{"id":32470,"date":"2023-11-09T18:53:36","date_gmt":"2023-11-09T18:53:36","guid":{"rendered":"https:\/\/one.sightlinemg.com\/federaltimes\/uncategorized\/2023\/11\/09\/following-the-roadmap-to-open-source-software-security\/"},"modified":"2026-08-08T18:56:01","modified_gmt":"2026-08-08T18:56:01","slug":"following-the-roadmap-to-open-source-software-security","status":"publish","type":"post","link":"https:\/\/one.sightlinemg.com\/federaltimes\/opinions\/2023\/11\/09\/following-the-roadmap-to-open-source-software-security\/","title":{"rendered":"Following the roadmap to open-source software security"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">There\u2019s no question that open-source software is central to the development and innovation required to meet federal missions \u2013 making its security of the utmost importance.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">OSS supports every critical infrastructure sector within the federal government. The federal government recognizes this and is prioritizing OSS security with measures such as the Office of the National Cyber Director\u2019s recent <a href=\"https:\/\/www.whitehouse.gov\/oncd\/briefing-room\/2023\/08\/10\/fact-sheet-office-of-the-national-cyber-director-requests-public-comment-on-open-source-software-security-and-memory-safe-programming-languages\/\">OS3I Initiative <\/a>and subsequent request for public information and the Cybersecurity and Infrastructure Security Agency\u2019s <a href=\"https:\/\/www.cisa.gov\/sites\/default\/files\/2023-09\/CISA-Open-Source-Software-Security-Roadmap-508c.pdf\">Open-Source Software Security Roadmap<\/a>. These initiatives will help agencies to better understand, manage and reduce the risks of open-source software that our nation\u2019s critical infrastructure is built on.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">It\u2019s up to oversight bodies such as CISA, government leaders and industry partners to set baseline expectations for OSS use and ensure top-level security to protect agencies\u2019 critical data \u2014 which could be at stake if agencies fail to have clear standards in place.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">To reduce vulnerabilities at scale, government leaders need to prioritize security and foster open-source software development best practices. This can be broken down into three top considerations to enhance security:<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u2014 Utilize supported enterprise OSS;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u2014 Implement secure-by-design practices in the development phase; and<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u2014 Leverage artificial intelligence.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Supported enterprise OSS offers more security<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Contrary to common belief, not all OSS is created equal. Federal agencies handling sensitive data should utilize supported enterprise open-source software where possible. Agencies using free versions of enterprise OSS at scale don\u2019t receive the level of support required to ensure data remains secure. Even if they are feature-rich, free tooling projects don\u2019t offer auditable, attestable security at scale.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Supported enterprise OSS provides an increased level of security and regulation with additional accountability for the provided code. It does this through quality checkpoints, automated testing, and enforceable DevSecOps pipelines to consistently validate contributions to the software. It also does a better job of managing risk and provides enhanced capabilities for visibility, transparency, reporting and auditability.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Additionally, hardening guides and best practices should be created and published for enterprise versions of OSS to reduce risk. Peer code review is a common practice in OSS community development. For better transparency and security, the platform hosting the OSS should have visibility into peer reviews and contribution approver history.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Public-private partnerships are essential to increasing accountability and transparency in the software development process. The government can look to industry partners for support in best practices for secure open-source software.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Keeping OSS secure by design<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">In addition to the OSS Security Roadmap, CISA also recently put out new guidance on<a href=\"https:\/\/www.cisa.gov\/securebydesign\"> <\/a><a href=\"https:\/\/www.cisa.gov\/securebydesign\">secure-by-design<\/a> practices for software providers as a critical approach to ensure the security of OSS. Secure-by-design products have security baked in at the start of the software lifecycle\u2014not as an afterthought or at the end of the development process.