Google this week announced plans to support the Open Source Technology Improvement Fund (OSTIF) to boost the security of open source projects.
The announcement, which follows Google’s $100 million pledge to open source security projects, will help OSTIF launch its Managed Audit Program (MAP), meant to review the security of projects critical to the open source environment.
A total of eight projects will benefit from Google’s contribution, including Git, the version control software in modern DevOps, considered the second-most critical application in C; Lodash, a JavaScript utility library that has more than 200 functions to help web development; and Laravel, a php web application framework used in full-stack web applications.
The remaining projects include Slf4j, a logging facade for Java logging frameworks; Jackson-core & Jackson-databind, which are considered the most-used non-JavaScript packages; and Httpcomponents-core & Httpcomponents-client, which are the core and client components of Apache httpcomponents.
“This marks a major success in bringing on large corporate donors to support OSTIF’s model of improving open source software through security reviews and source code audits. A focused, well-scoped review by an experienced team can drive significant and long-lasting improvements in widely used projects,” according to an OSTIF statement.
OSTIF said the Managed Audit Program will help expand security reviews to more projects vital to the open source ecosystem. Improvements brought to the selected eight libraries, frameworks, and apps are expected to have a great overall impact on the open-source ecosystem relying on them.
Related: Cisco, Sonatype and Others Join Open Source Security Foundation
Related: Tool Helps Developers Visualize Dependencies of Open Source Projects

More from Ionut Arghire
- Stolen GitHub Credentials Used to Push Fake Dependabot Commits
- Google Open Sources Binary File Comparison Tool BinDiff
- UAE-Linked APT Targets Middle East Government With New ‘Deadglyph’ Backdoor
- Xenomorph Android Banking Trojan Targeting Users in US, Canada
- $200 Million in Cryptocurrency Stolen in Mixin Network Hack
- Stealthy APT Gelsemium Seen Targeting Southeast Asian Government
- Nigerian Pleads Guilty in US to Million-Dollar BEC Scheme Role
- City of Dallas Details Ransomware Attack Impact, Costs
Latest News
- Stolen GitHub Credentials Used to Push Fake Dependabot Commits
- Google Open Sources Binary File Comparison Tool BinDiff
- macOS 14 Sonoma Patches 60 Vulnerabilities
- New GPU Side-Channel Attack Allows Malicious Websites to Steal Data
- Microsoft Adding New Security Features to Windows 11
- UAE-Linked APT Targets Middle East Government With New ‘Deadglyph’ Backdoor
- Sony Investigating After Hackers Offer to Sell Stolen Data
- The CISO Carousel and its Effect on Enterprise Cybersecurity
