CISA published federal guidance for open-source software security, telling agencies to set policies for OSS use, contribution, release, and maintenance; handle upstream zero-day cases; secure public-domain reuse rights for government-funded software; and evaluate open-weight AI models separately from OSS.
Open Source Software: Security Principles and Practices
CISA published federal guidance for open-source software security, telling agencies to set policies for OSS use, contribution, release, and maintenance; handle upstream zero-day cases; secure public-domain reuse rights for government-funded software; and evaluate open-weight AI models separately from OSS.
Source: Cisa