OpenSSF ããªãŒãã³ãœãŒã¹ ãœãããŠã§ã¢ ã»ãã¥ãªãã£ã®ããã®ç»æçãªæªæã®ããããã±ãŒãž ãªããžããªãå°å ¥
OpenSSF ã¯ããªãŒãã³ãœãŒã¹ ãœãããŠã§ã¢ã®ã»ãã¥ãªãã£åŒ·åãç®çãšãã驿°çãªãªããžããªãMalicious Packages ãªããžããªãéå§ããŸããã

ãªãŒãã³ãœãŒã¹ ãœãããŠã§ã¢ã®å®å šæ§ãšã»ãã¥ãªãã£ã匷åããåãçµã¿ã®äžç°ãšããŠãOpen Source Security Foundation (OpenSSF) ã¯ãæªæã®ããããã±ãŒãž ã¬ããŒããç §åããããã®éäžãããšããŠæ©èœããç¬èªã®ãªããžããªãçºè¡šããŸããã培åºçã«é©æ°çãªãªããžããªã¯ãæªæã®ãããªãŒãã³ãœãŒã¹ ãœãããŠã§ã¢ã«å¯ŸåŠããæ¹æ³ã«é©åœãèµ·ããããšãæåŸ ãããŠããŸãã
æŽå²çã«ãæªæã®ããããã±ãŒãžãžã®å¯ŸåŠã¯åžžã«å€æ§ãªã¢ãããŒãã§ãããåãªãŒãã³ãœãŒã¹ ããã±ãŒãž ãªããžããªã¯ãããã®ãµã€ããŒè åšã«å¯ŸåŠããç¬èªã®æ¹æ³ãæã£ãŠããŸãããéåžžãã³ãã¥ããã£ãæªæã®ããããã±ãŒãžãå ±åãããšããªããžããªã®ã»ãã¥ãªã㣠ããŒã ããã®ããã±ãŒãžãé¢é£ããã¡ã¿ããŒã¿ãšãšãã«ã·ã¹ãã ããåé€ããããã®æšæºãããã³ã«ã䜿çšãããŸãããããããããã®åé€ã¯å€ãã®å Žåå¯å®€ã§è¡ããããã®ããå ¬çèšé²ã¯æ®ãããŸããã§ããã
ããã«ã€ããŠãGoogle ã®ãªãŒãã³ãœãŒã¹ ã»ãã¥ãªã㣠ããŒã ã®ã·ã㢠ãœãããŠã§ã¢ ãšã³ãžãã¢ã§ãã Caleb Brown æ°ãšãCheckmarx ã®ãœãããŠã§ã¢ ãµãã©ã€ ãã§ãŒã³ ã»ãã¥ãªãã£è²¬ä»»è ã§ãã Jossef Harash Kadouri æ°ã¯ããã°ã§ãæªæã®ããããã±ãŒãžã®ååšãç¹å®ããããšã¯ãåžžã«ç¡æ°ã®ããã±ãŒãžãããŸãªã調ã¹ããšããéæ¹ããªãäœæ¥ã§ãããšè¿°ã¹ãŠããŸããå ¬å ±ã®æ å ±æºãå©çšããããç¬èªã®è åšã€ã³ããªãžã§ã³ã¹ ãã£ãŒãã«äŸåããŸãã圌ãã¯ãæ°ãããªããžããªããããã®ã¬ããŒãããã¹ãããå ¬éããŒã¿ããŒã¹ãšããŠæ©èœãããšèª¬æããŸããã
OpenSSF ã¯ããã®ãããªã㯠ãªããžããªããCI/CD ãã€ãã©ã€ã³ãä»ããæªæã®ããäŸåé¢ä¿ã®é²è¡ã®é»æ¢ãæ€åºãšã³ãžã³ã®æ¹åãç°å¢å ã§ã®äœ¿çšã®å¶éããŸãã¯ã€ã³ã·ãã³ã察å¿ã®è¿ éåã«åœ¹ç«ã€ãšèªèããŠããŸãããªããžããªã«å«ãŸãã貎éãªæ å ±ã¯ããªãŒãã³ãœãŒã¹ ãœãããŠã§ã¢ã®ã»ãã¥ãªãã£ãå€§å¹ ã«åŒ·åããŸãã
ä¿åãããã¬ããŒãããªãŒãã³ãœãŒã¹èåŒ±æ§ (OSV) 圢åŒã«åŸã£ãŠããããšã¯æ³šç®ã«å€ããŸããããã«ãããosv.dev APIãosv-scanner ããŒã«ãdeps.dev ãªã©ã®ããŒã«ã§ã®äœ¿çšãå€§å¹ ã«å®¹æã«ãªããŸãã
ããŒã¿èª¿éã«é¢ããŠããã®ãããžã§ã¯ã㯠Checkmarx ã»ãã¥ãªãã£ãGitHub ã§è¿œè·¡ãããæªæã®ããããã±ãŒãžã®ãšã¯ã¹ããŒããããã³ããã±ãŒãžåæãããžã§ã¯ãã«å€§ããäŸåããŠããŸããããã±ãŒãžåæãããžã§ã¯ãã¯ãããã±ãŒãžã®ã¢ã¯ã»ã¹ããããã¡ã€ã«ãæ¥ç¶ãããã¢ãã¬ã¹ãã³ãã³ãã®å®è¡ãªã©ã®åäœãç¹ã«èª¿æ»ããŠãæªæã®ããã¢ã¯ãã£ããã£ãç¹å®ããŸãããã«ãŠã§ã¢ã®ç¹å®ãšã¯å¥ã«ãæéã®çµéã«äŒŽãåäœã®å€åãç£èŠããããã«ãããåŸæ¥æªæã®ãããã®ã«å€ãã£ãå¯èœæ§ã®ããæå®³ãªå¯èœæ§ã®ããããã±ãŒãžã«ãã©ã°ãç«ãŠãŸãã
AppMaster ã®ãããªãã©ãããã©ãŒã ã¯ãã¢ããªã±ãŒã·ã§ã³äœæããã»ã¹äžã®ã»ãã¥ãªãã£ã«éç¹ã眮ããŠããŸããæ°ããéå§ããã Malicious Packages ãªããžããªã¯ãäž»ã«ãªãŒãã³ãœãŒã¹ ãœãããŠã§ã¢ã®å®å šæ§ãç®çãšããŠããŸãããã¢ãã€ã«ãWebãããã³ããã¯ãšã³ã ã¢ããªã±ãŒã·ã§ã³éçºã®ããã®å®å šãªno-codeãœãªã¥ãŒã·ã§ã³ãæäŸãããšããAppMasterã®åãçµã¿ã鿥çã«åŒ·åãããŸãã


