CIO Influence
CIO Influence News Networking Security

WhiteSource Renovate Users Now Rewarded Through Google-Sponsored OpenSSF Program

WhiteSource Renovate Users Now Rewarded Through Google-Sponsored OpenSSF Program
– WhiteSource Renovate (AKA Renovatebot) is now part of Scorecards 3.0. The Google Open Source Security (GOSS) Team further announced plans to integrate WhiteSource proactive dependency maintenance tool into its OpenSSF Allstar GitHub application.

WhiteSource, the leader in open source security and management, announced that use of WhiteSource Renovate, its free developer tool for proactive dependency maintenance, will be rewarded through the Secure Open Source (SOS) pilot rewards program. The program, run by the Linux Foundation, is sponsored by Google as part of the company’s $10 billion pledge to cybersecurity defense in response to the recent Executive Order on Cybersecurity.

WhiteSource Renovate automates open source dependency updates, reducing risk by mitigating security vulnerabilities and saving developers’ time. The Renovate App has enabled a diverse user base across github.com and gitlab.com to keep dependencies up-to-date since 2018, and has generated millions of pull requests in the process. The inclusion of WhiteSource Renovate as a positive indicator in the OpenSSF and Google Secure Open Source Rewards program further solidifies its position as the leading open source dependency management solution for developers.

Top iTechnology Networking News: IAR Systems Launches Cross-Platform Build Tools for Efficient Building and Testing in CI/CD Environments

“Open source components comprise between 60-80% of the codebase in modern applications,” said Rami Sass, Co-Founder and CEO of WhiteSource.”Unfortunately, open source projects are more attractive to hackers as their user base grows. Proactive dependency maintenance is the way forward for software organisations, because it helps prevent  vulnerabilities, as well as minimizing the cost of remediating them once found. WhiteSource’s proactive approach to application security is now endorsed as the industry standard through the Secure Open Source (SOS) rewards program.”

“Automated dependency management, along with comprehensive test coverage, is critical for keeping your dependencies up-to-date and preventing exploitation via known security vulnerabilities. WhiteSource Renovate is one of the tools recommended by OpenSSF’s Scorecard for proactive dependency management,” said Abhishek Arya, Principal Engineer and Manager, Google Open Source Security Team.

Top iTechnology Cloud News: Ardoq Joins Cloud Security Alliance

[To share your insights with us, please write to sghosh@martechseries.com]

Related posts

Cymulate Research Highlights Exposure Validation with Correlation of Weaknesses, Threats & Controls

Stats Perform and HEIM:SPIEL Partner in Fan Engagement

CIO Influence News Desk

InQuest Releases Data Demonstrating the Security Gap in the Major Cloud Email Providers

CIO Influence News Desk

Leave a Comment