OpenSSF ããªãŒãã³ãœãŒã¹ ãœãããŠã§ã¢ã®äœ¿çšãæé©åããããã®ãªãŒãã³ãœãŒã¹æ¶è²»ãããã§ã¹ããçºè¡š
Open Source Security Foundation (OpenSSF) ã¯ããªãŒãã³ãœãŒã¹ ãœãããŠã§ã¢ã®äœ¿çšã匷åããããã«ããªãŒãã³ãœãŒã¹æ¶è²»ãããã§ã¹ããçºè¡šããŸããã

ãªãŒãã³ãœãŒã¹ ãœãããŠã§ã¢ (OSS) ã®ã¡ãªãããããè³¢æã«ã«ãã»ã«åããããã®é²æ©çãªã¹ããããšããŠãOpen Source Security Foundation (OpenSSF) 㯠Open Source Consumption Manifesto (OSCM) ãç«ã¡äžããŸããã象城çãªã¢ãžã£ã€ã«å®£èšã«äŒŒã OSCM ã¯ãæ žãšãªã䟡å€èгã«ãã£ãŠåŒ·åãããææžã§ããããªãŒãã³ãœãŒã¹ã®äœ¿çšãåçåããããã«èšèšããã 15 ã®æéãå«ãŸããŠããŸãã
ãªãŒãã³ãœãŒã¹ ãœãããŠã§ã¢ããæ°é²æ°éã®ã€ãããŒã·ã§ã³ãšéçšå¹çã®åäžã«è²¢ç®ããŠããããšã¯çãã®äœå°ããããŸããããã ããOSS ãããžã§ã¯ãããšã«å質ãšã»ãã¥ãªãã£ã®ç¹ã§å€§ããªéããããããšã¯åšç¥ã®äºå®ã§ãããã®çµæãOpenSSF ã¯ã倿°ã®çµç¹ã«ããã£ãŠ OSS ãå©çšããããã®æŠç¥çã¢ãããŒããæ¬ åŠããŠããããšãæµ®ã圫ãã«ããŸããã
䟿å©ããè©°ã蟌ãŸããŠããããã«èŠãã OSS ã§ãããOSS èªäœã«ãå€ãã®æ¬ é¥ããããŸãã OSS ãåããè©äŸ¡ããã»ã¹ã«ãããŠãç¹ã«ãµãŒãããŒã㣠ãœãããŠã§ã¢ãšæ¯èŒããå Žåã«ãé©ãã¹ãé倱ã芳å¯ãããŠããŸããã»ãã¥ãªãã£ãã³ãŒãå質ãã©ã€ã»ã³ã¹ã®èгç¹ããããããåããŠãã粟æ»ã¯ãæ§ããã«èšã£ãŠãäžååã§ããããã¯ãOpenSSF ãšã³ã ãŠãŒã¶ãŒ ã¯ãŒãã³ã° ã°ã«ãŒãã«ãã£ãŠææãããŠããããã«ãé倧ãªãªã¹ã¯èŠå ãå¿ã³å¯ãããšã«ã€ãªãããŸãã
ãµãŒãããŒã㣠ãœãããŠã§ã¢ã«æªæã®ããã³ã³ãã³ããå«ãŸããå¯èœæ§ã¯äœãã§ãããOSS ã®è€éãã«æ £ããŠããªã人ã«ãšã£ãŠã¯ãããŠã³ããŒã段éã§ãªã¹ã¯ãé¡åšåããŸãã Sonatype ã®å ±ååµèšè å Œ CTO ã§ãã Brian Fox æ°ã¯ãSD Times ã§ OSS æ¶è²»ã®èœãšã穎ã«ã€ããŠè°è«ããä¿®æ£ããŒãžã§ã³ããã§ã«å©çšå¯èœã«ãªã£ãŠãããšãã«è匱ãªã³ã³ããŒãã³ããããŠã³ããŒããããã®ã 96% ã§ãããšè¿°ã¹ãŸããã
ãããã®åé¡ãèªèããOpenSSF ãšã³ã ãŠãŒã¶ãŒ ã¯ãŒãã³ã° ã°ã«ãŒãã¯ããããä¿®æ£ããæ¹æ³ãèæ¡ããããã«æŽ»åãéå§ããŸãããäžé£ã®è°è«ãçµãŠã圌ãã¯ãªãŒãã³ãœãŒã¹æ¶è²»å®£èšãèæ¡ããŸããã OSCM ã¯å³æ Œãªæãã§ã¯ãªããå æ¬æ§ã®å€§çŸ©ãæè·ããŠããããã®åœ¢ç¶ã¯ããã€ãã®åéããã®ã€ã³ãããã«ãã£ãŠåœ¢æãããŠããããã®ããã¹ãã¯ãããå©çšããå人ã«åºã¥ããŠæŽç·ŽãããŠããŸãã
