CyberzSOC

Publication detail
← Back to advisories & guidance

CISA Partners With OpenSSF Securing Software Repositories Working Group to Release Principles for Package Repository Security ↗ source

February 8, 2024 CISA Alert

Summary

Recognizing the critical role package repositories play in securing open source software ecosystems, this framework lays out voluntary security maturity levels for package repositories. This publication supports Objective 1.2 of CISA's Open Source Software Security Roadmap , which states the goal of "working collaboratively [with relevant working groups] to develop security principles for package managers." This product is provided subject to this Notification and this Privacy & Use policy.

News Coverage

No coverage found in monitored research blogs or news feeds.

CVEs Referenced in This Publication

No CVEs are referenced in this publication.

Vendors Named in This Publication

No KEV-catalogued vendors are named in this publication.