<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
     xmlns:content="http://purl.org/rss/1.0/modules/content/"
     xmlns:dc="https://purl.org/dc/elements/1.1/"
     xmlns:dcterms="http://purl.org/dc/terms/"
     xmlns:media="http://search.yahoo.com/mrss/"
     xmlns:atom="http://www.w3.org/2005/Atom"
     xmlns:cf="https://www.futureplc.com/rss/content-flags"
>
    <channel>
                    <atom:link href="https://www.itpro.com/feeds/tag/open-source" rel="self" type="application/rss+xml" />
                            <title><![CDATA[ Latest from ITPro in Open-source ]]></title>
                <link>https://www.itpro.com/software/open-source</link>
        <description><![CDATA[ All the latest open-source content from the ITPro team ]]></description>
                                    <lastBuildDate>Thu, 23 Jul 2026 11:57:23 +0000</lastBuildDate>
                            <language>en</language>
                                <item>
                                                            <title><![CDATA[ ‘These Chinese models are excellent’: Nvidia CEO Jensen Huang hails powerful new Chinese AI models like Kimi K3 – and says don’t be put off by security ‘misconceptions’ ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/software/open-source/these-chinese-models-are-excellent-nvidia-ceo-jensen-huang-hails-powerful-new-chinese-ai-models-like-kimi-k3-and-says-dont-be-put-off-by-security-misconceptions</link>
                                                                            <description>
                            <![CDATA[ As powerful new AI models like Kimi K3 hit the market, Huang says competition will be a positive for the global industry ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">TPXwaJQQSfDmtup4qWjdaF</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Nx4Vkmnsn4FBGv225qYypT-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 23 Jul 2026 11:57:23 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Open Source]]></category>
                                                    <category><![CDATA[Software]]></category>
                                                                                                <author><![CDATA[ ross.kelly@futurenet.com (Ross Kelly) ]]></author>                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Ross Kelly is ITPro&#039;s News &amp;amp; Analysis Editor, with a keen interest in cyber security, business leadership and emerging technologies.&lt;/p&gt;
&lt;p&gt;He graduated from Edinburgh Napier University in 2016 with a BA (Hons) in Journalism, and joined ITPro in 2022 after four years working in technology conference research.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;In his spare time, Ross enjoys cycling, walking and is an avid reader of history and non-fiction.&lt;/p&gt;
&lt;p&gt;You can contact Ross at ross.kelly@futurenet.com or on &lt;a href=&quot;https://twitter.com/rosswritesetc&quot;&gt;Twitter&lt;/a&gt; and &lt;a href=&quot;https://www.linkedin.com/in/ross-kelly-18a54411a/&quot;&gt;LinkedIn&lt;/a&gt;.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Nx4Vkmnsn4FBGv225qYypT-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Nvidia CEO Jensen Huang pictured in his signature leather jacket giving a thumbs up during a photo session following a joint press conference with representatives of Fujitsu.]]></media:description>                                                            <media:text><![CDATA[Nvidia CEO Jensen Huang pictured in his signature leather jacket giving a thumbs up during a photo session following a joint press conference with representatives of Fujitsu.]]></media:text>
                                <media:title type="plain"><![CDATA[Nvidia CEO Jensen Huang pictured in his signature leather jacket giving a thumbs up during a photo session following a joint press conference with representatives of Fujitsu.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Nx4Vkmnsn4FBGv225qYypT-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Nvidia CEO Jensen Huang has hailed the capabilities of Chinese open source AI models amidst growing interest in low-cost options for enterprises. </p><p>In an interview with <a href="https://www.axios.com/2026/07/22/nvidia-jensen-huang-china-open-source-ai" target="_blank"><u><em>Axios </em></u></a>this week, the Nvidia chief said competition between open and closed-source models is positive for the broader global AI industry. </p><p>“The world needs open models,” he told Axios. “These Chinese models are excellent. <a href="https://www.itpro.com/technology/artificial-intelligence/three-open-source-large-language-models-you-can-use-today">Open source models</a> that are excellent should be used”. </p><p>Huang’s comments come amidst growing interest in Chinese open source AI models in recent weeks. The Kimi K3 model, developed by Moonshot AI, temporarily paused subscriptions due to skyrocketing demand. </p><p>Surging interest in the Kimi K3 model bears similarities to that of DeepSeek, which <a href="https://www.itpro.com/technology/artificial-intelligence/the-deepseek-bombshell-has-been-a-wakeup-call-for-us-tech-giants">rocked the US AI industry </a>when it launched in early 2025. </p><p>A key advantage of these models lies in both their performance and cost efficiency, the latter of which has become a key focus for enterprises amidst growing concerns over spiralling AI costs in recent months. </p><p>As <a href="https://www.itpro.com/software/open-source/open-source-ai-performance-cost-savings-proprietary-models-linux-foundation"><u><em>ITPro </em></u><u>reported in November 2025</u></a>, open source AI models often perform on-par with closed source options, and could potentially save enterprises millions in costs each year.  </p><p>Open source models "routinely achieve 90% or more” of the performance of closed counterparts, the study noted. They also benefit from “significantly lower prices”, with operational costs plunging up to 84% in some cases. </p><p>In a <a href="https://go.redirectingat.com/?id=92X1583683&xcust=itpro_gb_1425528928358339126&xs=1&url=https%3A%2F%2Fwww.nature.com%2Farticles%2Fs41586-025-09422-z&sref=https%3A%2F%2Fwww.itpro.com" target="_blank"><u>research paper</u></a> published by DeepSeek last year, the company said it <a href="https://www.itpro.com/technology/artificial-intelligence/deepseeks-r1-model-training-costs-pour-cold-water-on-big-techs-massive-ai-spending"><u>spent a paltry amount training its flagship R1 model</u></a> compared to US rivals who’ve spent billions on training purposes. </p><p>Anthropic CEO Dario Amodei suggested <a href="https://www.itpro.com/technology/artificial-intelligence/dollar100-billion-to-build-an-ai-model-anthropic-ceo-dario-amodei-predicts-soaring-ai-training-costs-but-models-will-become-far-more-powerful"><u>building a new AI model could cost over $100 billion</u></a> in 2024. </p><h2 id="security-concerns-persist">Security concerns persist</h2><p>While the popularity of Chinese AI models continues rising, concerns over security have been flagged repeatedly. </p><p>The concerns surrounding Chinese AI models typically focus on areas such as data privacy and national security, with some critics suggesting these tools could be used as a ‘backdoor’ for Chinese intelligence services. </p><p><a href="https://www.axios.com/2026/07/20/ai-us-china-open-source-kimi" target="_blank"><u><em>Axios </em></u><u>previously reported</u></a> that the White House could consider imposing restrictions or tight conditions on US firms working with these models. </p><p>DeepSeek was <a href="https://www.itpro.com/technology/artificial-intelligence/deepseek-r1-model-jailbreak-security-flaws">subject to the same scrutiny</a> during its rise to prominence across 2025, for example. In August last year, <a href="https://www.itpro.com/security/using-deepseek-at-work-security-risks"><u>cybersecurity experts told </u><u><em>ITPro</em></u></a><em> </em>that using DeepSeek equated to “printing out and handing over your confidential information”. </p><p>Huang told Axios that these concerns are a “misconception” and can be used by enterprises safely. On the topic of potential White House restrictions, Huang said this could prove counterproductive and that American firms should consider a breadth of options. </p><p>“You can download the models. You could fine-tune it, you can enhance it, you can guardrail it as you desire,” he said. </p><p>Huang has a vested interest on this front, however, and noted that increased usage will ultimately benefit Nvidia. </p><p>“If there’s great AI, even if it’s open, wherever it comes from, there will be more use,” he told <em>Axios</em>. “Whenever there’s more use, you’ll have to sell a lot more Nvidia computers. We’ll have to build more data centers. We’ll have more services. The technology will diffuse into more industries”. </p><p>Bill Conner, president and CEO Jitterbit, said the Kimi K3 launch marks a “clear turning point in accelerating global adoption of Chinese LLMs” but still urged caution with regard to security. </p><p>“Enterprises may underestimate the security, accountability, and governance risks associated with adopting new Chinese LLMs,” he said. </p><p>“Moonshot AI operates as a cloud service with data stored in China, introducing potential risks for organizations whose data may be shared unknowingly.”</p><p>Conner said adoption of Chinese AI models should be treated as a “strategic risk decision, not merely a cost-saving opportunity”. </p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Will AI ring the death knell for open source? ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/software/open-source/will-ai-ring-the-death-knell-for-open-source</link>
                                                                            <description>
                            <![CDATA[ With projects facing fresh challenges in the AI era, the path forward remains murky ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">rBkKneeCWMuaMkbZAFDVL8</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/PnY54jNHbRiFpqgT9ex3R5-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 09 Jul 2026 07:00:00 +0000</pubDate>                                                                                                                                <updated>Mon, 13 Jul 2026 12:54:39 +0000</updated>
                                                                                                                                            <category><![CDATA[Open Source]]></category>
                                                    <category><![CDATA[Software]]></category>
                                                                                                <author><![CDATA[ keumars.afifi-sabet@futurenet.com (Keumars Afifi-Sabet) ]]></author>                    <dc:creator><![CDATA[ Keumars Afifi-Sabet ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/EAvwpZggMZ2K5h8s2pTAEm.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/PnY54jNHbRiFpqgT9ex3R5-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Female software developer using AI tools while coding at a desktop computer in an office space.]]></media:description>                                                            <media:text><![CDATA[Female software developer using AI tools while coding at a desktop computer in an office space.]]></media:text>
                                <media:title type="plain"><![CDATA[Female software developer using AI tools while coding at a desktop computer in an office space.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/PnY54jNHbRiFpqgT9ex3R5-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Open source can't catch a break. As the world of software development marches forward with new tools and capabilities expanding productivity – an evolution driven predominantly by <a href="https://www.itpro.com/strategy/28181/what-is-ai"><u>AI</u></a> – the community endures significant headwinds. </p><p>"In the age of AI-driven security threats, protecting customer data has to come first," <a href="https://cal.com/blog/cal-com-goes-closed-source-why"><u>wrote</u></a> Bailey Pumfleet, co-founder and CEO of scheduling software maker Cal.com, in April. </p><p>After five years as "open source champions", the company announced it would go "closed source". Cal.com is far from the only example, with several organizations and projects including Tailwind, curl, Jazzband, Godot – and even the U.K. <a href="https://www.digitalhealth.net/2026/05/nhse-to-move-away-from-open-source-over-ai-security-concerns/"><u>National Health Service</u></a> (NHS) – also struggling in the wake of AI.</p><p>Tension has always plagued open source, with concerns around funding, infrastructure, and even expectations management, negating any meaningful green shoots. The threat has <a href="https://www.itpro.com/development/open-source/370040/existential-tensions-put-open-source-on-the-warpath-to-crisis-point"><u>even been described as "existential"</u></a>, but the community has nevertheless survived and thrived, celebrating incredible adoption rates in recent years. But things feel different. AI poses an existential threat in many areas — but will it continue to hack away at the beleaguered open source community, or is there a viable path forward for the movement?</p><h2 id="open-source-is-battling-ai-centric-headwinds">Open source is battling AI-centric headwinds</h2><p>"In the past, exploiting an application required a highly skilled hacker with years of experience and a significant investment of time to find and exploit vulnerabilities," wrote Cal.com's Pumfleet in the blog post. The reality is that humans don’t have the time, attention, or patience to find everything. Today, AI can be pointed at an open source codebase and systematically scan it for vulnerabilities."</p><p>Security is just one aspect in an increasingly fraught dynamic. Tailwind, the organization behind a popular CSS framework that web developers incorporate into their projects, <a href="https://github.com/tailwindlabs/tailwindcss.com/pull/2388#issuecomment-3717222957"><u>announced on 7 January</u></a> it had slashed its four-person dev team to just one. The reason, CEO Adam Wathan cited, was "the brutal impact AI has had"; web traffic to documentation – which is the only way people can find out about its commercial products – was down 40% from early 2023. </p><p>There are also examples of projects struggling to cope with an onslaught of low-quality contributions. Take Godot, the open source game engine that's drowning in AI slop code pull requests (PRs), according to one of the primary maintainers, <a href="https://bsky.app/profile/akien.bsky.social/post/3meyerixvhs2p"><u>Rémi Verschelde</u></a>, who described this as "increasingly draining and demoralizing". </p><p>The Jazzband collective, a Python project ecosystem, was sunset this year after ten years of activity due to the "slopocalypse" with floods of PRs and AI-generated spam rendering "Jazzband’s model of open membership and shared push access untenable".</p><p>There are plenty of other issues to contend with. They may include the fact that using advanced AI tools may be gated on the need to spend money, and that it's unclear whether you're speaking with a human or an AI agent at any given time. </p><h2 id="how-open-source-projects-are-coping-with-ai">How open source projects are coping with AI</h2><p>Amanda Brock, CEO of OpenUK, tells <em>ITPro</em> that the industry is still grappling with AI as a novel force and different projects are handling it in different ways – with some handling it much better than others. "For some projects, they have not been able to manage the scale of it. And for some small companies, they have said they've had to close," she says, but added this isn't a universal experience, with others managing to get a grip on the headwinds.</p><p>"I'm skeptical about their business plan," Brock added on Tailwind, "and I could be wrong, and I'm not an authority on this in terms of each company's business and whether they were doing well enough. But I'm a bit skeptical when many are surviving about the few that are closing, and I don't know if that's the most vulnerable or the ones without the right business structures or teams."</p><p>However, Brock states the challenges are very real and unlike much else the community has experienced. For example: "When AI comes to Wikipedia, it not only comes at a huge scale by volume of eyes on the site or the pages, it looks at every page, and it does it in an instant. And the overwhelm is huge. And that's the equivalent of what open source projects feel when their repos are scraped; when they suddenly have this inbound volume from AI."</p><p>An example of a project that's fared better in wrestling with AI is Homebrew, the package manager. Its project leader Mike McQuaid tells <em>ITPro</em> Homebrew's response was to fight fire with fire. "We have had an increase in low-effort activity, but we respond with low effort," he says. "Our bots automatically close issues, we’ll close without review, we don’t dignify them with a response, et cetera."</p><p>McQuaid adds that, despite some notable examples, it's overstated that many projects are going closed source or winding down, and it's not representative of the wider experience. He says projects weather the storm "the same way we always have," with one measure including prioritizing maintainers' time, effort, and enjoyment over contributors, and prioritizing contributors over users. Responding to rudeness is also met with low effort, no effort, or blocking. He also suggested leaning very hard onto <a href="https://mikemcquaid.com/ruby-on-guard-rails/"><u>guardrails</u></a>.</p><h2 id="resolving-the-fate-of-open-source">Resolving the fate of open source</h2><p>McQuaid says the notion that AI could lead to the end of open source is "far too dramatic" and that there are plenty of positives to enjoy in a grand trade-off, despite there being an element of entering the unknown. These positive improvements include the way that AI allows some people to go much faster, that there are plenty of free AI tools available, and that many of these can help with code review, fixing bugs and triaging. </p><p>"It isn’t making huge negative changes without any positive remediations," he explains. "It’s just resetting people’s expectations of what 'working on open source' might be like for them. Some people won’t enjoy it any more. Many people equally are contributing who didn’t or wouldn’t before."</p><p>Despite many positive steps taken in the open source world over the last decade, Brock dwells in a sense of pessimism – but not entirely because of the immediate effects of AI. "I have been very pessimistic in some ways for a long time," she says, "because after lockdown everybody came out seeming to think that 'we'd won'." And what we'd won was, we've got a scale of adoption — but that scale of adoption wasn't matched by a scale of understanding, or funding.</p><p>"My worry was that you were going to see it, go full circle and end up back in proprietary because of exactly this kind of thing. I did not imagine AI, but I could see that things might happen, that meant that we were just overwhelmed because we got into a position where people expected an SLA-type delivery and support for free because the code was free."</p><h2 id="building-on-open-source-s-legacy">Building on open source's legacy</h2><p>"If it hadn't been AI, it would have been something else," Brock reiterates, saying the challenges have been piling up "at a time when people are reeling" one after another in the last few years. </p><p>"We've just had a decade since we really saw all this adoption start. We're a small group of experts [and scaling from] the small to the many hasn't worked."</p><p>Brock wants to see more gatekeeping, because "good projects have always gatekept". She adds: "There is this sense in the wider world that open source has always been a wild west, and that anybody can contribute – and that's just not the case."</p><p>Beyond that, she sees hope in models like the German <a href="https://www.sovereign.tech/"><u>Sovereign Tech Agency</u></a>, which brings together dozens of maintainers into standards development. There are calls in the U.K. for a similar system, with a foundation in the model of the Linux Foundation, or China's OpenAtom, that brings together expertise at a national level to work on intellectual property (IP), managing GitHub repos, and other key elements, for public sector open source.</p><p>By professionalizing the industry, however, you run the risk of losing projects when things go wrong. CHAOSS, a Linux Foundation project that measures open source health, is an example of a project in dire straits, having just lost its funding. Former director of data science Dawn Foster left her role in March, and the project has returned to the community.</p><p> But, Brock says, "it's hard to reignite the volunteers" when they see funded people doing the work. "So it all has to be done in a very careful, measured, and joined-up way across borders," she explains.</p><p>When it comes to the future, Brock remains adamant that urgent action is needed or open source will be consigned to history. "We're already seeing eight companies controlling the AI landscape," she says. </p><p>"If we allow open source to fail, the only organizations in the world that will be able to manage that are some of those big tech ones that will already have it in place. So I don't think it's in the human and public interest to allow open source to fail."</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ The UK is betting big on the power of open source AI ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/software/open-source/the-uk-is-betting-big-on-the-power-of-open-source-ai</link>
                                                                            <description>
                            <![CDATA[ The government wants to encourage open source developers to help improve public services ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">VKvLigwj5Yo3rAzn2K4an8</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/XUFTVxXHrTRAVBdujTYj6P-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 11 Jun 2026 10:56:20 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Open Source]]></category>
                                                    <category><![CDATA[Software]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/XUFTVxXHrTRAVBdujTYj6P-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Artificial intelligence (AI) concept image showing a digitized cube with &#039;AI&#039; written on it resting on top of circuit boards.]]></media:description>                                                            <media:text><![CDATA[Artificial intelligence (AI) concept image showing a digitized cube with &#039;AI&#039; written on it resting on top of circuit boards.]]></media:text>
