Topic: open source

Why We Need an Open Source System of Context in the AI Era

The market keeps saying “SaaS is dead.” That’s probably true, but it’s also incomplete. What’s actually dying is the idea that value lives inside a vendor-controlled black box. The next era is about utilities: unlimited coding capacity and unlimited analytical capability. And if those two utilities are real, then the vendor model has to change. … continue reading

Report: Open source licensing conflicts hit an all-time high as organizations struggle to audit AI-generated code for IP risks

AI-generated code introduces a lot of risk into the development process. A recent Sonatype report found that AI hallucinated 27% of upgrade recommendations for open source projects, while research from Veracode found that AI introduced security vulnerabilities in 45% of 80 coding tasks across 100+ different LLMs. Now, new research from Black Duck is shedding … continue reading

Report: AI hallucinates 27% of upgrade recommendations for open source projects

Open-source adoption is being accelerated by AI and automation, but developers need to proceed with caution to ensure they’re not introducing extra risk into their software supply chain. Brian Fox, co-founder and CTO of Sonatype, explained that AI can accelerate good engineering, but it can also scale mistakes faster, especially if it doesn’t have real-world … continue reading

Chainguard adds 10 new projects to EmeritOSS program for prolonging the life of open source tools

Chainguard is adding 10 new open source projects to EmeritOSS, its program for supporting mature open source projects that don’t require continuous upkeep or whose maintainers need to step away. “EmeritOSS exists for the projects that have earned their stripes. They’ve shipped, scaled, and supported real systems, and while their maintainers may be ready to … continue reading

Google launches OSS Rebuild tool to improve trust in open source packages

Google is hoping to improve public trust in open source projects with the launch of a new open source project called OSS Rebuild that reproduces upstream artifacts and compares the new package with the original artifact. According to Google, this process enables customers to verify a package’s origin, understand and repeat its build process, and … continue reading

Google’s Agent2Agent protocol finds new home at the Linux Foundation

At the Open Source Summit North America, it was announced that Google donated its Agent2Agent (A2A) protocol to the Linux Foundation. The A2A protocol offers a standard way for connecting agents to each other. In this way, it complements Anthropic’s Model Context Protocol (MCP), which provides a way to connect agents to different data sources … continue reading

Open source wins again! Redis adds GNU AGPL license to its offering

Over the past year or so, the industry has seen several open-source projects forked because the founders of those projects changed their licenses in moves they say were to protect their intellectual property. Redis switched from the open BSD license to the more restrictive Redis Source Available License v2 and the Server Side Public License … continue reading

Report: Keeping up with patches is the number one challenge when using open source software

A new report is revealing that the most challenging aspect of utilizing open source projects is keeping up with updates and patches.   According to the 2025 State of Open Source report from Perforce Software, the Eclipse Foundation, and the Open Source Initiative, when asked to rank challenges on a scale of one to five, over … continue reading

Sonatype reveals 18,000 malicious open source packages in its Q1 Open Source Malware Index

Sonatype, a company focused on software supply chain security, has announced the results of its quarterly Open Source Malware Index, which provides insights into malicious open source packages.  The index found 17,954 malicious open source software packages, including several hijacked npm crypto packages, a malicious npm package disguised as the Truffle for VS Code extension, … continue reading

OpenSSF creates Project Security Baseline

UPDATED MARCH 28 The Open Source Security Foundation (OpenSSF) has created a Project Security Baseline that helps open source projects of all sizes ensure that their efforts are secure. The baseline defines a minimum set of requirements for application security that developers can do to enforce secure development practices, such as how they need to … continue reading

Techniques to secure open source software

Attackers are increasingly targeting open source projects, seeking to exploit holes in software that millions of organizations rely on as the foundation of their technology stacks. The staggering 280% year-over-year increase in software supply chain attacks in 2023 serves as a stark warning: open source projects and their leadership must elevate security to their highest … continue reading

ActiveState relaunching its platform for open source management

ActiveState today announced it is rebranding and relaunching its product as an open source management platform to help enterprises manage open source complexities, ensure supply chain security, and streamline DevSecOps. The platform, which integrates with existing tools, aims to proactively manage open-source risks by providing tools for discovery, analysis, remediation, and governance.  It offers a … continue reading

1 2 3 112
DMCA.com Protection Status