"CISA Announces New Efforts to Help Secure Open Source Ecosystem"
"CISA Announces New Efforts to Help Secure Open Source Ecosystem"
The US Cybersecurity and Infrastructure Security Agency (CISA) has announced several initial key actions that it will take in collaboration with the open source community to help secure the open source ecosystem. CISA is working with package repositories to encourage the adoption of the Principles for Package Repository Security. This framework, developed by CISA and the Open Source Security Foundation's (OpenSSF) Securing Software Repositories Working Group, delves into voluntary security maturity levels for package repositories.