                                <media:title type="plain"><![CDATA[Artificial intelligence (AI) concept image showing a digitized cube with &#039;AI&#039; written on it resting on top of circuit boards.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/XUFTVxXHrTRAVBdujTYj6P-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The UK government has announced a series of measures to support <a href="https://www.itpro.com/software/open-source/open-source-ai-just-got-a-major-seal-of-approval-from-us-regulators-but-will-it-push-developers-in-the-right-direction">open source AI developers</a> with funding, mentoring, and a direct line of communication into government.</p><p>A new Open-Source AI Builder Fund<em> </em>will see more than £500,000 worth of compute - 160,000 GPU-hours of processing power from the UK’s AI Research Resource - set aside for innovators to turn prototypes into AI tools that improve public services from libraries to the NHS. </p><p>An Open-Source AI Builder Mentoring Scheme will pair up the winners of a recent Hack for Impact hackathon with experts from the Incubator for Artificial Intelligence (i.AI), the government’s in-house AI team, to help the best ideas become working public tools. </p><p>Held in partnership with Nvidia, the hackathon saw hundreds of open source AI developers from across the UK build tools to tackle challenges across public services and city infrastructure, using open data from the City of London.  </p><p>A new Open-Source AI Dev Board, meanwhile, will give ten UK-based developers under the age of 30 a direct line into government, so they can influence how AI is used and developed. </p><p>Chaired by AI Minister Kanishka Narayan, the board will convene a series of roundtables over the rest of this year. </p><p>"The <a href="https://www.itpro.com/technology/artificial-intelligence/amazing-ai-tools-to-try-today">best AI tools</a> in the world won’t be built behind closed doors by a handful of companies. They’ll be built by people who ship code, share it, and let others make it better," said Narayan.  </p><p>"We want those people choosing to build here in Britain. And we want them to know that this is a country that backs them to succeed."</p><h2 id="open-source-focus-welcomed-but-work-still-to-be-done">Open source focus welcomed, but work still to be done</h2><p>The government’s focus on <a href="https://www.itpro.com/software/28109/what-is-open-source">open source</a> AI is a welcomed move, according to Sopra Steria CTO Andy Whitehurst. </p><p>Recent <a href="https://openuk.uk/wp-content/uploads/2026/04/Open-Source-Skills-Report-2026-1.pdf" target="_blank"><u>analysis from OpenUK</u></a> showed the UK’s community is growing at a nominal rate, with more than 38,000 UK-based developers now making at least one contribution to open source projects in Q1 2026 - a 7% year-on-year increase. </p><p>Whitehurst noted, however, that the UK tech industry still faces acute challenges in terms of marketing itself as a go-to destination. </p><p>"Targeted interventions like the builder fund and support programs are a positive step in helping projects move from prototype to real-world deployment, but economic uncertainty, constraints around data use, and the reality of a relatively small standalone market can still make the UK a harder proposition for some <a href="https://www.itpro.com/technology/artificial-intelligence/why-buy-vs-build-is-the-wrong-question-for-ai-strategy">AI providers</a>, particularly those that rely on large, diverse datasets or cross-border operations," he said. </p><p>Whitehurst added that if the UK wants to be a “true global AI leader” which attracts the best talent and supports its own “homegrown champions”, it needs to focus on three key foundations. </p><p>“Sovereignty, in terms of control over critical technology and data; scalability, so AI businesses can grow and adapt; and skills, to ensure a strong domestic talent pipeline,” he commented.</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ ‘Open source should rest on transparency, not deception’: Euro-Office ‘sovereignty’ claims questioned in scathing open letter by LibreOffice maintainers ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/software/open-source-should-rest-on-transparency-not-deception-euro-office-sovereignty-claims-questioned-in-scathing-open-letter-by-libreoffice-maintainers</link>
                                                                            <description>
                            <![CDATA[ The developers behind LibreOffice have questioned Euro-Office’s sovereignty credentials and use of a Microsoft-based document format ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">obnZGi3PbtuTrD58C9tvpV</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/YfH4YfBJwqGBq5tCEPQ77n-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 10 Jun 2026 10:21:05 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Software]]></category>
                                                                                                <author><![CDATA[ ross.kelly@futurenet.com (Ross Kelly) ]]></author>                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Ross Kelly is ITPro&#039;s News &amp;amp; Analysis Editor, with a keen interest in cyber security, business leadership and emerging technologies.&lt;/p&gt;
&lt;p&gt;He graduated from Edinburgh Napier University in 2016 with a BA (Hons) in Journalism, and joined ITPro in 2022 after four years working in technology conference research.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;In his spare time, Ross enjoys cycling, walking and is an avid reader of history and non-fiction.&lt;/p&gt;
&lt;p&gt;You can contact Ross at ross.kelly@futurenet.com or on &lt;a href=&quot;https://twitter.com/rosswritesetc&quot;&gt;Twitter&lt;/a&gt; and &lt;a href=&quot;https://www.linkedin.com/in/ross-kelly-18a54411a/&quot;&gt;LinkedIn&lt;/a&gt;.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/YfH4YfBJwqGBq5tCEPQ77n-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Digital sovereignty concept image showing digitized flag of the European Union (EU) imposed over a blue background with binary code. ]]></media:description>                                                            <media:text><![CDATA[Digital sovereignty concept image showing digitized flag of the European Union (EU) imposed over a blue background with binary code. ]]></media:text>
                                <media:title type="plain"><![CDATA[Digital sovereignty concept image showing digitized flag of the European Union (EU) imposed over a blue background with binary code. ]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/YfH4YfBJwqGBq5tCEPQ77n-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Euro-Office launched with a mind to shake up the productivity software space by giving European enterprises a “sovereign alternative” to products such as Google Workspace and Microsoft 365. </p><p>But it’s had a rocky start since launching this week, with critics lambasting the productivity suite as a “de facto ally of Microsoft”. </p><p>An <a href="https://blog.documentfoundation.org/blog/2026/06/08/an-open-letter/" target="_blank"><u>open letter</u></a> from The Document Foundation, the maintainers behind LibreOffice, detailed a series of gripes with Euro-Office. First and foremost, it claims the coalition responsible for development has deceptively marketed the product as the first open source productivity suite built in Europe. </p><p>That title, TDF noted, belongs to OpenOffice.org, which was launched in 2001 and based on StarOffice source code, and subsequently followed by LibreOffice in 2010. </p><p>“We feel compelled – reluctantly, since open source should rest on transparency, not deception – to correct this claim,” the open letter reads. “These are two genuine open-source office suites, built from source code that originated in Europe.”</p><h2 id="euro-office-document-format-slammed">Euro-Office document format slammed</h2><p>Adding insult to injury, TDF claims that the OOXML (Office Open XML) document format used by Euro-Office makes it a “de facto ally of Microsoft”.</p><p><a href="https://www.itpro.com/176100/ooxml-and-the-future-of-open-standards">OOXML </a>is a proprietary document format developed and controlled by Microsoft, and is used in the tech giant’s various document, spreadsheet, and presentation products. </p><p>The use of this format, TDF suggests, is a red flag for users aiming to shore up sovereignty practices by virtue of the fact control remains “firmly in Redmond and far from Europe”.</p><p>“Document formats are a subject still rife with misinformation. This is understandable on the part of Microsoft, which developed and controls the horrible proprietary OOXML format, designed precisely to prevent Digital Sovereignty by maintaining content lock-in,” the open letter reads. </p><p>“It is far less understandable on the part of companies that claim to advocate open source, such as those promoting Euro-Office.”</p><h2 id="opendocument-format-the-pillar-of-digital-sovereignty">OpenDocument Format the 'pillar of digital sovereignty'</h2><p>According to TDF, use of the ISO-standardized OpenDocument Format (ODF) should be used as a baseline for what constitutes a truly ‘sovereign’ productivity suite. </p><p>Italo Vignoli, a founding member of TDF and author of the open letter, describes this as the “pillar of Digital Sovereignty” and fired a broadside at companies promoting so-called sovereign products.</p><p>“It is worth remembering that many of those who champion Digital Sovereignty today were silent back in 2006, when the open ISO/IEC ODF standard — the pillar of Digital Sovereignty — was announced: not only did they not listen to us during all these years, but in some cases they greeted us with a condescending smile,” the open letter reads. </p><p>A spokesperson for Nextcloud told <em>ITPro </em>the company agrees that proprietary file formats are a “serious hindrance to digital sovereignty”, adding that the company intends to <a href="https://nextcloud.com/blog/euro-office-building-momentum/" target="_blank"><u>improve ODF support</u></a>. </p><p>“We thus need to free users who are stuck using these formats, and enable them to work with an open office platform. This will allow organizations to transition to open document formats like ODF,” the spokesperson said. </p><p>“For this reason, as we stated before in our blog about our roadmap, Euro-Office will focus development efforts on improving ODF support. Ultimately, ODF should be the standard - not OOXM, and we will work towards that.”</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ IBM and Red Hat believe they have the answer to open source security risks ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/ibm-and-red-hat-believe-they-have-the-answer-to-open-source-security-risks</link>
                                                                            <description>
                            <![CDATA[ Project Lightwell is backed by a $5 billion investment and a team of more than 20,000 engineers ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">TcG8EBRspu5V7D6HUtMPmE</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/T3bahCery9gj9T3n8Srp4C-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 29 May 2026 10:19:25 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/T3bahCery9gj9T3n8Srp4C-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[The IBM booth pictured during the RSA Conference in San Francisco, California, US, on Wednesday, April 26, 2023]]></media:description>                                                            <media:text><![CDATA[The IBM booth pictured during the RSA Conference in San Francisco, California, US, on Wednesday, April 26, 2023]]></media:text>
