HomeSecurityGoogle: New tool makes it easier to identify open source bugs

Google: New tool makes it easier to find open source bugs

The Open Source Vulnerilities (OSV) website , created by Google , offers a database of vulnerabilities , with the aim of helping to fix bugs in open source projects and helping open source maintainers and consumers.

Google: New tool makes it easier to find open source bugs

Google argues that users have difficulty mapping a vulnerability to the package versions they use because the versioning schemes in existing vulnerability templates don't properly match the actual open source versioning schemes. "The result is missed vulnerabilities that affect downstream consumers," it warns.

Google is already sponsoring open source projects to move them from the problematic C to the secure Rust programming language. Last week, it also proposed a framework for the open source community to judge which projects should be considered “critical” and stricter rules for developers contributing to those projects.

OSV aims to address issues around the creation of bugs recently discovered through automation.

“ For open source maintainers, OSV automation helps reduce the burden of testing. Each vulnerability undergoes automated bifurcation and impact analysis to determine the specific commit series and releases affected ,” Google notes

“We plan to collaborate with open source communities to extend data from various language ecosystems (e.g. NPM, PyPI) and develop a pipeline for package maintainers to submit vulnerabilities with minimal effort.“

bugs

Google's effort mirrors Microsoft 's open source security initiatives through GitHub that aim to accelerate remediation through tools like Microsoft Teams.

According to Google, OSV is intended to provide accurate data on “where a vulnerability was exposed and where it was patched, thereby helping open source software consumers accurately determine if they are affected and then make security fixes as quickly as possible.”

Currently, this feed contains vulnerabilities from OSS-Fuzz, the bot created to detect open source software for bugs. Most of the bugs filed with OSV come from C and C++ code.

OSS-Fuzz has been a successful Google program, helping to uncover thousands of bugs in key open source projects.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS