Tech giants band together to form the GitHub Security Lab

The likes of Mozilla, Intel and Oracle have joined with Microsoft for the open-source project

Some of the biggest tech firms have joined forces to launch a community-led GitHub scheme in which researchers will hunt down and fix bugs in open-source projects.

The co-operative effort will see security researchers report new vulnerabilities in open source projects using GitHub's newly-developed CodeQL tool. This semantic code analysis engine will let users query code as if it were data, in order to find all variants of a discovered vulnerability, and then share findings with the wider community.

Advertisement - Article continues below

GitHub's Security Lab will also work to build tools to better secure code-bases, more effectively connect the wider security community, and bring developers together as well.

"GitHub's approach to security addresses the whole open source security lifecycle," said vice president for product management and security Jamie Cool.

"GitHub Security Lab will help identify and report vulnerabilities in open source software, while maintainers and developers use GitHub to create fixes, coordinate disclosure, and update dependent projects to a fixed version."

The initiative has launched as a 14-strong collaboration between F5 Networks, GitHub, Google, HackerOne, Intel, IOActive, JP Morgan, Microsoft, Mozilla, NCC Group, Okta, Trail of Bits, Uber and VMware.

The team behind Security Lab will dedicate full-time resources into finding and reporting vulnerabilities, and has already found more than 100 issues deemed serious enough to be issued with CVE categorisations.

Advertisement
Advertisement - Article continues below

The CodeQL tool, developed by GitHub, is also being made open-source, with users able to explore reams of open source code to find vulnerabilities, especially different versions of the same vulnerability that can otherwise be difficult to trace.

Advertisement - Article continues below

Developers are also being incentivised to contribute through a bug bounty programme which offers an award of up to $2,500, depending on the severity of the flaw and the quality of the submitted query.

GitHub's initiative is similar in nature to a host of other organisations that have been created in recent years to combat the rising tide of cyber crime, and bolster cyber security in general.

Microsoft, for example, is also a founding member of the CyberPeace Institute, which was established alongside Mastercard and the Hewlett Foundation in September to combat global cyber crime.

Mozilla, Intel and Red Hat among others were also part of a just freshly-launched initiative to make the software development process more secure. The Bytecode Alliance will be an open source community dedicated to creating secure software foundations.

Featured Resources

Preparing for long-term remote working after COVID-19

Learn how to safely and securely enable your remote workforce

Download now

Cloud vs on-premise storage: What’s right for you?

Key considerations driving document storage decisions for businesses

Download now

Staying ahead of the game in the world of data

Create successful marketing campaigns by understanding your customers better

Download now

Transforming productivity

Solutions that facilitate work at full speed

Download now
Advertisement

Most Popular

Visit/business/business-operations/356395/nvidia-overtakes-intel-as-most-valuable-us-chipmaker
Business operations

Nvidia overtakes Intel as most valuable US chipmaker

9 Jul 2020
Visit/laptops/29190/how-to-find-ram-speed-size-and-type
Laptops

How to find RAM speed, size and type

24 Jun 2020
Visit/security/cyber-attacks/356417/trump-confirms-cyber-attacks-on-russia-election-trolls
cyber attacks

Trump confirms US cyber attack on Russia election trolls

13 Jul 2020