                                <media:title type="plain"><![CDATA[The IBM booth pictured during the RSA Conference in San Francisco, California, US, on Wednesday, April 26, 2023]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/T3bahCery9gj9T3n8Srp4C-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>IBM and its subsidiary Red Hat are pumping $5 billion into improving the security of open-source projects.</p><p><a href="https://www.ibm.com/products/lightwell">Project Lightwell</a> is designed as an enterprise clearinghouse for open source software, with a new AI-driven model for securing the software supply chain.</p><p>The idea is to use advanced AI capabilities, offered through commercial subscriptions, to validate and test fixes across a huge volume of open source code. Enterprises will be able to integrate secure patches directly into their existing software supply chains, say the firms, with enterprise-grade validation and lifecycle management.</p><p>They can report and resolve vulnerabilities, receive patches optimized for production environments, spanning both Red Hat offerings and independent community code, and share fixes upstream so that open source communities can include them in long-term maintenance.</p><p>And all this will be backed by a team of more than 20,000 engineers working across upstream and enterprise environments. The focus will be on upstream maintenance alongside open source community leaders; high-volume, AI-assisted vulnerability review, triage, and prioritization; and secure patch development, dependency hardening, and release engineering.</p><p>"Open source is the backbone of today's digital economy and the foundation of modern AI, and we are at an inflection point in how it is built, secured, and scaled," said Arvind Krishna, chairman and CEO of IBM. </p><p>"With Project Lightwell, IBM and Red Hat are helping define a new industry model, one that brings together AI, engineering expertise, and trusted collaboration, to secure open source software at its source and across the entire supply chain. This is about strengthening trust in the systems that power business, government, and society."</p><p>IBM and Red Hat are already working with a group of early adopters on Project Lightwell, including Bank of America, BNY, Citi, Goldman Sachs, JPMorganChase, Mastercard, Morgan Stanley, Royal Bank of Canada, State Street, Visa, and Wells Fargo. </p><p>"The real-world insights from these initial deployments will actively shape how vulnerabilities are identified, validated, and remediated at scale across complex software supply chains," the firms said.</p><p>More than nine-in-ten Fortune 500 companies rely on open source software - but security is an ever-present problem. Sonatype <a href="https://www.itpro.com/software/open-source/the-open-source-ecosystem-is-booming-thanks-to-ai-but-hackers-are-taking-advantage">identified</a> 454,648 malicious open source packages in 2025, up 67% on the previous year, with one state-linked group alone tied to more than 800 malicious packages.</p><p>Meanwhile, <a href="https://www.itpro.com/software/open-source/86-percent-of-enterprise-codebases-contain-open-source-vulnerabilities">according to Black Duck</a>, 86% of codebases contain <a href="https://www.itpro.com/software/28109/what-is-open-source">open source</a> vulnerabilities, with 81% of those classified as high or critical risk, up from 74% in the previous year.</p><p>"Most enterprises cannot keep up with the volume, complexity, and speed of risk. AI-driven vulnerability discovery is accelerating both the volume and speed of CVE creation, compounding an already unsustainable remediation gap," said IBM.</p><p>"Project Lightwell delivers validated fixes to the specific open source versions organizations already run. By combining large-scale engineering, AI, and a coordinated clearinghouse model, it enables organizations to move from detection to remediation without disrupting stability, certification, or compliance requirements."</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ What is the Solid Project and what could it mean for businesses? ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/software/open-source/what-is-the-solid-project-and-what-could-it-mean-for-businesses</link>
                                                                            <description>
                            <![CDATA[ Decentralized data stores could give customers more control over their data – with seismic implications for enterprise data management ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">8U2D3Pr6VaKBuwqj5TFcJF</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/QxkcFZoV4mY7ehzAESGkCB-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 12 May 2026 12:02:18 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Open Source]]></category>
                                                    <category><![CDATA[Software]]></category>
                                                                                                                    <dc:creator><![CDATA[ Drew Turney ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/6H5MTKayRu4E8ukZSEVkHX.jpeg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Drew Turney is a freelance journalist who has been working in the industry for more than 25 years. He has written on a range of topics including technology, film, science, and publishing.&lt;/p&gt;
&lt;p&gt;Since 1995, Drew has written for publications including MacWorld, PCMag, io9, Variety, Empire, GQ, and the Daily Telegraph.In all, he has contributed to more than 150 titles. He is an experienced interviewer, features writer, and media reviewer with a strong background in scientific knowledge.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;At &lt;em&gt;ITPro&lt;/em&gt;, Drew has written on the topics of smart manufacturing, cyber security certifications, computing degrees, data analytics, and mixed reality technologies.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;He has worked as a film reviewer for many years and has led a number of interviews with the cast and crew of notable films and has also written extensively on books, authors, and the publishing industry.&lt;/p&gt;
&lt;p&gt;Before entering the field of journalism full-time, Drew was a graphic designer. He spent time working on a combination of web and print media throughout the early 2000s, before pursuing freelance journalism as his sole pursuit in 2006.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/QxkcFZoV4mY7ehzAESGkCB-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[An abstract visualization of data, shown as a glowing blue and orange web on a blue background.]]></media:description>                                                            <media:text><![CDATA[An abstract visualization of data, shown as a glowing blue and orange web on a blue background.]]></media:text>
                                <media:title type="plain"><![CDATA[An abstract visualization of data, shown as a glowing blue and orange web on a blue background.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/QxkcFZoV4mY7ehzAESGkCB-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Consumers own very little of the data they generate, and this feeds directly into the business models of many digital enterprises. But this landscape is being reshaped by legislation and independent organizations – with potentially big implications for IT leaders.</p><p>The <a href="https://www.itpro.com/technology/social-media/mastodon-vs-twitter-should-you-migrate-your-social-media-account"><u>Fediverse</u></a>, for instance, is a decentralized social media framework that creates a network of independently operated servers, communicating via shared protocols that let users move between social platforms without being locked into a big tech ecosystem.</p><p>Even further reaching is the Solid Project. Solid – short for social linked data – is a web-decentralization project spearheaded by World Wide Web inventor Tim Berners Lee. It intends to give consumers private data 'pods' that they own and control. All their data – financial, medical, social, etc – goes into it, and each user decides who gets access to their data, how much, and for how long.</p><p>Currently, companies own vast amounts of consumer information, which they trade with countless more through a vast data brokerage industry for advertising. This profitable practice also comes with practical benefits, such as improved risk management, AI development, and enhanced marketing. </p><p>But if Solid gains traction, this will all come to change – so what exactly does Solid mean for businesses?</p><h2 id="familiar-systems">Familiar systems</h2><p>Although the Solid Project is philosophically distinct from the way the internet currently operates, a lot of the under the hood systems that would drive it are already in place. Businesses would have to rely on <a href="https://www.itpro.com/security/the-top-api-risks-and-how-to-mitigate-them"><u>application programming interfaces (APIs)</u></a> to a greater extent in order to access user data, with a greater emphasis on <a href="https://www.itpro.com/security/network-security/358282/what-is-zero-trust"><u>zero trust</u></a> security policies to do so safely.</p><p>Ahmad Shadid, founder of AI research lab O Foundation adds that data pods or digital wallets are also a great use case for Web3 and <a href="https://www.itpro.com/security/28031/what-is-blockchain"><u>blockchain</u></a> technology. "[It'd be] one login you use everywhere and a simple permission user interface where you can grant 'read transactions for last 90 days' to a budgeting app, or 'share vaccine status only' with a clinic and revoke it at any time," he says.</p><p>Together with the privacy and security concerns such systems address, it could also mitigate out of date or duplicated information shared between many companies. Use of a data pod means switching apps without reuploading the same information for the umpteenth time – businesses can simply access the same sensitive information once granted access, which also reduces their <a href="https://www.itpro.com/business/policy-and-legislation/governance-risk-and-compliance-is-a-major-growth-opportunity-but-how-will-the-market-develop"><u>compliance risks</u></a> such as data storage requirements under the <a href="https://www.itpro.com/it-legislation/27814/what-is-gdpr-everything-you-need-to-know"><u>General Data Protection Regulation (GDPR)</u></a>.</p><h2 id="pros-and-cons-of-solid-for-businesses">Pros and cons of Solid for businesses</h2><p>There's an essential tension between Solid and functions such as customer-specific advertising and <a href="https://www.itpro.com/business/careers-and-training/uk-firms-are-dragging-their-heels-on-ai-training-shadow-ai-means-they-need-to-move-fast-to-avoid-unauthorized-use"><u>AI training</u></a>. Right now, there's an economic imperative to hoard all available data – within <a href="https://www.itpro.com/security/privacy/ai-is-forcing-a-fundamental-shift-in-data-privacy-and-governance"><u>data privacy and governance requirements</u></a> – for when it becomes monetizable. Customer data can be used to feed directly into <a href="https://www.itpro.com/strategy/29282/what-is-predictive-analytics"><u>predictive analytics</u></a> models for future consumer purchases. On an enterprise level, customer data also helps developer organizations to roll out updates based on customer usage data, and to make <a href="https://www.itpro.com/business/business-strategy/what-does-data-driven-mean-in-business"><u>data-driven decisions</u></a> on future products and service offerings.</p><p>"Corporate resistance is ... economically unlikely," says Pedrotti. "Companies have entire business models based on data ownership and won't voluntarily sign away that value. And regulation enforcement would be difficult across jurisdictions – companies would find ways around laws through terms of service that technically comply but continue to give them practical control over user data."</p><p>Arne Möhle, CEO and co-founder at Tuta Mail agrees any such efforts will face extreme opposition from tech corporations. "We've seen this with the lobbying efforts in the EU when the Digital Markets Act was still in the making." In fact, in the leadup to the 2023 EU acts, tech companies <a href="https://www.euronews.com/my-europe/2023/09/11/tech-companies-spend-more-than-100-million-a-year-on-eu-digital-lobbying"><u>spent €113 million a year on lobbying</u></a>.</p><p>On the Solid Project, Wright concedes there's unlikely to be a sudden reversal. "Adoption tends to follow regulatory shifts, market incentives and consumer expectations," he says – a pattern the world's already seen with <a href="https://www.itpro.com/policy-legislation/30661/what-is-open-banking"><u>Open Banking</u></a>. </p><p>He also thinks adoption will shift as new players see benefits. "Startups developing new apps could access years of user history from day one. Imagine launching a health app that already knows three years of fitness patterns, injury history, and seasonal trends based on data already collected from Strava, MyGarminConnect and MyFitnessPal. As more applications support the Solid Project and each user's Pod receives more data [new] apps automatically benefit from the network effect."</p><p>All of which means there's actually an argument for big tech to support users owning all their data.