Get the latest tech news
How to make open source software more secure
Earlier this year, a Microsoft developer realized that someone had inserted a backdoor into the code of open source utility XZ Utils, which is used in
Villa and his team at Tidelift propose a model where the company pays open source maintainers to take care of their code and partners to fix vulnerabilities. CISA, Black explained, is now getting involved, launching initiatives to tell businesses what are the best — and worst — security practices when it comes to deploying open source software. Villa said that there’s a need for “multiple approaches” and “defense in depth,” which means there’s a need for several layers of security to protect the open source ecosystem.
Or read this on TechCrunch