October 14, 2021

The Open Source Security Foundation

Atte Lahtiranta, CTO, Goldman Sachs

Like most any modern enterprise, Goldman Sachs runs on open source software. This is one reason we recently launched our Open Source Program Office (OSPO). Our OSPO is working with the Goldman Sachs developer community to accelerate our rate of open source contributions, including pull requests of patches and new features, to projects on which we rely. We're also continuing to open source projects originated in our organization, such as our recent contributions of CatchIT and Legend to FINOS. The central role that open source plays in our software bills of material is also why we will continue to grow our financial support of open source projects both in the form of direct grants to maintainers as well as through open source foundations and consortia.

An example of a foundation we've chosen to support is the Open Source Security Foundation (OpenSSF). OpenSSF is part of the wider Linux Foundation family of initiatives. Yesterday the Linux Foundation and OpenSSF announced our participation in an overall cross-industry commitment of $10M to be used to further secure the open source software supply chain. The OpenSSF was created to help companies and organizations, from both the private and public sector, to respond to the imperative that is cybersecurity. The OpenSSF also represents a collective mobilization in response to the May 2021 White House Cybersecurity Executive Order call-to-action.

Cybersecurity is not something that can be done in silos. The OpenSSF will be an important forum where we can bring everyone together – including large corporations, startups, individual contributors, and maintainers - to share learnings and build improved tooling. Together, we will be able to:

  • Improve vulnerability detection in open source packages, "shifting left" detection to earlier in the process, and accelerating the distribution of patches to impacted users.
  • Create leading practices for controlling and managing the software supply chain, especially in regards to continuous integration and continuous deployment (CI/CD) and associated rapid iteration development methodologies.
  • Improve testing methodologies and frameworks.
  • Better train our teams -- secure software starts with the humans that build and use it.

Goldman Sachs is excited to work alongside the open source community on this critical initiative. To learn more and get involved, visit the OpenSSF GitHub.


See https://www.gs.com/disclaimer/global_email for important risk disclosures, conflicts of interest, and other terms and conditions relating to this blog and your reliance on information contained in it.

GS DAP® is owned and operated by Goldman Sachs. This site is for informational purposes only and does not constitute an offer to provide, or the solicitation of an offer to provide access to or use of GS DAP®. Any subsequent commitment by Goldman Sachs to provide access to and / or use of GS DAP® would be subject to various conditions, including, amongst others, (i) satisfactory determination and legal review of the structure of any potential product or activity, (ii) receipt of all internal and external approvals (including potentially regulatory approvals); (iii) execution of any relevant documentation in a form satisfactory to Goldman Sachs; and (iv) completion of any relevant system / technology / platform build or adaptation required or desired to support the structure of any potential product or activity. All GS DAP® features may not be available in certain jurisdictions. Not all features of GS DAP® will apply to all use cases. Use of terms (e.g., "account") on GS DAP® are for convenience only and does not imply any regulatory or legal status by such term.
Certain solutions and Institutional Services described herein are provided via our Marquee platform. The Marquee platform is for institutional and professional clients only. This site is for informational purposes only and does not constitute an offer to provide the Marquee platform services described, nor an offer to sell, or the solicitation of an offer to buy, any security. Some of the services and products described herein may not be available in certain jurisdictions or to certain types of clients. Please contact your Goldman Sachs sales representative with any questions. Any data or market information presented on the site is solely for illustrative purposes. There is no representation that any transaction can or could have been effected on such terms or at such prices. Please see https://www.goldmansachs.com/disclaimer/sec-div-disclaimers-for-electronic-comms.html for additional information.
Transaction Banking services are offered by Goldman Sachs Bank USA (“GS Bank”). GS Bank is a New York State chartered bank, a member of the Federal Reserve System and a Member FDIC.
Mosaic is a service mark of Goldman Sachs & Co. LLC. This service is made available in the United States by Goldman Sachs & Co. LLC and outside of the United States by Goldman Sachs International, or its local affiliates in accordance with applicable law and regulations. Goldman Sachs International and Goldman Sachs & Co. LLC are the distributors of the Goldman Sachs Funds. Depending upon the jurisdiction in which you are located, transactions in non-Goldman Sachs money market funds are affected by either Goldman Sachs & Co. LLC, a member of FINRA, SIPC and NYSE, or Goldman Sachs International. For additional information contact your Goldman Sachs representative. Goldman Sachs & Co. LLC, Goldman Sachs International, Goldman Sachs Liquidity Solutions, Goldman Sachs Asset Management, L.P., and the Goldman Sachs funds available through Goldman Sachs Liquidity Solutions and other affiliated entities, are under the common control of the Goldman Sachs Group, Inc.
© 2024 Goldman Sachs. All rights reserved.