</p><p>Bannach says behaviour in the corporate sphere tends to shift in response to regulation, risk and revenue – a shift we're seeing now. "GDPR, the <a href="https://www.itpro.com/business/policy-legislation/368435/what-is-the-eus-digital-markets-act-dma"><u>DMA</u></a> and the <a href="https://www.itpro.com/business/policy-and-legislation/three-things-you-need-to-know-about-the-eu-data-act-ahead-of-this-weeks-big-compliance-deadline"><u>EU Data Act</u></a>, cookie deprecation, and rising breach and <a href="https://www.itpro.com/security/28084/what-is-ransomware"><u>ransomware</u></a> defence costs all push firms to reduce hoarded data and operate on permissioned, auditable access," he says. "Early movers gain regulatory compliance benefits and customer loyalty. Resistance will persist, but the commercial and compliance incentives are aligning."</p><p>To Shadid, the benefits to business are obvious – and quantifiable. "Less liability means fewer massive centralized data lakes to hack or mismanage. Better quality means first-party, verified streams direct from user-controlled pods rather than stitched-together data from brokers. There's also a clearer legal basis for AI training and analytics – consent is explicit and revocable at the source."</p><p>Wright agrees, saying data pods with the Solid Project eliminate costs because companies building consumer-facing apps will no longer need to handle user data storage or <a href="https://www.itpro.com/strategy/28935/what-is-identity-management-and-what-role-does-it-play-in-security-strategy"><u>identity management</u></a>.</p><iframe allow="" height="200px" width="100%" id="" style="" class="position-center" data-lazy-priority="high" data-lazy-src="https://player.captivate.fm/episode/db98e7d4-39e3-4dfe-bdfa-e05ab9c11b6d/"></iframe><h2 id="whose-data-is-it-anyway">Whose data is it anyway?</h2><p>Not all data is the same. "There are very large datasets where we're increasingly less concerned like social media posts and searches being 'in the wild' – convenience outweighs whatever concerns many have," says Victor Cho, Founder/CEO at AI-focused business communication tools provider Emovid. "But we're very concerned about certain datasets like health and financial information." </p><p>Wright agrees the landscape for data varies enormously, but he stresses the Solid Project isn't about 'harmonizing' data law, it just wants to enable it at the architecture level:</p><p>"[The architecture] makes Solid complementary to varying legal regimes. In jurisdictions with strong protections like the EU, it makes rights like <a href="https://www.itpro.com/data-protection/22378/what-is-googles-right-to-be-forgotten"><u>data portability and erasure</u></a> achievable rather than theoretical. In jurisdictions with weaker protections, it confers de facto control that doesn't depend on regulation."</p><p>Meanwhile, there are also moves to classify data as a commercial asset, thus codifying its true value. Joe Hughes, CEO of Manx Technology Group, advocates for the legal standards set by the Isle of Man Data Asset Foundation. He thinks it's definition – not technology – around data that represents the largest barrier to personal data pod ownership systems.</p><p>"[The Foundation] addresses this by leveraging the Isle of Man Foundations Act 2011 to give data a legal personality," he says. "By defining data as an asset in law it can be assigned value, listed on a balance sheet, used as collateral on a loan or considered during M&A. Our model doesn't prevent organizations from accessing data, it changes the terms and recognizes sovereignty. Access becomes explicit, trusted, controlled, permissioned, and contractual."</p><p>Wright counters that while individuals managing their pods is the cornerstone of Solid, it's not the only model. Another possibility would be group pods for shared data, or pods storing the certified copy of data owned or issued by another entity like a bank or driver's license authority. This would have the same effect for businesses, of reducing organizational data burden and setting out a more standardized architecture for verifying user identities and accessing sensitive data.</p><p>There’s also potential for an approach such as Solid to assist businesses with enterprise AI deployment. For example, Wright adds that the Solid Project could serve as the memory and data-sharing layer for agentic AI systems.</p><p>"The average person isn't going to self-host a server or manage API permissions for their medical records – that's the gap right now,” explains Scott McIntosh, president of AI business consultancy Digital Treehouse.</p><p>“The technology exists, but the user experience isn't there yet. AI is going to be the interface that makes it actually work. Instead of handing over all your data to every app and platform that asks for it, your AI agent shares only what's needed, for as long as it's needed, and revokes access when the interaction is done. You wouldn't need to understand the technical side of it. You'd just tell your AI what you're comfortable sharing and it handles the rest."</p><p>The business that can deliver this system could see massive user uptake. The extent to which web-decentralization projects such as Solid could play a role in this deployment is yet to be determined.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ AI is coming to Ubuntu: Canonical exec teases future AI features and agentic workflow capabilities for version 26.10 — but on a ‘strictly opt-in basis’ ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/software/ubuntu-ai-roadmap-canonical-agentic-workflows</link>
                                                                            <description>
                            <![CDATA[ A range of new AI features are coming to Ubuntu over the next year, according to maintainers, but only providing they’re of “sufficient maturity and quality”. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">acVo5hcLZcfyVbADqWLJYL</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/FjngZHdGeAfmS9xSXU8UWm-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 29 Apr 2026 09:59:02 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Software]]></category>
                                                                                                <author><![CDATA[ ross.kelly@futurenet.com (Ross Kelly) ]]></author>                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Ross Kelly is ITPro&#039;s News &amp;amp; Analysis Editor, with a keen interest in cyber security, business leadership and emerging technologies.&lt;/p&gt;
&lt;p&gt;He graduated from Edinburgh Napier University in 2016 with a BA (Hons) in Journalism, and joined ITPro in 2022 after four years working in technology conference research.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;In his spare time, Ross enjoys cycling, walking and is an avid reader of history and non-fiction.&lt;/p&gt;
&lt;p&gt;You can contact Ross at ross.kelly@futurenet.com or on &lt;a href=&quot;https://twitter.com/rosswritesetc&quot;&gt;Twitter&lt;/a&gt; and &lt;a href=&quot;https://www.linkedin.com/in/ross-kelly-18a54411a/&quot;&gt;LinkedIn&lt;/a&gt;.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/FjngZHdGeAfmS9xSXU8UWm-1280-80.jpg">
                                                            <media:credit><![CDATA[Canonical]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Ubuntu logo and branding imposed over a white background.]]></media:description>                                                            <media:text><![CDATA[Ubuntu logo and branding imposed over a white background.]]></media:text>
                                <media:title type="plain"><![CDATA[Ubuntu logo and branding imposed over a white background.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/FjngZHdGeAfmS9xSXU8UWm-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>A range of new AI features are coming to <a href="https://www.itpro.com/operating-systems/25139/linux-mint-vs-ubuntu-which-one-is-better">Ubuntu </a>over the next year, according to maintainers, but only providing they’re of “sufficient maturity and quality”. </p><p>In a <a href="https://discourse.ubuntu.com/t/the-future-of-ai-in-ubuntu/81130" target="_blank"><u>blog post</u></a> detailing AI plans for the operating system, Jon Seager, VP of engineering at Ubuntu’s parent company, Canonical, said the firm is exploring the prospect of a dual approach to integration.</p><p>This approach centers around improving OS functionality with AI models running “in the background” while the implementation of “AI native” features will also be rolled out - but only to those who opt in. </p><p>“Over the past few weeks I’ve begun to develop a framework to help think about different kinds of AI adoption within Ubuntu," Seager wrote. “At the center of that is the idea of <em>explicit </em>and <em>implicit </em>AI features.”</p><p>Implicit AI, according to Seager, aims to enhance existing features within the operating system without sweeping changes. One example touted included the launch of speech-to-text and text-to-speech functionalities within the OS. </p><p>“I don’t see these as “AI features”, I see them as critical accessibility features that can be dramatically improved through the adoption of LLMs with minimal (if any) drawbacks,” he noted. </p><p>Seager added that these features will rely on local inference, using open weight models. Local inference is an area in which Canonical has been expanding capabilities recently, he noted, particularly with regard to “<a href="https://jnsgr.uk/2026/01/developing-with-ai-on-ubuntu/#inference-snaps" target="_blank"><u>inference snaps</u></a>”. </p><p>Inference snaps provide “simplified local access” to inference using models catered specifically for user hardware. </p><p>“The combination of Ubuntu’s widespread adoption and Canonical’s partnership with silicon companies has enabled us to deliver a high performance foundational inference capability for the distribution with very little cognitive overhead for our users,” he wrote. </p><h2 id="tasteful-agentic-functionality-in-ubuntu">‘Tasteful’ agentic functionality in Ubuntu</h2><p>With agentic AI firmly in the spotlight over the last 18 months, Seager noted there are plans afoot on this front. These fall firmly under the “explicit” aspect of the firm’s plans. </p><p>Agentic capabilities within the operating system have huge potential, he noted, helping in tasks such as “authoring new documents or applications”, as well as personal automated tasks and troubleshooting support.</p><p>“I love the idea that all the power and capability that Linux has acquired over the past few years could become more accessible to more people,” Seager wrote. </p><p>In this case, there will be strict guardrails. A strong focus has been placed on privacy and security when considering integration of agentic workflows. </p><p>“We’re making plans on how to integrate agentic workflows into Ubuntu for those who want it in a way that feels tasteful, aligned with our user base and respectful of our privacy and security values,” Seager wrote. </p><p>“With this comes a big responsibility for us to ensure that the relevant security and confinement controls are in place to prevent unwanted side-effects.”</p><p>On the topic of confinement, Seager noted that the aforementioned inference snaps will be subject to the “same <a href="https://snapcraft.io/docs/explanation/security/snap-confinement/?_gl=1*1si0vrm*_ga*MTI3NzExODk5NC4xNzc3NDQ3MjYw*_ga_5LTL1CNEJM*czE3Nzc0NTE1MTUkbzIkZzAkdDE3Nzc0NTE1MTUkajYwJGwwJGgw"><u>confinement rules as other snaps</u></a>”. </p><p>These confinement rules limit the amount of access applications have to system resources. By adopting this approach, Canonical aims to improve user confidence and prevent “indiscriminate access” to machines and data. </p><h2 id="a-strictly-opt-in-basis">A "strictly opt-in” basis</h2><p>Reaction to Seager’s post appears to have been mostly positive, albeit bordering on apprehensive, with one user describing it as “one of the most sensible posts relating to the use of AI I have read”. </p><p>Limited backlash prompted Seager to publish a <a href="https://discourse.ubuntu.com/t/the-future-of-ai-in-ubuntu/81130/41"><u>clarification post</u></a> confirming details on user controls and consent. </p><p>On the prospect of a potential “kill switch” for AI features, Seager noted this won’t be included. However, given AI functionalities will be delivered using snaps, users will have the option of removing these. </p><p>“Which I supposed acts as a sort of kill switch for the features we’re planning on shipping,” he wrote. </p><p>Moreover, any AI features will be launched in a preview format on a “strictly opt-in basis” upon the launch of version 26.10. Future versions will also have an opt-in function for AI features, he noted. </p><p>“In subsequent releases, my plan is to have a step in the initial setup wizard that allows the user to choose whether or not they’d like the AI-native features enabled,” Seager commented. </p><p>“Because of the size of most LLMs, we simply couldn’t ship them in the installer anyway, so opting out at first run is simple: they just won’t be there.”</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Compromised open source package pushed malicious Elementary CLI release to developers ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/software/open-source/compromised-open-source-package-pushed-malicious-elementary-cli-release-to-developers</link>
