Security News

It's time enterprise businesses place their complete trust in open source
2021-09-16 16:11

Jack Wallen believes this milestone should help big businesses realize it is time to trust open source software. According to the company, "The certification further strengthens Canonical's industry-leading open source offering, reassuring customers in all industries that they can securely consume open source in a regulated fashion that complies with all the industry standards and best practices."

Travis CI Flaw Exposes Secrets of Thousands of Open Source Projects
2021-09-16 06:38

Continuous integration vendor Travis CI has patched a serious security flaw that exposed API keys, access tokens, and credentials, potentially putting organizations that use public source code repositories at risk of further attacks. Travis CI is a hosted CI/CD solution used to build and test software projects hosted on source code repository systems like GitHub and Bitbucket.

Why open source software supply chain management is worse than you think
2021-09-15 13:00

The seventh annual State of the Software Supply Chain Report from Sonatype found that developers think software management practices are in much better shape than what conditions on the ground indicate. The analysis found that the majority of respondents use an ad hoc approach to software supply chain management for most parts of the process, except for remediation and inventory.

Spectro Cloud open source project makes bare metal Kubernetes accessible
2021-08-17 12:36

The new contribution to the open source Kubernetes ecosystem addresses the need for organizations to easily deploy, run and manage Kubernetes clusters directly on top of bare metal servers, increasing performance and minimizing cost and operational effort."Running Kubernetes directly on bare metal servers is the next big thing for the Kubernetes community, but it has been challenging and difficult to implement," said Tenry Fu, CEO, Spectro Cloud.

Open source software plays an important role in the success of leading organizations
2021-08-09 03:00

DataStax unveiled research findings that show how leading organizations are winning with data, and how others can close the gap. Through insights from over 500 technology executives and practitioners, the report reveals clear, proven patterns for success with data among today's "Data leaders" - those most likely to excel at using data to deliver value to customers.

Cisco, Sonatype and Others Join Open Source Security Foundation
2021-08-02 13:07

The Open Source Security Foundation, the cross-industry forum focused on improving open source software security, has expanded its member list with the addition of names such as Accurics, Anchore, Bloomberg Finance, Cisco Systems, Codethink, Cybertrust Japan, OpenUK, ShiftLeft, Sonatype and Tidelift. With open source software becoming a central pillar of the application development lifecycle, ensuring the security of open source code is essential to securing modern software, regardless of whether it is used on end-user devices or in enterprise environments.

Dynatrace’s enhancements deliver analytics capabilities to more open-source services
2021-08-01 01:00

Dynatrace announced customers can extend Smartscape, the Dynatrace platform's real-time and continuously updated topology, to bring Dynatrace's powerful AIOps and analytics capabilities to more open-source services, including OpenTelemetry, FluentD, and Prometheus. As a result, DevOps and SRE teams can easily curate and analyze data streams from any source, at scale.

Several Bugs Found in 3 Open-Source Software Used by Several Businesses
2021-07-29 20:32

Cybersecurity researchers on Tuesday disclosed nine security vulnerabilities affecting three open-source projects - EspoCRM, Pimcore, and Akaunting - that are widely used by several small to medium businesses and, if successfully exploited, could provide a pathway to more sophisticated attacks. All the security flaws in question, which impact EspoCRM v6.1.6, Pimcore Customer Data Framework v3.0.0, Pimcore AdminBundle v6.8.0, and Akaunting v2.1.12, were fixed within a day of responsible disclosure, researchers Wiktor S?dkowski of Nokia and Trevor Christiansen of Rapid7 noted.

GitLab Releases Open Source Tool for Hunting Malicious Code in Dependencies
2021-07-26 12:23

GitLab last week announced the release of a new open source tool designed to help software developers identify malicious code in their projects' dependencies. Code reuse is a central approach to today's programming, but implementing open-source libraries in software comes with inherent risks.

The Audacity! How to wreck an open-source project and anger a community
2021-07-06 14:57

Now, prior to this, you may or may not have heard that the Audacity developers were toying around with adding telemetry to collect data from users. "All your personal data is stored on our servers in the European Economic Area. However, we are occasionally required to share your personal data with our main office in Russia and our external counsel in the USA.".