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">CISA\u2019s guidance, as well as guidelines set by standards like<a href=\"https:\/\/csrc.nist.gov\/Projects\/ssdf\"> <\/a><a href=\"https:\/\/csrc.nist.gov\/Projects\/ssdf\">NIST\u2019s Secure Software Development Framework<\/a> (SSDF), reinforce critical considerations for keeping software secure by design, which must carry over into open-source environments. In the case of OSS security specifically, the SSDF acts as a guide to confirm secure-by-design principles and leads to an initial level of trust for OSS adoption. In accordance with secure-by-design principles, developers and federal leaders utilizing software should consider tools that automatically scan for vulnerabilities and have strong environmental visibility.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Another tool government leaders should consider to ensure all software is secure by design is a Software Bill of Materials or an inventory of components that make up software. SBOMs also include critical information about the libraries, tools, and processes used to develop, build, and deploy a software artifact. Keeping a record of what tool was used to generate the SBOM and an accompanying digital attestation can certify that the artifact hasn\u2019t been modified.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Prioritizing security within the development phase and with a supported platform of choice is critical to building and maintaining trust. Attestation and trustworthiness are also easier to attain with a singular DevSecOps platform that is used for build, test, and secure functionality.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Applying AI to enhance OSS<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The federal government is expanding its capabilities with the use of artificial intelligence, which is another tool agencies should consider for their OSS security journey. AI has the capacity to automate menial tasks and will take some of the burden off of developers, leaving them with more time to focus on security. Organizations should also look beyond just using AI for code development and incorporate it throughout the software development lifecycle in capacities such as explaining code to non-technical users and providing security support.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">When integrated through each stage of the software development lifecycle, AI can help proactively prevent or reduce the requirements for approvals in the development process. It can also be applied to new code and automated test creation, automated selection of reviewers, and assisted remediation of identified vulnerabilities.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Government agencies considering AI should pay attention to the models and platforms used, vendor transparency, and coding best practices. Human verification of code should continue to be an ongoing requirement with the supplement of automated security scanning.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">OSS is foundational to software development, spurring innovation and enabling the government to develop critical programs more rapidly, providing a base for critical infrastructure. It is paramount to follow best practices for OSS security to reduce risk and better protect government assets.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This undertaking doesn\u2019t have to be done alone \u2013 federal leaders should look to incentivize intentional partnerships between government and industry to encourage collaboration and accountability. Working together to secure OSS is crucial to national security. Utilizing these considerations can bolster OSS security and, in turn, empower the government to innovate for mission-critical operations.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><i>Joel Krooswyk<\/i> is the Federal CTO at GitLab, a developer of secure software products and services.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>It\u2019s up to oversight bodies such as CISA, government leaders and industry partners to set baseline expectations for OSS use and ensure security.