                                                                            <description>
                            <![CDATA[ The open source Elementary CLI tool has more than one million monthly downloads ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">UCzswgi2KJFY9GCoKpu4PE</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/hsfthUtkTmaHSt3kanY4hM-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 28 Apr 2026 10:50:55 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Open Source]]></category>
                                                    <category><![CDATA[Software]]></category>
                                                                                                <author><![CDATA[ ross.kelly@futurenet.com (Ross Kelly) ]]></author>                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Ross Kelly is ITPro&#039;s News &amp;amp; Analysis Editor, with a keen interest in cyber security, business leadership and emerging technologies.&lt;/p&gt;
&lt;p&gt;He graduated from Edinburgh Napier University in 2016 with a BA (Hons) in Journalism, and joined ITPro in 2022 after four years working in technology conference research.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;In his spare time, Ross enjoys cycling, walking and is an avid reader of history and non-fiction.&lt;/p&gt;
&lt;p&gt;You can contact Ross at ross.kelly@futurenet.com or on &lt;a href=&quot;https://twitter.com/rosswritesetc&quot;&gt;Twitter&lt;/a&gt; and &lt;a href=&quot;https://www.linkedin.com/in/ross-kelly-18a54411a/&quot;&gt;LinkedIn&lt;/a&gt;.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/hsfthUtkTmaHSt3kanY4hM-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Supply chain security concept image showing 15 locked padlocks with one outlying padlock left unlocked. ]]></media:description>                                                            <media:text><![CDATA[Supply chain security concept image showing 15 locked padlocks with one outlying padlock left unlocked. ]]></media:text>
                                <media:title type="plain"><![CDATA[Supply chain security concept image showing 15 locked padlocks with one outlying padlock left unlocked. ]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/hsfthUtkTmaHSt3kanY4hM-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Threat actors gained access to sensitive developer data and cryptocurrency wallets after a popular <a href="https://www.itpro.com/software/28109/what-is-open-source">open source</a> software tool was compromised. </p><p>Developers behind the Elementary Python command line interface (CLI) tool revealed a recent release (version 0.23.3) included malicious code. </p><p>Attackers exploited a script injection vulnerability in the open source project’s GitHub Actions workflow to push the malicious update to users. </p><p>This malicious version was subsequently published on <a href="https://www.itpro.com/security/cyber-attacks/pypi-attack-targeting-of-repository-shows-no-sign-of-stopping">PyPI</a>, as well as a Docker image pushed to the project’s registry. </p><p>In a <a href="https://www.elementary-data.com/post/security-incident-report-malicious-release-of-elementary-oss-python-cli-v0-23-3" target="_blank"><u>blog post</u></a> detailing the incident, developers said the malicious version was removed roughly 12 hours later. Elementary Cloud, the Elementary dbt package, and other CLI versions weren’t affected.</p><p>A replacement version (0.23.4) has also been released, however developers warned those who downloaded the malicious version are still at high risk. </p><h2 id="what-happened-with-the-elementary-cli-attack">What happened with the Elementary CLI attack?</h2><p><a href="https://www.stepsecurity.io/blog/elementary-data-compromised-on-pypi-and-ghcr-forged-release-pushed-via-github-actions-script-injection" target="_blank"><u>Analysis of the incident</u></a> by researchers at StepSecurity found attackers exploited a script injection vulnerability in the project’s GitHub Actions workflow. </p><p>Thereafter, they used the workflow’s GITHUB_TOKEN to “forge a signed release commit” and push the malicious version through a legitimate release pipeline. </p><p>According to StepSecurity, a .pth file was baked into the release, which upon startup allowed the threat actor(s) to harvest an array of sensitive data, including: </p><ul><li>SSH keys</li><li>Cloud credentials, including AWS, GCP, and Azure</li><li>CI secrets</li><li>Container orchestration data</li><li>System data (passwords, logs, shell history)</li><li>Crypto wallet files (including Bitcoin, Litecoin, Monero, and Ripple)</li></ul><h2 id="what-developers-need-to-know">What developers need to know</h2><p>Project maintainers warned that users who installed the malicious version should “assume that any credentials accessible to the environment where it ran may have been exposed”. </p><p>Developers outlined a series of steps to take for those affected, including: </p><ul><li>Check your installed version (pip show elementary-data | grep Version)</li><li>If the version is 0.23.3, uninstall it and replace it with the safe version</li><li>Delete your cache files to avoid any artifacts</li><li>Check for the malware’s marker file on any machine where the CLI may have run: If this file is present, the payload executed on that machine.</li></ul><p>Developers are also advised to rotate credentials that were accessible from the environment where 0.23.3 ran. This includes dbt profiles, cloud provider keys, API tokens, <a href="https://www.itpro.com/security/cyber-security/359457/what-are-ssh-keys">SSH keys</a>, and contents of .env files. </p><p>“<a href="https://www.itpro.com/business/digital-transformation/cicd-comes-into-focus-as-enterprises-ramp-up-application-modernization-efforts">CI/CD</a> runners are especially exposed because they typically have broad sets of secrets mounted at runtime,” the blog post noted. </p><p>In the wake of the incident, project maintainers noted they have “hardened” open source release flows and permissions. </p><p>The vulnerable GitHub Action workflow has also been removed, while an audit of other GitHub Actions workflows across the organisation has been conducted to identify the same type of script injection flaw. </p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ ‘The build pipeline is becoming the new frontline’: Axios npm compromise highlights growing software supply chain risks, experts warn ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-attacks/the-build-pipeline-is-becoming-the-new-frontline-axios-npm-compromise-highlights-growing-software-supply-chain-risks-experts-warn</link>
                                                                            <description>
                            <![CDATA[ Cyber criminals exploited a hijacked maintainer account to compromise one of the world's most widely used JavaScript libraries ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">FtT83GNxmPjbmsmBPsDEnS</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/4XZYfjMuoUwrLG8MTcaQBi-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 01 Apr 2026 10:32:11 +0000</pubDate>                                                                                                                                <updated>Wed, 01 Apr 2026 14:13:01 +0000</updated>
                                                                                                                                            <category><![CDATA[Cyber Attacks]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/4XZYfjMuoUwrLG8MTcaQBi-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Cybersecurity concept image showing digital data storage modules with padlock symbols in a storage environment.]]></media:description>                                                            <media:text><![CDATA[Cybersecurity concept image showing digital data storage modules with padlock symbols in a storage environment.]]></media:text>
                                <media:title type="plain"><![CDATA[Cybersecurity concept image showing digital data storage modules with padlock symbols in a storage environment.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/4XZYfjMuoUwrLG8MTcaQBi-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Attackers have compromised the npm account of Axios and published malicious versions to spread <a href="https://www.itpro.com/security/30081/what-is-a-trojan-virus">remote access trojans (RATs)</a> to millions of developers.</p><p>Axios is a JavaScript HTTP client and is one of the most popular packages on npm, with more than 100 million weekly downloads. It manages requests between clients, such as browsers or Node.js apps, and servers.</p><p>On Monday, two malicious updates, <em>axios@1.14.1</em> and <em>axios@0.30.3</em>, were published, apparently through the compromise of the npm account of axios’ primary maintainer Jason Saayman. </p><p>The updates were identified almost immediately by several security firms and remained live for around two or three hours. The malicious versions introduce a dependency that executes during installation and deploys a cross‑platform remote access trojan (RAT) targeting macOS, Windows, and <a href="https://www.itpro.com/operating-systems/24841/windows-vs-linux-whats-the-best-operating-system">Linux</a>. </p><p>The <a href="https://www.itpro.com/malware/28076/what-is-malware">malware </a>communicates with a command and control (C2) server to retrieve platform‑specific second‑stage payloads, researchers noted. After execution, it deletes itself and replaces its own package.json with a clean version to evade forensic detection.</p><p>According to StepSecurity, the malicious dependency was staged 18 hours in advance, with separate payloads pre-built for all three operating systems. Both release branches were poisoned within 39 minutes of each other.</p><p>StepSecurity added that within two seconds of npm install, the malware was already calling home to the attacker's server before npm had even finished resolving dependencies -– making this one of the most operationally-sophisticated supply chain attacks ever documented against a top-10 npm package.</p><p>Because there were no git tags, any manual audit of the <a href="https://www.itpro.com/open-source/31833/what-is-github">GitHub </a>repo would have failed to show anything was wrong.</p><h2 id="axios-npm-incident-highlights-supply-chain-dangers">Axios npm incident highlights supply chain dangers</h2><p>Ilkka Turunen, field CTO at Sonatype, said the latest npm-related incident highlights the growing dangers faced by developers globally, with threat actors ramping up attacks. </p><p>“Attackers have figured out they don’t need to compromise the code people trust if they can compromise the trust around it," Turunen said. </p><p>"In this case, the malicious capability was introduced through a staged dependency and designed to erase its own tracks, which made the attack harder to spot and slower to understand. That’s not just malware — it shows a more deliberate and mature playbook."</p><p>Anyone who installed either version before the takedown should assume their system is compromised and is advised to immediately quarantine hosts, implement their full incident response playbook, and rotate all exposed secrets. </p><p>It's not known who is responsible for the compromise, although many researchers are throwing suspicion on a North Korean actor known as UNC1069 that focuses on stealing cryptocurrency via centralized exchanges (CEX), software developers at financial institutions, tech firms, and venture capital funds. </p><p>The supply chain attack marks the latest in a string of attempts to exploit trust in <a href="https://www.itpro.com/software/28109/what-is-open-source">open source</a> ecosystems, according to Upwind security researcher Avital Harel.</p><p>"The build pipeline is becoming the new frontline. Attackers know that if they can compromise the systems that build and distribute software, they can inherit trust at scale," Harel commented. </p><p>"Organizations should be looking much more closely at CI/CD systems, package dependencies, and developer environments, because that’s increasingly where attackers are placing their bets." </p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ The pros and cons of open source AI for business ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/software/open-source/the-pros-and-cons-of-open-source-ai-for-business</link>
