CISA Outlines Efforts to Secure Open Source Software
Summary
Steps that CISA will take in partnership with the community include promoting the Principles for Package Repository Security, a framework outlining security maturity levels for package repositories and a new effort to enable collaboration and information sharing with open source software infrastructure operators. Furthermore, CISA will publish materials from the summit’s tabletop exercise, so that the open source community can use the lessons learned to improve vulnerability and incident response. The Python Software Foundation will add more providers to PyPI for credential-less publishing, including GitLab, Google Cloud, and ActiveState. Multi-factor authentication is now required from the maintainers of high-impact npm projects, who also have new tools available to automatically generate provenance and SBOMs, so that consumers can trace and verify dependencies. Supporting vulnerability scanning for years, the Maven Central plans additional enhancements, including access control on namespaces, Trusted Publishing evaluation, and Sigstore implementation, and will benchmark its security processes against best practices.