<\/p>\n","protected":false},"author":7,"featured_media":47928,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"_yoast_wpseo_meta-robots-noindex":"","_yoast_wpseo_meta-robots-nofollow":"","_yoast_wpseo_canonical":"","_acf":"","_yoast_wpseo_primary_category":26,"_jetpack_feature_clip_id":0,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","_smg_distribution_targets":[]},"categories":[31,14,26],"tags":[],"coauthors":[5992],"class_list":["post-32470","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-home","category-it-networks","category-opinions"],"acf":{"subheadline":"","legacy_arc_id":"M24LK36WSJFBBI3PMQ3KGMVF5E","arc_canonical_url":"\/opinion\/2023\/11\/09\/following-the-roadmap-to-open-source-software-security\/","remove_feature_photo":false,"is_sponsored":false,"subtype":"","redirect_url":"","disable_inline_ads":false,"native_logo_pretext":"Presented By:"},"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v26.0 (Yoast SEO v28.1) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>Following the roadmap to open-source software security - Federal Times<\/title>\n<meta name=\"description\" content=\"It\u2019s up to oversight bodies such as CISA, government leaders and industry partners to set baseline expectations for OSS use and ensure security.\" \/>\n<meta name=\"robots\" content=\"noindex, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Following the roadmap to open-source software security\" \/>\n<meta property=\"og:description\" content=\"It\u2019s up to oversight bodies such as CISA, government leaders and industry partners to set baseline expectations for OSS use and ensure security.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/one.sightlinemg.com\/federaltimes\/opinions\/2023\/11\/09\/following-the-roadmap-to-open-source-software-security\/\" \/>\n<meta property=\"og:site_name\" content=\"Federal Times\" \/>\n<meta property=\"article:published_time\" content=\"2023-11-09T18:53:36+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-08-08T18:56:01+00:00\" \/>\n<meta name=\"author\" content=\"Joel Krooswyk\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Joel Krooswyk\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"5 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\n\t    \"@context\": \"https:\\\/\\\/schema.org\",\n\t    \"@graph\": [\n\t        {\n\t            \"@type\": \"Article\",\n\t            \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/opinions\\\/2023\\\/11\\\/09\\\/following-the-roadmap-to-open-source-software-security\\\/#article\",\n\t            \"isPartOf\": {\n\t                \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/opinions\\\/2023\\\/11\\\/09\\\/following-the-roadmap-to-open-source-software-security\\\/\"\n\t            },\n\t            \"author\": {\n\t                \"name\": \"migration\",\n\t                \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/#\\\/schema\\\/person\\\/cc76c831bb37a926738c8391fca7a3b1\"\n\t            },\n\t            \"headline\": \"Following the roadmap to open-source software security\",\n\t            \"datePublished\": \"2023-11-09T18:53:36+00:00\",\n\t            \"dateModified\": \"2026-08-08T18:56:01+00:00\",\n\t            \"mainEntityOfPage\": {\n\t                \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/opinions\\\/2023\\\/11\\\/09\\\/following-the-roadmap-to-open-source-software-security\\\/\"\n\t            },\n\t            \"wordCount\": 952,\n\t            \"commentCount\": 0,\n\t            \"publisher\": {\n\t                \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/#organization\"\n\t            },\n\t            \"image\": {\n\t                \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/opinions\\\/2023\\\/11\\\/09\\\/following-the-roadmap-to-open-source-software-security\\\/#primaryimage\"\n\t            },\n\t            \"thumbnailUrl\": \"https:\\\/\\\/one.sightlinemg.com\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/AP1109301107397.jpg.jpg\",\n\t            \"articleSection\": [\n\t                \"Home\",\n\t                \"IT &amp; Networks\",\n\t                \"Opinion\"\n\t            ],\n\t            \"inLanguage\": \"en-US\",\n\t            \"potentialAction\": [\n\t                {\n\t                    \"@type\": \"CommentAction\",\n\t                    \"name\": \"Comment\",\n\t                    \"target\": [\n\t                        \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/opinions\\\/2023\\\/11\\\/09\\\/following-the-roadmap-to-open-source-software-security\\\/#respond\"\n\t                    ]\n\t                }\n\t            ]\n\t        },\n\t        {\n\t            \"@type\": \"WebPage\",\n\t            \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/opinions\\\/2023\\\/11\\\/09\\\/following-the-roadmap-to-open-source-software-security\\\/\",\n\t            \"url\": \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/opinions\\\/2023\\\/11\\\/09\\\/following-the-roadmap-to-open-source-software-security\\\/\",\n\t            \"name\": \"Following the roadmap to open-source software security - Federal Times\",\n\t            \"isPartOf\": {\n\t                \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/#website\"\n\t            },\n\t            \"primaryImageOfPage\": {\n\t                \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/opinions\\\/2023\\\/11\\\/09\\\/following-the-roadmap-to-open-source-software-security\\\/#primaryimage\"\n\t            },\n\t            \"image\": {\n\t                \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/opinions\\\/2023\\\/11\\\/09\\\/following-the-roadmap-to-open-source-software-security\\\/#primaryimage\"\n\t            },\n\t            \"thumbnailUrl\": \"https:\\\/\\\/one.sightlinemg.com\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/AP1109301107397.jpg.jpg\",\n\t            \"datePublished\": \"2023-11-09T18:53:36+00:00\",\n\t            \"dateModified\": \"2026-08-08T18:56:01+00:00\",\n\t            \"description\": \"It\u2019s up to oversight bodies such as CISA, government leaders and industry partners to set baseline expectations for OSS use and ensure security.\",\n\t            \"breadcrumb\": {\n\t                \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/opinions\\\/2023\\\/11\\\/09\\\/following-the-roadmap-to-open-source-software-security\\\/#breadcrumb\"\n\t            },\n\t            \"inLanguage\": \"en-US\",\n\t            \"potentialAction\": [\n\t                {\n\t                    \"@type\": \"ReadAction\",\n\t                    \"target\": [\n\t                        \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/opinions\\\/2023\\\/11\\\/09\\\/following-the-roadmap-to-open-source-software-security\\\/\"\n\t                    ]\n\t                }\n\t            ]\n\t        },\n\t        {\n\t            \"@type\": \"ImageObject\",\n\t            \"inLanguage\": \"en-US\",\n\t            \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/opinions\\\/2023\\\/11\\\/09\\\/following-the-roadmap-to-open-source-software-security\\\/#primaryimage\",\n\t            \"url\": \"https:\\\/\\\/one.sightlinemg.com\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/AP1109301107397.jpg.jpg\",\n\t            \"contentUrl\": \"https:\\\/\\\/one.sightlinemg.com\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/AP1109301107397.jpg.jpg\"\n\t        },\n\t        {\n\t            \"@type\": \"BreadcrumbList\",\n\t            \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/opinions\\\/2023\\\/11\\\/09\\\/following-the-roadmap-to-open-source-software-security\\\/#breadcrumb\",\n\t            \"itemListElement\": [\n\t                {\n\t                    \"@type\": \"ListItem\",\n\t                    \"position\": 1,\n\t                    \"name\": \"Home\",\n\t                    \"item\": \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/\",\n\t                    \"ad_zone\": \"home\"\n\t                },\n\t                {\n\t                    \"@type\": \"ListItem\",\n\t                    \"position\": 2,\n\t                    \"name\": \"Opinion\",\n\t                    \"item\": \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/opinions\\\/\",\n\t                    \"ad_zone\": \"opinions\"\n\t                },\n\t                {\n\t                    \"@type\": \"ListItem\",\n\t                    \"position\": 3,\n\t                    \"name\": \"Following the roadmap to open-source software security\"\n\t                }\n\t            ]\n\t        },\n\t        {\n\t            \"@type\": \"WebSite\",\n\t            \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/#website\",\n\t            \"url\": \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/\",\n\t            \"name\": \"Federal Times\",\n\t            \"description\": \"Federal Times\",\n\t            \"publisher\": {\n\t                \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/#organization\"\n\t            },\n\t            \"potentialAction\": [\n\t                {\n\t                    \"@type\": \"SearchAction\",\n\t                    \"target\": {\n\t                        \"@type\": \"EntryPoint\",\n\t                        \"urlTemplate\": \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/?s={search_term_string}\"\n\t                    },\n\t                    \"query-input\": {\n\t                        \"@type\": \"PropertyValueSpecification\",\n\t                        \"valueRequired\": true,\n\t                        \"valueName\": \"search_term_string\"\n\t                    }\n\t                }\n\t            ],\n\t            \"inLanguage\": \"en-US\"\n\t        },\n\t        {\n\t            \"@type\": \"Organization\",\n\t            \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/#organization\",\n\t            \"name\": \"Federal Times\",\n\t            \"url\": \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/\",\n\t            \"logo\": {\n\t                \"@type\": \"ImageObject\",\n\t                \"inLanguage\": \"en-US\",\n\t                \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/#\\\/schema\\\/logo\\\/image\\\/\",\n\t                \"url\": \"https:\\\/\\\/one.sightlinemg.com\\\/wp-content\\\/uploads\\\/2026\\\/06\\\/federal-logo-white.png\",\n\t                \"contentUrl\": \"https:\\\/\\\/one.sightlinemg.com\\\/wp-content\\\/uploads\\\/2026\\\/06\\\/federal-logo-white.png\",\n\t                \"caption\": \"Federal Times\"\n\t            },\n\t            \"image\": {\n\t                \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/#\\\/schema\\\/logo\\\/image\\\/\"\n\t            }\n\t        },\n\t        {\n\t            \"@type\": \"Person\",\n\t            \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/#\\\/schema\\\/person\\\/cc76c831bb37a926738c8391fca7a3b1\",\n\t            \"name\": \"migration\",\n\t            \"image\": {\n\t                \"@type\": \"ImageObject\",\n\t                \"inLanguage\": \"en-US\",\n\t                \"@id\": \"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/9e8d47be443ce94ce7fc357677b5f9c70235bb1f59e7267a102a74af58c04f59?s=96&d=mm&r=gcf4cb6ee0ec29e49e7a963234e4340ec\",\n\t                \"url\": \"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/9e8d47be443ce94ce7fc357677b5f9c70235bb1f59e7267a102a74af58c04f59?s=96&d=mm&r=g\",\n\t                \"contentUrl\": \"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/9e8d47be443ce94ce7fc357677b5f9c70235bb1f59e7267a102a74af58c04f59?s=96&d=mm&r=g\",\n\t                \"caption\": \"migration\"\n\t            },\n\t            \"url\": \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/author\\\/migration\\\/\"\n\t        }\n\t    ]\n\t}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"Following the roadmap to open-source software security - Federal Times","description":"It\u2019s up to oversight bodies such as CISA, government leaders and industry partners to set baseline expectations for OSS use and ensure security.","robots":{"index":"noindex","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"og_locale":"en_US","og_type":"article","og_title":"Following the roadmap to open-source software security","og_description":"It\u2019s up to oversight bodies such as CISA, government leaders and industry partners to set baseline expectations for OSS use and ensure security.","og_url":"https:\/\/one.sightlinemg.com\/federaltimes\/opinions\/2023\/11\/09\/following-the-roadmap-to-open-source-software-security\/","og_site_name":"Federal Times","article_published_time":"2023-11-09T18:53:36+00:00","article_modified_time":"2026-08-08T18:56:01+00:00","author":"Joel Krooswyk","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Joel Krooswyk","Est. reading time":"5 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/one.sightlinemg.com\/federaltimes\/opinions\/2023\/11\/09\/following-the-roadmap-to-open-source-software-security\/#article","isPartOf":{"@id":"https:\/\/one.sightlinemg.com\/federaltimes\/opinions\/2023\/11\/09\/following-the-roadmap-to-open-source-software-security\/"},"author":{"name":"migration","@id":"https:\/\/one.sightlinemg.com\/federaltimes\/#\/schema\/person\/cc76c831bb37a926738c8391fca7a3b1"},"headline":"Following the roadmap to open-source software security","datePublished":"2023-11-09T18:53:36+00:00","dateModified":"2026-08-08T18:56:01+00:00","mainEntityOfPage":{"@id":"https:\/\/one.sightlinemg.com\/federaltimes\/opinions\/2023\/11\/09\/following-the-roadmap-to-open-source-software-security\/"},"wordCount":952,"commentCount":0,"publisher":{"@id":"https:\/\/one.sightlinemg.com\/federaltimes\/#organization"},"image":{"@id":"https:\/\/one.sightlinemg.com\/federaltimes\/opinions\/2023\/11\/09\/following-the-roadmap-to-open-source-software-security\/#primaryimage"},"thumbnailUrl":"https:\/\/one.sightlinemg.com\/wp-content\/uploads\/2026\/08\/AP1109301107397.jpg.jpg","articleSection":["Home","IT &amp; Networks","Opinion"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/one.sightlinemg.com\/federaltimes\/opinions\/2023\/11\/09\/following-the-roadmap-to-open-source-software-security\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/one.sightlinemg.com\/federaltimes\/opinions\/2023\/11\/09\/following-the-roadmap-to-open-source-software-security\/","url":"https:\/\/one.sightlinemg.com\/federaltimes\/opinions\/2023\/11\/09\/following-the-roadmap-to-open-source-software-security\/","name":"Following the roadmap to open-source software security - Federal Times","isPartOf":{"@id":"https:\/\/one.sightlinemg.com\/federaltimes\/#website"},"primaryImageOfPage":{"@id":"https:\/\/one.sightlinemg.com\/federaltimes\/opinions\/2023\/11\/09\/following-the-roadmap-to-open-source-software-security\/#primaryimage"},"image":{"@id":"https:\/\/one.sightlinemg.com\/federaltimes\/opinions\/2023\/11\/09\/following-the-roadmap-to-open-source-software-security\/#primaryimage"},"thumbnailUrl":"https:\/\/one.sightlinemg.com\/wp-content\/uploads\/2026\/08\/AP1109301107397.jpg.jpg","datePublished":"2023-11-09T18:53:36+00:00","dateModified":"2026-08-08T18:56:01+00:00","description":"It\u2019s