                                                                            <description>
                            <![CDATA[ Leaders face a choice between frontier freedom and cloud lock-in without thr right adoption strategy ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">8P6VpHKXdSdeuik4NsAbz9</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/TeTemFzsXKP9wv3C8GriNJ-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 31 Mar 2026 09:30:17 +0000</pubDate>                                                                                                                                <updated>Thu, 02 Apr 2026 15:39:55 +0000</updated>
                                                                                                                                            <category><![CDATA[Open Source]]></category>
                                                    <category><![CDATA[Software]]></category>
                                                                                                                    <dc:creator><![CDATA[ Keri Allan ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/oJZkdPii464j27ff4GCcoT.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/TeTemFzsXKP9wv3C8GriNJ-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Open source vulnerabilities concept image showing HTML code on a computer screen.]]></media:description>                                                            <media:text><![CDATA[Open source vulnerabilities concept image showing HTML code on a computer screen.]]></media:text>
                                <media:title type="plain"><![CDATA[Open source vulnerabilities concept image showing HTML code on a computer screen.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/TeTemFzsXKP9wv3C8GriNJ-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Discussion is intensifying around whether <a href="https://www.itpro.com/technology/artificial-intelligence/the-risks-of-open-source-ai-models"><u>open source AI</u></a> can offer more flexibility and resilience compared to proprietary AI – but the conversation is muddied by confusion around what makes an AI solution ‘open’.</p><p>Thanks to the 30-year-old Open Source Definition (OSD) there’s a clear understanding of <a href="https://www.itpro.com/software/28109/what-is-open-source"><u>what’s considered open source</u></a> software, but the same cannot be said for AI, says Amanda Brock, CEO at OpenUK. She believes trying to define open source AI as a whole hasn’t worked, and that a better approach is disaggregation: looking at what the components of a form of AI are, and how they’re licensed.</p><p>This is because most so-called open models are open weights only, says Nell Watson, IEEE senior member, author and AI ethics engineer at Singularity University. “You get the trained parameters, but not the training data, methodology or reproducibility guarantees. Llama is not open source in the way <a href="https://www.itpro.com/operating-systems/28025/best-linux-distros"><u>Linux</u></a> is. That distinction matters, because the value proposition of openness – auditability, sovereignty and independent verification – depends on which layers are actually open.”</p><p>“Equally important is what license it’s shared on. This is where we can see <a href="https://www.itpro.com/technology/artificial-intelligence/meta-open-source-ai-linux-foundation"><u>‘open washing’</u></a>, where someone uses the term ‘open source’ to describe their project when the license has some form of restriction,” says Brock. She points to Meta’s Llama 2 as an example. </p><p>“There’s a commercial restriction and an acceptable use policy in the Llama software license, meaning it’s neither open source nor open model. Coming up to its launch, Meta was calling it open innovation behind the scenes and I think that’s right. There are degrees of openness around AI, and we have to be careful to understand what these distinctions and definitions are.” </p><h2 id="the-case-for-open-source-ai">The case for open source AI </h2><p>Once enterprises have clarity on what they're actually adopting, they can then weigh up the pros and cons. One advantage of open-source AI is retaining more control. </p><p>While choosing a proprietary application programming interface (API) can make things easier at the start, it can create compounding dependencies including pricing you don’t control, availability you can’t enforce and data handling you can’t verify.</p><p>The question every CIO should ask is what happens when your vendor changes terms, raises prices or discontinues the model you’ve built around, says Watson. “Enterprises that went all-in on single-vendor cloud stacks in the 2010s learned this lesson the hard way. AI is heading for the same reckoning, only faster,” she warns.</p><p>Regulated industries are leading the way, with <a href="https://blogs.nvidia.com/blog/ai-in-financial-services-survey-2026/" target="_blank"><u>Nvidia reporting</u></a> financial services firms deploying open weight models at higher rates than most. 84% of respondents surveyed by the chip giant stated that open source models are important to their overall AI strategy. </p><p>"Open models that have been vetted and hardened allow enterprises to maintain full ownership and control of both models and training data," says IDC research manager Dr Michele Rosen – with half of respondents in regulated sectors calling this "critical."</p><p><a href="https://www.itpro.com/security/data-protection/digital-sovereignty-enterprises-known-unknowns"><u>Digital sovereignty</u></a> is sharpening this pressure further, as enterprises serving international clients can no longer treat data residency and compliance as an afterthought.</p><h2 id="can-open-source-compete-with-the-hyperscalers">Can open source compete with the hyperscalers? </h2><p>The control argument is all well and good, but counts for nothing if the technology can't do the job. Belief that open source AI simply can't keep up with hyperscalers is widespread, but that’s only partly true.</p><p>The reality is that most enterprises don’t need ‘frontier’ capabilities. Instead, they’re after reliable, auditable and cost-predictable performance on specific workflows, and for those use cases, a fine-tuned open model will often outperform a general-purpose frontier model, “because specificity beats scale,” says Watson. </p><p>For organizations like Bloomberg, the open versus proprietary question is largely beside the point. "In a production environment, it's less about open weight vs proprietary and more about performance metrics. A smaller model, whether open weight or proprietary, might actually give you better speed and accuracy in a given situation,” says Amanda Stent, head of AI Strategy and Research in the Office of the CTO at Bloomberg.</p><p>“The gap at the absolute frontier still exists for the most demanding general reasoning tasks, but optimizing for benchmarks that don’t match your workload is an expensive distraction,” continues Watson. “The enterprises getting the most value from AI right now are those asking ‘what do we actually need?’ rather than ‘<a href="https://www.itpro.com/technology/artificial-intelligence/we-need-to-stop-caring-about-ai-model-releases">what model tops the leaderboard</a>?’.”</p><p>In the next few years, a hybrid model to model licensing could become the dominant approach.</p><p>“Proprietary APIs will remain the standard for general purpose ‘daily assistant’ copilots, while open source will become the backbone of internal, mission-critical AI platforms,” says Mark Scrivens, CEO of FPT UK. “We’re already seeing this in highly regulated sectors such as healthcare and banking, financial services and insurance, where we’re seeing a surge in open-source adoption for large-scale transformation projects.” </p><h2 id="what-to-consider-before-choosing-open-source-ai">What to consider before choosing open source AI</h2><p>The case for open-source AI is building, but so is the to-do list, as it demands significantly more from an enterprise than just signing up for an API key. Brock points to the parallel with early open source software. The assumption then was that free to use meant free to run, and that simply wasn’t the case. </p><p>In the case of open-source AI, models often require more hands-on oversight. “Unlike proprietary models, open-source deployments place the responsibility squarely on internal teams,” says Rosen. “Therefore, moving beyond proprietary APIs requires a higher level of operational maturity.”</p><p>“It requires a shift from AI user to operator,” adds Scrivens. “Organizations need <a href="https://www.itpro.com/hardware/30399/what-is-a-gpu"><u>GPU</u></a>-ready clusters, whether on-premise or via the cloud. This transition also requires talent proficient in <a href="https://www.itpro.com/software/development/breaking-boundaries-empowering-channel-partners-to-unite-devops-and-mlops-for-a-stronger-software-supply-chain"><u>machine learning operations (MLOps)</u></a>, model evaluation and prompt engineering. Organizations should also be prepared to monitor model drift, performance and security in real time.”</p><p>Not all open-source projects are equal either. Some have thriving contributor ecosystems, while others are effectively a single corporate sponsor with a permissive license, notes Brock, and enterprises need to know the difference before they commit.</p><h2 id="building-a-strategy-that-works">Building a strategy that works  </h2><p>For those weighing up their options, Scrivens recommends organizations begin with pilot projects that use open source models to test performance, cost and operational requirements. The next step, he says, is building a flexible architecture that supports both proprietary and open source options. </p><p>According to Watson, the enterprises making the smartest moves right now are treating this as a “constitutional moment”.</p><p>“They’re putting <a href="https://www.itpro.com/technology/artificial-intelligence/organizations-face-ticking-timebomb-over-ai-governance"><u>governance</u></a> structures and technical architectures in place that preserve real optionality before the market consolidates further. Sovereign AI capability – the ability to inspect, modify, govern and if necessary, walk away from your AI systems, is something you either build now or negotiate for later from a position of weakness,” she advises. </p><p>“The window is open, but won’t remain so indefinitely,” she concludes. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Open source is booming in Europe as enterprises look to strengthen digital autonomy ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/software/open-source/open-source-is-booming-in-europe-as-enterprises-look-to-strengthen-digital-autonomy</link>
