Tag: Open-Source Packages

Google Launches OSS Rebuild to Expose Malicious Code in Widely Used Open-Source Packages
News

Google Launches OSS Rebuild to Expose Malicious Code in Widely Used Open-Source Packages

In an effort to strengthen the security of open-source package ecosystems and stop software supply chain threats, Google has announced the start of a new project dubbed OSS Rebuild. In a blog post this week, Matthew Suozzo of the Google Open Source Security Team (GOSST) stated that OSS Rebuild provides security teams with powerful data to prevent penetration without putting undue strain on upstream maintainers, since supply chain hacks continue to target widely-used dependencies. With aspirations to expand to other open-source software development platforms, the project's goal is to provide build provenance for packages across the Crates.io (Rust), npm (JS/TS), and Python Package Index (Python) package registries. The goal of OSS Rebuild is to create reliable security metadata by...