Open Source Software, was introduced in a blog post from the company. In the post, Andy Chang, group product manager for security and privacy at Google Cloud, pointed to some of the challenges of securing open-source software and stressed Google's commitment to open source.

There has been an increasing awareness in the developer community, enterprises, and governments of software supply chain risks," Chang wrote, citing last year's major log4j vulnerability as an example. Google continues to be one...

Continue reading...

External Content
Source RSS or Atom Feed
Feed Location http://www.theverge.com/rss/index.xml
Feed Title The Verge - All Posts
Feed Link https://www.theverge.com/
Reply 0 comments