ãã®ãããã§ã¹ãã«ã¯ãæ¢ç¥ã®è匱æ§ãæå®³ãªããã±ãŒãžã«é¢é£ããã³ã³ããŒãã³ãã®ç£æ»ããã³é颿©èœãéããŠãªãŒãã³ãœãŒã¹ã®å©çšã匷åãããªã©ã極ããŠéèŠãªèŠå®ãå«ãŸããŠããŸãã
æå³çã«æå®³ãªã³ã³ããŒãã³ãã«ããè åšã«å¯Ÿæããããã®æ¥µããŠéèŠãªææ®µã¯ãã³ã³ããŒãã³ãã®æ¶è²»ãç£èŠããå æ¬çãªè¿œè·¡ã·ã¹ãã ãå°å ¥ããããšã§ãããããããŒã¿ãè¡åãã£ãŒããšçµã¿åãããããšã§ãã·ã¹ãã ã¯ã詳现ãªç²Ÿæ»ãåŸ ã£ãŠäœããæ¿èªãã¹ããããããšãå²ãåœãŠãã¹ããããªã¢ã«ã¿ã€ã ã§å€æã§ããããã«ãªãããšãã©ãã¯ã¹æ°ã¯ä»ãå ããã
ãªãŒãã³ãœãŒã¹ ãœãããŠã§ã¢ã®å¯èŠ³æž¬æ§ãžã®éãæ©ã¿å§ããçµç¹ã«ãšã£ãŠãã¢ããªã±ãŒã·ã§ã³ãéèŠåºŠã«ãã£ãŠåé¡ããããšããå§ããããšã¯æçã§ãããã®åŸãéåžžã¯ãœãããŠã§ã¢éšå衚ãä»ããŠããããã®ã¢ããªã±ãŒã·ã§ã³ã«çµã¿èŸŒãŸããŠãã OSS ã®ã€ã³ãã³ããªãäœæããããŸããŸãªãµãã©ã€ã€ãŒãç¹å®ããå¿ èŠããããŸãã Fox æ°ã«ãããšãçŸåšãããªãã®æ°ã®éçºããŒã ããããã®éèŠãªã³ã³ããŒãã³ããå°å ¥ããŠããŸããã
ãã®åŸãããŸããŸãªãã®ã³ã° ãã¬ãŒã ã¯ãŒã¯ã䜿çšãããªã©ãåãæ©èœã«è€æ°ã®ãµãã©ã€ã€ãŒãæ¡çšãããŠããäŸãæ¢ãããšãè³¢æã§ããæ¬¡ã«éèŠãªã®ã¯ãå®å šãªãœãããŠã§ã¢éçºã®å®è·µãè©äŸ¡ããŠãæè¯ã®ãµãã©ã€ã€ãŒã«çŠç¹ãåœãŠãããšã§ãããã®è©äŸ¡ã¯ãæ¢ç¥ã®è匱æ§ããœãããŠã§ã¢ã®å€ãã人æ°ããããé©çšã«ãããå¹³åæéãªã©ã®èŠçŽ ã«ãã£ãŠæ±ºãŸããŸãã
åçµç¹ã¯ãç¬èªã®ãªã¹ã¯éžå¥œãšåè¿°ã®åæã«åºã¥ããŠæ±ºå®ã調æŽããå¿ èŠããããŸãã PII ããŒã¿ãåŠçããã¢ããªã±ãŒã·ã§ã³ã®æ¢ç¥ã®é倧ãªè匱æ§ã®çºèŠãªã©ãäžå®ã®æšæºçãªãªã¹ã¯èš±å®¹åºŠã¯ãããŸãããOSS 䜿çšããªã·ãŒã®äœæã¯ãéçºãã CI/CD ãŸã§ããããŠæãéèŠãªã®ã¯ãªãªãŒã¹æãŸã§ãSDLC å šäœã§ãããçµ±åããããšãæå³ããŸãã
倿§ãªno-codeããã³low-codeãã©ãããã©ãŒã ãæº¢ããŠããçŸåšã®ç¶æ³ã§ã¯ãOSCM ã®ãããªå¯Ÿçãæ¡çšããããšãéèŠã§ããããã¯ãšã³ããWebãã¢ãã€ã« ã¢ããªã±ãŒã·ã§ã³ãäœæããããã®å æ¬çãªno-codeããŒã«ã§ãã AppMaster ã®ãããªãã©ãããã©ãŒã ã¯ãOSS ã®éèŠæ§ãç¹°ãè¿ã匷調ãããªã¹ã¯ã軜æžãçç£æ§ãåäžãããããã« OSCM ã®ãããªææ®µã匷å¶ããŸããçµç¹ããªãŒãã³ãœãŒã¹ã®åãæå€§éã«æŽ»çšããã«ã¯ãæœåšçãªãªã¹ã¯ãšéå¹çãæå°éã«æããããšãéèŠã§ãããããã OSCM ãå€§å¹ ã«æ¯æŽããŸãã


