Following the White House's open-source security summit, Google proposes setting up an organization to serve as a marketplace for open source maintenance
to ensure national infrastructure and other important systems can rely on open source projects.” https://blog.google/... Kent Walker / @kent_walker : Open source software is the connective tissue for much of what we all do online, and it deserves the same focus and funding we give to our roads and bridges. Today we shared with @WhiteHouse some of our ideas for protecting open source security. https://blog.google/... Phil Venables / @philvenables : Pleased to partner with The White House and other agencies and companies at today's summit on making Open Source software safer and more secure. https://blog.google/...
It also extends Google’s earlier effort to document how it supports open-source projects, but recasts support as infrastructure security rather than simply project stewardship.
First-order effects
Google puts a marketplace-style organization on the agenda for the White House’s effort to protect critical open-source projects, giving maintainers a proposed route to surface maintenance needs.
Organizations that rely on important open-source software gain a proposed vehicle for directing support toward the projects underlying their systems.
Second-order effects
Major software companies invited to the White House process face pressure to support a shared maintenance model rather than treat open-source security solely as an internal engineering responsibility.
A marketplace model would make funding priorities more explicit, concentrating attention on projects identified as important to national infrastructure and other critical systems.
Third-order effects
If adopted, the proposal points to open-source maintenance becoming a governed infrastructure function, with coordination among companies, developers, and government rather than ad hoc sponsorship.
That shift would make the selection of which projects receive support a consequential form of gatekeeping, even as the code remains openly available.
The trend: Open-source security is being treated increasingly as critical infrastructure that needs durable, coordinated maintenance funding.
#log4j has highlighted the need to improve our software security and the transparency of our software supply chain. Enjoying the discussion with @WHNSC and leading open source project managers about how to bring coherence to federal efforts to increase software resilience.
Proud to continue our work with the Biden Administration to strengthen cybersecurity across public and private sectors through critical areas like open source software. Today, we had the opportunity to discuss this and more with the @WhiteHouse. https://twitter.com/...
Important to discuss how we evolve security models in the aftermath of #Log4j - @Google joined the White House Open Source Software Security Summit today to offer proposals for better public/private sector support of the open source ecosystem https://twitter.com/...
This would be like exclusively inviting the owners of private hospitals to a meeting about public health issues - large corps capturing disproportionate amounts of the value compared to what gets shared back to the commons is a huge part of the problem right now. https://twitter.…
looking forward to seeing the F500/G2000 follow suit with efforts like this, not just the hyper scalers who have been contributing and using open source for decades https://twitter.com/...
y'know the funny thing about this? ... they're asking everyone but the people that fucking write the software in question. i mean, they're not even talking to an ASF rep, never mind the log4j devs https://twitter.com/...
Coming out of White House Open Source Software Security Summity (WHOSSSS?): 3 key points summarized by @Kent_Walker @Google 1) Identify critical projects (e.g. via SLSA) 2) Standardize security baselines (ditto) 3) Fund security fixits (no free lunch) https://blog.google/...
“It's time for industry and government to come together to establish baseline standards for security, maintenance, provenance, and testing — to ensure national infrastructure and other important systems can rely on open source projects.” https://blog.google/...
Securing the open source software ecosystem is a critical step in keeping people and their information safe online. Glad we could share recommendations with the @WhiteHouse and others as part of our ongoing partnership to strengthen cybersecurity. https://blog.google/...
Open source software is the connective tissue for much of what we all do online, and it deserves the same focus and funding we give to our roads and bridges. Today we shared with @WhiteHouse some of our ideas for protecting open source security. https://blog.google/...
Pleased to partner with The White House and other agencies and companies at today's summit on making Open Source software safer and more secure. https://blog.google/...