At Open Source Summit Europe, the Fintech Open Source Foundation announced that the Open Source Enterprise Resiliency Alliance is operational with initial funding from six Premier members, including Deutsche Bank, Goldman Sachs, Morgan Stanley, NatWest and RBC. The Linux Foundation vertical said OSERA, announced as an intent to form in June, has published a first version of a patching and attestation standard and delivered attested secure package updates across more than 50 widely used Java and Spring ecosystem projects. The alliance argues that banks running similar open source stacks duplicate work when they each fix the same vulnerabilities, citing research that one in five financial institutions maintain private versions of the same projects, a fork tax that raises cost and risk. Its source code is public, governance is member-led under the Linux Foundation and its standards are open, and it frames the work as complementary to commercial and community support models as regulations such as DORA, NIS2 and the EU Cyber Resilience Act raise expectations for vulnerability management.
Major banks back OSERA to standardize and fund open source security fixes
At Open Source Summit Europe, the Fintech Open Source Foundation announced that the Open Source Enterprise Resiliency Alliance is operational with initial funding from six Premier members, including Deutsche Bank, Goldman Sachs, Morgan Stanley, NatWest and RBC. The Linux Foundation vertical said OSERA, announced as an intent to form in June, has published a first version of a patching and attestation standard and delivered attested secure package updates across more than 50 widely used Java and Spring ecosystem projects. The alliance argues that banks running similar open source stacks duplicate work when they each fix the same vulnerabilities, citing research that one in five financial institutions maintain private versions of the same projects, a fork tax that raises cost and risk. Its source code is public, governance is member-led under the Linux Foundation and its standards are open, and it frames the work as complementary to commercial and community support models as regulations such as DORA, NIS2 and the EU Cyber Resilience Act raise expectations for vulnerability management.
Source: Linux Foundation