The US Cybersecurity and Infrastructure Security Agency has published new guidance on securing open source software, which it says is now embedded in nearly every modern system from business applications to critical infrastructure.
The guidance covers risk management across the full lifecycle of open source software, introduces a C4 Framework for trust assessment, and provides recommendations for vulnerability management, software bills of materials, secure development and handling of open source AI systems, CISA reports.