GitHub targets vulnerable open source components

General News

Summary

GitHub has introduced an automated alert mechanism to enable developers to address vulnerabilities in the open source components their code uses. But, to demonstrate the scale of the problem facing the open source community, the database shows that there are over 173,000 vulnerabilities in GitHub that have not been reviewed. In January this year, a number of major tech firms, including Google and IBM, participated in the White House Open Source Software Security Summit. To coincide with the summit, Kent Walker, president of global affairs at Google and Alphabet, posted a blog discussing the need to secure open source code effectively. “Growing reliance on open source means it’s time for industry and government to come together to establish baseline standards for security, maintenance, provenance and testing – to ensure national infrastructure and other important systems can rely on open source projects,” he wrote.

Classifications

industries
Fintech & Banking
applications
Data Management

AskAI Classifications

Labels
Developer Tools DevOps Software SaaS

Linked Companies

GitHub, Inc.
$1M to $5M
Semmle
$1M to $5M