{"id":22778,"date":"2020-11-11T06:14:11","date_gmt":"2020-11-11T11:14:11","guid":{"rendered":"https:\/\/devopsnews.online\/?p=22778"},"modified":"2020-11-11T06:14:11","modified_gmt":"2020-11-11T11:14:11","slug":"how-to-keep-your-open-source-projects-secure","status":"publish","type":"post","link":"https:\/\/devopsnews.online\/how-to-keep-your-open-source-projects-secure\/","title":{"rendered":"How to keep your open-source projects secure?"},"content":{"rendered":"

There are many risks involved with introducing a new code into a software. This is why Google developed a new scorecard system in order to help developers assess the risks related to open-source dependencies before it is introduced into their systems.<\/p>\n

Scorecards is a project released by OpenSSF, the Open-Source Security Foundation. This system aims to provide higher visibility to developers regarding the risk level of a software package by generating a \u2018security score\u2019 encouraging the decision-making process.<\/p>\n

Scorecards establishes a first evaluation criterion, which then produces a scorecard for an open-source project. It is then up to the developers to decide which packages are the best for their use case, depending on their level of trust. The metrics used to evaluate these packages include a security policy, code review process, and continuous test coverage with fuzzing and static-code analysis tools.<\/p>\n

The goal of scorecards is to enhance the virility in open-source security, especially with so many cyber threats, as well as helping organizations scale-out automated analysis and trust decisions.<\/p>\n

Although scorecards is very recent, there is an essential need for developers and open-source projects to have more resources in order to avoid attacks.<\/p>\n","protected":false},"excerpt":{"rendered":"

