• Archives
  • Cryptocurrency
  • Earnings
  • Enterprise
  • About TechBooky
  • Submit Article
  • Advertise Here
  • Contact Us
TechBooky
  • African
  • AI
  • Metaverse
  • Gadgets
Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
Search in posts
Search in pages
  • African
  • AI
  • Metaverse
  • Gadgets
Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
Search in posts
Search in pages
TechBooky
Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
Search in posts
Search in pages
Home Cloud

Google To Start Distributing Secured Open-Source Software Libraries

Olagoke Ajibola by Olagoke Ajibola
May 17, 2022
in Cloud, Enterprise
Share on FacebookShare on Twitter

Is The Use of Open Source Software Putting Your Business at Risk? | Global IP & Technology Law Blog

Today, Google launches a new security feature. The new initiative is aimed at securing the open-source software supply chain by curating and distributing a security-vetted collection of open-source packages to Google Cloud customers. 

The new service introduced in a blog post has been branded Assured Open Source Software. In the blog post, Andy Chang, group product manager for security and privacy at Google Cloud, highlighted some of the challenges faced by securing open-source software and also stressed Google’s continuous commitment to securing open source.

In the blog post, Chang wrote that “There has been an increasing awareness in the developer community, enterprises, and governments of software supply chain risks.” Chang cites a major vulnerability – log4j from last year as an example. He further wrote that “Google continues to be one of the largest maintainers, contributors, and users of open source and is deeply involved in helping make the open-source software ecosystem more secure.”

Google has disclosed that the Assured Open Source Software service will give enterprises and government users access to the same vetted open-source packages that Google itself uses in its projects. According to the company, these packages are regularly scanned, analyzed, and fuzz-tested for vulnerabilities and built with Google Cloud’s Cloud Build service with evidence of SLSA-compliance (that’s ‘Supply-chain Levels for Software Artifacts,’ a framework for safeguarding artifact integrity across software supply chains). 

A list of the 550 major open-source libraries reviewed by Google is available on GitHub, the list will continue to be reviewed. While these libraries can all be downloaded independently, the Assured OSS program will see to the distribution of audited versions through Google Cloud — to mitigate incidents where developers intentionally or unintentionally corrupt widely used open-source libraries. At the moment, this service remains in the early access mode and is expected to be available to a wider customer range for testing by Q3 2022.

The new service announcement comes at a time when there is a wide industry drive to see to the improvement of the security of the open-source software supply chain. This drive has also enjoyed the support of the Biden administration.

Earlier in the year 2022, a handful of the nation’s largest tech companies held a meeting with representatives of the US federal agencies, this includes the Department of Homeland Security and the Cybersecurity and Infrastructure Security Agency. The meeting focused on a discussion around open-source software security in the wake of the log4j bug. A recent meeting of the companies involved also resulted in a pledge of more than $30 million in funding to boost open-source software security. Asides from the provision of funds, Google has also committed to putting engineering hours to work towards ensuring the supply chain is secure. Google recently announced the formation of an “Open Source Maintenance Crew” that would work with the maintainers of popular libraries for improved security.

Related Posts:

  • OUXSPAPPUVK27H6RHKQWKLT4VI
    OpenAI Is Developing A New Language Model Open Source AI
  • 633909b1-478e-4792-bf45-85ba6fe3cbcb
    Google AI Agent Big Sleep Finds First Security Flaw…
  • Circle-droid_1@2x
    Google Develops Android OS Privately Amid Strategy Shift
  • deccanherald_2025-07-15_likoucgy_Sun-Day-Tracker-app
    Bitchat By Jack Dorsey Tracks Sun Exposure
  • google-intel-confidential-computing-more-s.max-2000×2000
    Google Cloud Reported More Than 10 Bugs On Intel’s…
  • Proton-Launches-Cross-Platform-Authenticator-App-with-Secure-Sync
    Proton Launch A New 2FA App
  • congress-ai-25_1200xx5000-2813-0-260
    US Congress Targets Chinese AI with 'No Adversarial AI Act
  • sam altman
    OpenAI Offers Free Models to Challenge Chinese Firms, Meta

Discover more from TechBooky

Subscribe to get the latest posts sent to your email.

Tags: businessChainenterprisegoogleOpenopen-sourceSecuresecurityServicesoftwaresourceSupply
Olagoke Ajibola

Olagoke Ajibola

Olagoke Ajibola is a creative writer and content producer with an eye for details and excellence. He has a demonstrated history of telling stories for TV, Film and Online. Aside from being fascinated by the power of imagination, his other interest are travel, sport, reading and meeting people.

BROWSE BY CATEGORIES

Receive top tech news directly in your inbox

subscription from
Loading

Freshly Squeezed

  • Breaking: Google Keeps Chrome, But Judge Orders Search Data Sharing September 2, 2025
  • YouTube Premium Targets Account Sharing, Netflix-Style September 2, 2025
  • Microsoft Fixes Windows Certificate Enrolment Bug September 1, 2025
  • Microsoft to Enforce MFA on Azure Resource Management in October September 1, 2025
  • How to Read Faster: 10 Best Speed Reading Apps in 2025 (Ranked & Reviewed) August 31, 2025
  • WhatsApp Working On Shorter Disappearing Message Timers August 29, 2025

Browse Archives

September 2025
MTWTFSS
1234567
891011121314
15161718192021
22232425262728
2930 
« Aug    

Quick Links

  • About TechBooky
  • Advertise Here
  • Contact us
  • Submit Article
  • Privacy Policy
Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
Search in posts
Search in pages
  • African
  • Artificial Intelligence
  • Gadgets
  • Metaverse
  • Tips
  • About TechBooky
  • Advertise Here
  • Submit Article
  • Contact us

© 2025 Designed By TechBooky Elite

Discover more from TechBooky

Subscribe now to keep reading and get access to the full archive.

Continue reading

We use cookies to ensure that we give you the best experience on our website. If you continue to use this site we will assume that you are happy with it.