up to oversight bodies such as CISA, government leaders and industry partners to set baseline expectations for OSS use and ensure security.","breadcrumb":{"@id":"https:\/\/one.sightlinemg.com\/federaltimes\/opinions\/2023\/11\/09\/following-the-roadmap-to-open-source-software-security\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/one.sightlinemg.com\/federaltimes\/opinions\/2023\/11\/09\/following-the-roadmap-to-open-source-software-security\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/one.sightlinemg.com\/federaltimes\/opinions\/2023\/11\/09\/following-the-roadmap-to-open-source-software-security\/#primaryimage","url":"https:\/\/one.sightlinemg.com\/wp-content\/uploads\/2026\/08\/AP1109301107397.jpg.jpg","contentUrl":"https:\/\/one.sightlinemg.com\/wp-content\/uploads\/2026\/08\/AP1109301107397.jpg.jpg"},{"@type":"BreadcrumbList","@id":"https:\/\/one.sightlinemg.com\/federaltimes\/opinions\/2023\/11\/09\/following-the-roadmap-to-open-source-software-security\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/one.sightlinemg.com\/federaltimes\/","ad_zone":"home"},{"@type":"ListItem","position":2,"name":"Opinion","item":"https:\/\/one.sightlinemg.com\/federaltimes\/opinions\/","ad_zone":"opinions"},{"@type":"ListItem","position":3,"name":"Following the roadmap to open-source software security"}]},{"@type":"WebSite","@id":"https:\/\/one.sightlinemg.com\/federaltimes\/#website","url":"https:\/\/one.sightlinemg.com\/federaltimes\/","name":"Federal Times","description":"Federal Times","publisher":{"@id":"https:\/\/one.sightlinemg.com\/federaltimes\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/one.sightlinemg.com\/federaltimes\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/one.sightlinemg.com\/federaltimes\/#organization","name":"Federal Times","url":"https:\/\/one.sightlinemg.com\/federaltimes\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/one.sightlinemg.com\/federaltimes\/#\/schema\/logo\/image\/","url":"https:\/\/one.sightlinemg.com\/wp-content\/uploads\/2026\/06\/federal-logo-white.png","contentUrl":"https:\/\/one.sightlinemg.com\/wp-content\/uploads\/2026\/06\/federal-logo-white.png","caption":"Federal Times"},"image":{"@id":"https:\/\/one.sightlinemg.com\/federaltimes\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/one.sightlinemg.com\/federaltimes\/#\/schema\/person\/cc76c831bb37a926738c8391fca7a3b1","name":"migration","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/9e8d47be443ce94ce7fc357677b5f9c70235bb1f59e7267a102a74af58c04f59?s=96&d=mm&r=gcf4cb6ee0ec29e49e7a963234e4340ec","url":"https:\/\/secure.gravatar.com\/avatar\/9e8d47be443ce94ce7fc357677b5f9c70235bb1f59e7267a102a74af58c04f59?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/9e8d47be443ce94ce7fc357677b5f9c70235bb1f59e7267a102a74af58c04f59?s=96&d=mm&r=g","caption":"migration"},"url":"https:\/\/one.sightlinemg.com\/federaltimes\/author\/migration\/"}]}},"jetpack_sharing_enabled":true,"distributor_meta":false,"distributor_terms":false,"distributor_media":false,"distributor_original_site_name":"Federal Times","distributor_original_site_url":"https:\/\/one.sightlinemg.com\/federaltimes","push-errors":false,"jetpack_featured_media_url":"https:\/\/one.sightlinemg.com\/wp-content\/uploads\/2026\/08\/AP1109301107397.jpg.jpg","_links":{"self":[{"href":"https:\/\/one.sightlinemg.com\/federaltimes\/wp-json\/wp\/v2\/posts\/32470","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/one.sightlinemg.com\/federaltimes\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/one.sightlinemg.com\/federaltimes\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/one.sightlinemg.com\/federaltimes\/wp-json\/wp\/v2\/users\/7"}],"replies":[{"embeddable":true,"href":"https:\/\/one.sightlinemg.com\/federaltimes\/wp-json\/wp\/v2\/comments?post=32470"}],"version-history":[{"count":1,"href":"https:\/\/one.sightlinemg.com\/federaltimes\/wp-json\/wp\/v2\/posts\/32470\/revisions"}],"predecessor-version":[{"id":32473,"href":"https:\/\/one.sightlinemg.com\/federaltimes\/wp-json\/wp\/v2\/posts\/32470\/revisions\/32473"}],"wp:attachment":[{"href":"https:\/\/one.sightlinemg.com\/federaltimes\/wp-json\/wp\/v2\/media?parent=32470"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/one.sightlinemg.com\/federaltimes\/wp-json\/wp\/v2\/categories?post=32470"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/one.sightlinemg.com\/federaltimes\/wp-json\/wp\/v2\/tags?post=32470"},{"taxonomy":"author","embeddable":true,"href":"https:\/\/one.sightlinemg.com\/federaltimes\/wp-json\/wp\/v2\/coauthors?post=32470"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}