There are many risks involved with introducing a new code into a software. This is why Google developed a new scorecard system in order to help developers assess the risks related to open-source dependencies before it is introduced into their systems. Scorecards is a project released by OpenSSF, the Open-Source Security Foundation. This system aims…<\/p>\n","protected":false},"author":123458,"featured_media":22779,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"content-type":"","pmpro_default_level":"","footnotes":""},"categories":[3352,3480,3239],"tags":[67,914,59],"yoast_head":"\nHow to keep your open-source projects secure? - DevOps Online North America<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/devopsnews.online\/how-to-keep-your-open-source-projects-secure\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"How to keep your open-source projects secure? - DevOps Online North America\" \/>\n<meta property=\"og:description\" content=\"There are many risks involved with introducing a new code into a software. This is why Google developed a new scorecard system in order to help developers assess the risks related to open-source dependencies before it is introduced into their systems. Scorecards is a project released by OpenSSF, the Open-Source Security Foundation. This system aims...\" \/>\n<meta property=\"og:url\" content=\"https:\/\/devopsnews.online\/how-to-keep-your-open-source-projects-secure\/\" \/>\n<meta property=\"og:site_name\" content=\"DevOps Online North America\" \/>\n<meta property=\"article:published_time\" content=\"2020-11-11T11:14:11+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/devopsnews.online\/wp-content\/uploads\/2020\/11\/jussara-romao-3cM5Vw3UjaY-unsplash-scaled.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"2560\" \/>\n\t<meta property=\"og:image:height\" content=\"1920\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Yashesh Patel\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@DevOpsAmerica\" \/>\n<meta name=\"twitter:site\" content=\"@DevOpsAmerica\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Yashesh Patel\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"1 minute\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/devopsnews.online\/how-to-keep-your-open-source-projects-secure\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/devopsnews.online\/how-to-keep-your-open-source-projects-secure\/\"},\"author\":{\"name\":\"Yashesh Patel\",\"@id\":\"https:\/\/devopsnews.online\/#\/schema\/person\/1183cef5fa13624c55f3faf81f391435\"},\"headline\":\"How to keep your open-source projects secure?\",\"datePublished\":\"2020-11-11T11:14:11+00:00\",\"dateModified\":\"2020-11-11T11:14:11+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/devopsnews.online\/how-to-keep-your-open-source-projects-secure\/\"},\"wordCount\":201,\"publisher\":{\"@id\":\"https:\/\/devopsnews.online\/#organization\"},\"image\":{\"@id\":\"https:\/\/devopsnews.online\/how-to-keep-your-open-source-projects-secure\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/devopsnews.online\/wp-content\/uploads\/2020\/11\/jussara-romao-3cM5Vw3UjaY-unsplash-scaled.jpg\",\"keywords\":[\"DevOps\",\"DevSecOps\",\"open-source\"],\"articleSection\":[\"Cloud\",\"DevOps\",\"News\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/devopsnews.online\/how-to-keep-your-open-source-projects-secure\/\",\"url\":\"https:\/\/devopsnews.online\/how-to-keep-your-open-source-projects-secure\/\",\"name\":\"How to keep your open-source projects secure? - DevOps Online North America\",\"isPartOf\":{\"@id\":\"https:\/\/devopsnews.online\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/devopsnews.online\/how-to-keep-your-open-source-projects-secure\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/devopsnews.online\/how-to-keep-your-open-source-projects-secure\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/devopsnews.online\/wp-content\/uploads\/2020\/11\/jussara-romao-3cM5Vw3UjaY-unsplash-scaled.jpg\",\"datePublished\":\"2020-11-11T11:14:11+00:00\",\"dateModified\":\"2020-11-11T11:14:11+00:00\",\"breadcrumb\":{\"@id\":\"https:\/\/devopsnews.online\/how-to-keep-your-open-source-projects-secure\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/devopsnews.online\/how-to-keep-your-open-source-projects-secure\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/devopsnews.online\/how-to-keep-your-open-source-projects-secure\/#primaryimage\",\"url\":\"https:\/\/devopsnews.online\/wp-content\/uploads\/2020\/11\/jussara-romao-3cM5Vw3UjaY-unsplash-scaled.jpg\",\"contentUrl\":\"https:\/\/devopsnews.online\/wp-content\/uploads\/2020\/11\/jussara-romao-3cM5Vw3UjaY-unsplash-scaled.jpg\",\"width\":2560,\"height\":1920},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/devopsnews.online\/how-to-keep-your-open-source-projects-secure\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/devopsnews.online\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"How to keep your open-source projects secure?\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/devopsnews.online\/#website\",\"url\":\"https:\/\/devopsnews.online\/\",\"name\":\"DevOps Online North America\",\"description\":\"by 31 Media Ltd.\",\"publisher\":{\"@id\":\"https:\/\/devopsnews.online\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/devopsnews.online\/?s={search_term_string}\"},\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/devopsnews.online\/#organization\",\"name\":\"DevOps Online North America\",\"url\":\"https:\/\/devopsnews.online\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/devopsnews.online\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/devopsnews.online\/wp-content\/uploads\/2020\/03\/DevOpsOnline_email.png\",\"contentUrl\":\"https:\/\/devopsnews.online\/wp-content\/uploads\/2020\/03\/DevOpsOnline_email.png\",\"width\":198,\"height\":64,\"caption\":\"DevOps Online North America\"},\"image\":{\"@id\":\"https:\/\/devopsnews.online\/#\/schema\/logo\/image\/\"},\"sameAs\":[\"https:\/\/x.com\/DevOpsAmerica\"]},{\"@type\":\"Person\",\"@id\":\"https:\/\/devopsnews.online\/#\/schema\/person\/1183cef5fa13624c55f3faf81f391435\",\"name\":\"Yashesh Patel\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/devopsnews.online\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/7133dcc024275e35cf81ef202ce76441?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/7133dcc024275e35cf81ef202ce76441?s=96&d=mm&r=g\",\"caption\":\"Yashesh Patel\"},\"sameAs\":[\"https:\/\/devopsnews.online\"],\"url\":\"https:\/\/devopsnews.online\/author\/yashesh-patel\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"How to keep your open-source projects secure? - DevOps Online North America","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/devopsnews.online\/how-to-keep-your-open-source-projects-secure\/","og_locale":"en_US","og_type":"article","og_title":"How to keep your open-source projects secure? - DevOps Online North America","og_description":"There are many risks involved with introducing a new code into a software. This is why Google developed a new scorecard system in order to help developers assess the risks related to open-source dependencies before it is introduced into their systems. Scorecards is a project released by OpenSSF, the Open-Source Security Foundation. This system aims...","og_url":"https:\/\/devopsnews.online\/how-to-keep-your-open-source-projects-secure\/","og_site_name":"DevOps Online North America","article_published_time":"2020-11-11T11:14:11+00:00","og_image":[{"width":2560,"height":1920,"url":"https:\/\/devopsnews.online\/wp-content\/uploads\/2020\/11\/jussara-romao-3cM5Vw3UjaY-unsplash-scaled.jpg","type":"image\/jpeg"}],"author":"Yashesh Patel","twitter_card":"summary_large_image","twitter_creator":"@DevOpsAmerica","twitter_site":"@DevOpsAmerica","twitter_misc":{"Written by":"Yashesh Patel","Est. reading time":"1 minute"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/devopsnews.online\/how-to-keep-your-open-source-projects-secure\/#article","isPartOf":{"@id":"https:\/\/devopsnews.online\/how-to-keep-your-open-source-projects-secure\/"},"author":{"name":"Yashesh Patel","@id":"https:\/\/devopsnews.online\/#\/schema\/person\/1183cef5fa13624c55f3faf81f391435"},"headline":"How to keep your open-source projects secure?","datePublished":"2020-11-11T11:14:11+00:00","dateModified":"2020-11-11T11:14:11+00:00","mainEntityOfPage":{"@id":"https:\/\/devopsnews.online\/how-to-keep-your-open-source-projects-secure\/"},"wordCount":201,"publisher":{"@id":"https:\/\/devopsnews.online\/#organization"},"image":{"@id":"https:\/\/devopsnews.online\/how-to-keep-your-open-source-projects-secure\/#primaryimage"},"thumbnailUrl":"https:\/\/devopsnews.online\/wp-content\/uploads\/2020\/11\/jussara-romao-3cM5Vw3UjaY-unsplash-scaled.jpg","keywords":["DevOps","DevSecOps","open-source"],"articleSection":["Cloud","DevOps","News"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/devopsnews.online\/how-to-keep-your-open-source-projects-secure\/","url":"https:\/\/devopsnews.online\/how-to-keep-your-open-source-projects-secure\/","name":"How to keep your open-source projects secure? - DevOps Online North America","isPartOf":{"@id":"https:\/\/devopsnews.online\/#website"},"primaryImageOfPage":{"@id":"https:\/\/devopsnews.online\/how-to-keep-your-open-source-projects-secure\/#primaryimage"},"image":{"@id":"https:\/\/devopsnews.online\/how-to-keep-your-open-source-projects-secure\/#primaryimage"},"thumbnailUrl":"https:\/\/devopsnews.online\/wp-content\/uploads\/2020\/11\/jussara-romao-3cM5Vw3UjaY-unsplash-scaled.jpg","datePublished":"2020-11-11T11:14:11+00:00","dateModified":"2020-11-11T11:14:11+00:00","breadcrumb":{"@id":"https:\/\/devopsnews.online\/how-to-keep-your-open-source-projects-secure\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/devopsnews.online\/how-to-keep-your-open-source-projects-secure\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/devopsnews.online\/how-to-keep-your-open-source-projects-secure\/#primaryimage","url":"https:\/\/devopsnews.online\/wp-content\/uploads\/2020\/11\/jussara-romao-3cM5Vw3UjaY-unsplash-scaled.jpg","contentUrl":"https:\/\/devopsnews.online\/wp-content\/uploads\/2020\/11\/jussara-romao-3cM5Vw3UjaY-unsplash-scaled.jpg","width":2560,"height":1920},{"@type":"BreadcrumbList","@id":"https:\/\/devopsnews.online\/how-to-keep-your-open-source-projects-secure\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/devopsnews.online\/"},{"@type":"ListItem","position":2,"name":"How to keep your open-source projects secure?"}]},{"@type":"WebSite","@id":"https:\/\/devopsnews.online\/#website","url":"https:\/\/devopsnews.online\/","name":"DevOps Online North America","description":"by 31 Media Ltd.","publisher":{"@id":"https:\/\/devopsnews.online\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/devopsnews.online\/?s={search_term_string}"},"query-input":"required name=search_term_string"}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/devopsnews.online\/#organization","name":"DevOps Online North America","url":"https:\/\/devopsnews.online\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/devopsnews.online\/#\/schema\/logo\/image\/","url":"https:\/\/devopsnews.online\/wp-content\/uploads\/2020\/03\/DevOpsOnline_email.png","contentUrl":"https:\/\/devopsnews.online\/wp-content\/uploads\/2020\/03\/DevOpsOnline_email.png","width":198,"height":64,"caption":"DevOps Online North America"},"image":{"@id":"https:\/\/devopsnews.online\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/DevOpsAmerica"]},{"@type":"Person","@id":"https:\/\/devopsnews.online\/#\/schema\/person\/1183cef5fa13624c55f3faf81f391435","name":"Yashesh Patel","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/devopsnews.online\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/7133dcc024275e35cf81ef202ce76441?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/7133dcc024275e35cf81ef202ce76441?s=96&d=mm&r=g","caption":"Yashesh Patel"},"sameAs":["https:\/\/devopsnews.online"],"url":"https:\/\/devopsnews.online\/author\/yashesh-patel\/"}]}},"_links":{"self":[{"href":"https:\/\/devopsnews.online\/wp-json\/wp\/v2\/posts\/22778"}],"collection":[{"href":"https:\/\/devopsnews.online\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/devopsnews.online\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/devopsnews.online\/wp-json\/wp\/v2\/users\/123458"}],"replies":[{"embeddable":true,"href":"https:\/\/devopsnews.online\/wp-json\/wp\/v2\/comments?post=22778"}],"version-history":[{"count":1,"href":"https:\/\/devopsnews.online\/wp-json\/wp\/v2\/posts\/22778\/revisions"}],"predecessor-version":[{"id":22780,"href":"https:\/\/devopsnews.online\/wp-json\/wp\/v2\/posts\/22778\/revisions\/22780"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/devopsnews.online\/wp-json\/wp\/v2\/media\/22779"}],"wp:attachment":[{"href":"https:\/\/devopsnews.online\/wp-json\/wp\/v2\/media?parent=22778"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/devopsnews.online\/wp-json\/wp\/v2\/categories?post=22778"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/devopsnews.online\/wp-json\/wp\/v2\/tags?post=22778"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}