                                                                            <description>
                            <![CDATA[ Concerns over lock-in, rising prices, and vendor reliance are fueling a shift to open source alternatives ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">XjkoJ2CiYjXDVv3Mg6GUng</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/qnGSwbfzp9zTsFt2t49oUT-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 25 Mar 2026 09:41:55 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Open Source]]></category>
                                                    <category><![CDATA[Software]]></category>
                                                                                                <author><![CDATA[ ross.kelly@futurenet.com (Ross Kelly) ]]></author>                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Ross Kelly is ITPro&#039;s News &amp;amp; Analysis Editor, with a keen interest in cyber security, business leadership and emerging technologies.&lt;/p&gt;
&lt;p&gt;He graduated from Edinburgh Napier University in 2016 with a BA (Hons) in Journalism, and joined ITPro in 2022 after four years working in technology conference research.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;In his spare time, Ross enjoys cycling, walking and is an avid reader of history and non-fiction.&lt;/p&gt;
&lt;p&gt;You can contact Ross at ross.kelly@futurenet.com or on &lt;a href=&quot;https://twitter.com/rosswritesetc&quot;&gt;Twitter&lt;/a&gt; and &lt;a href=&quot;https://www.linkedin.com/in/ross-kelly-18a54411a/&quot;&gt;LinkedIn&lt;/a&gt;.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/qnGSwbfzp9zTsFt2t49oUT-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[EU flags fly outside the union headquarters in Brussels, Belgium.]]></media:description>                                                            <media:text><![CDATA[EU flags fly outside the union headquarters in Brussels, Belgium.]]></media:text>
                                <media:title type="plain"><![CDATA[EU flags fly outside the union headquarters in Brussels, Belgium.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/qnGSwbfzp9zTsFt2t49oUT-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Open source software is booming in Europe, new research suggests, driven in part by increased efforts to reduce reliance on US-based vendors. </p><p>Figures from Perforce's 2026 <a href="https://www.openlogic.com/resources/state-of-open-source-report">State of Open Source Report</a> show 63% of organizations across the EU and UK cite concerns over vendor lock-in as a key motivation behind opting for open source software. </p><p>That marks a significant difference compared to US counterparts, Perforce noted, where just 51% of respondents highlighted this as a notable concern. </p><p>Perforce said the increased appetite for open source software reflects a "broader push by European enterprises to strengthen digital autonomy", maintain robust data sovereignty rules, and meet evolving regulatory requirements.</p><p>"The regulatory compliance landscape in the EU has forced many companies to pay closer attention to third-party vendors they partner with, in order to meet <a href="https://www.itpro.com/162240/demand-for-tougher-data-breach-legislation">stricter data security and privacy requirements</a>," the report notes. </p><p>"Some are wary of becoming too dependent on commercial providers and entrusting them to manage their data infrastructures."</p><p>Notably, Perforce found cost was also a key factor for the shift to open source software on both sides of the Atlantic. </p><p>61.84% of respondents specifically highlighted the lack of licensing costs and overall financial savings as a primary driver behind their use of open source software. </p><p>"These top two drivers – reducing costs and avoiding vendor lock-in – make sense in light of ongoing economic uncertainty and trade/tariff volatility," the report states. </p><p>"Organizations that want to save money and keep their options open have begun migrating off of proprietary platforms and SaaS offerings to cost-effective open source alternatives that can give them more flexibility and autonomy."</p><h2 id="reducing-us-reliance">Reducing US reliance</h2><p>Vendor lock-in has become a recurring flashpoint for enterprises on both sides of the Atlantic over the last three years, with EU regulators locked in <a href="https://www.itpro.com/business/policy-and-legislation/microsoft-facing-ftc-antitrust-probe-over-cloud-ai-competition-concerns">repeated battles with big tech companies such as Microsoft over software licensing fees</a>. </p><p>While these concerns have largely been centered around the financial burden placed on enterprises, the issue has been exacerbated amidst claims that European businesses are too reliant on US tech services. </p><p>Political uncertainty over the last 15 months has prompted calls for EU-based firms to opt for homegrown alternatives. </p><p>Earlier this month, MEPs, industry leaders, and digital experts called for greater efforts to bolster Europe's digital ecosystem to provide viable alternatives for enterprises. </p><p>During a panel discussion at Wire's European Digital Sovereignty Summit in Brussels, Wire CEO Benjamin Schilz said reducing reliance on foreign tech solutions is "key to protecting democratic stability and data sovereignty" across the region. </p><p>"Open source, interoperability, and transparent standards are essential to build trust, avoid vendor lock-in, and strengthen resilience," Schilz added. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Big tech is clamping down on open source ‘AI slop’ reports ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/software/open-source/big-tech-is-clamping-down-on-open-source-ai-slop-reports</link>
                                                                            <description>
                            <![CDATA[ Firms including Microsoft, OpenAI, and Google have pledged funding to bolster open source security and cut down on slop reports ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">Qc7J3fqhMgBMkDM3u69KhM</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/ongkdNjDSDqmVxz5VXn9Td-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 19 Mar 2026 10:32:39 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Open Source]]></category>
                                                    <category><![CDATA[Software]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/ongkdNjDSDqmVxz5VXn9Td-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Human hand pointing at a laptop computer with AI symbol on screen and blue gunge with &#039;slop&#039; icon pouring out of keyboard.]]></media:description>                                                            <media:text><![CDATA[Human hand pointing at a laptop computer with AI symbol on screen and blue gunge with &#039;slop&#039; icon pouring out of keyboard.]]></media:text>
                                <media:title type="plain"><![CDATA[Human hand pointing at a laptop computer with AI symbol on screen and blue gunge with &#039;slop&#039; icon pouring out of keyboard.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/ongkdNjDSDqmVxz5VXn9Td-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>A host of big tech firms have handed over $12.5 million in funding to advance open source security and try to eliminate <a href="https://www.itpro.com/software/open-source/ai-slop-security-reports-are-driving-open-source-maintainers-mad">"AI slop" bug reports</a>.</p><p>Firms including OpenAI, Anthropic, AWS, Google, Microsoft, and GitHub have pledged funding for Alpha-Omega and the Open Source Security Foundation (OpenSSF), both security initiatives within the Linux Foundation. </p><p>The aim is to develop long-term, sustainable security solutions that support <a href="https://www.itpro.com/software/28109/what-is-open-source">open source</a> communities worldwide.</p><p>The move comes as open source maintainers contend with an unprecedented number of security reports, many of which are generated by automated systems. </p><p>Mark Ryland, director of the Office of the <a href="https://www.itpro.com/careers/28228/ciso-job-description-what-does-a-ciso-do">CISO </a>for AWS, said these AI-generated reports are overwhelming their ability to review them. </p><p>"Many of the reports are of very low quality — a reality given rise to the new industry term '<a href="https://www.itpro.com/technology/artificial-intelligence/satya-nadella-microsoft-ai-slop-2026">AI slop</a>'," he said. "Many projects have already elected to put guidelines in place for AI submissions, while others have shut down upstream contributions entirely to prevent a flood of AI-generated pull requests."</p><h2 id="closer-ties-with-open-source-maintainers">Closer ties with open source maintainers</h2><p>The new investment will allow Alpha-Omega and OpenSSF to work directly with maintainers and their communities to make emerging security capabilities accessible, practical, and aligned with existing project workflows. </p><p>“Grant funding alone is not going to help solve the problem that AI tools are causing today on open source security teams,” said Greg Kroah-Hartman of the Linux kernel project. </p><p>“OpenSSF has the active resources needed to support numerous projects that will help these overworked maintainers with the triage and processing of the increased AI-generated security reports they are currently receiving.”</p><p>The GitHub Secure Open Source Fund is adding an additional $5.5 million in Azure credits and funding to provide training and expertise. </p><p>GitHub Security Lab, meanwhile, is improving the security advisory experience on GitHub and Private Vulnerability Reporting (PVR) features, with an eye on reducing the burden of low-quality reports and helping maintainers manage increased volume.</p><p>Google, meanwhile, will provide AI-powered tools like Big Sleep and CodeMender from Google DeepMind – already used to protect the company's own systems. It's also extending research initiatives like Sec-Gemini to open source projects.</p><p>“Our commitment remains focused: to sustainably secure the entire lifecycle of open source software,” said Steve Fernandez, general manager of OpenSSF. </p><p>“By directly empowering the maintainers, we have an extraordinary opportunity to ensure that those at the front lines of software security have the tools and standards to take preventative measures to stay ahead of issues and build a more resilient ecosystem for everyone.”</p><h2 id="ai-slop-reports-are-skyrocketing">AI slop reports are skyrocketing</h2><p>Concerns about AI slop bug reports have been voiced by a number of organizations, including the Python Software Foundation.</p><p>Developers behind cURL, an open source command line interface (CLI) tool which allows developers to transfer data, recently shut down its bug bounty scheme in response to a growing number of slop reports. </p><p>As <a href="https://www.itpro.com/software/open-source/curl-open-source-bug-bounty-program-scrapped"><u><em>ITPro </em></u><u>reported at the time</u></a>, lead maintainer Daniel Stenberg said the current volume of submissions is placing a “high load” on the security team.</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Notepad++ hackers remained undetected and pushed malicious updates for six months – here’s who’s responsible, how they did it, and how to check if you’ve been affected ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-attacks/notepad-hackers-remained-undetected-and-pushed-malicious-updates-for-six-months-heres-whos-responsible-how-they-did-it-and-how-to-check-if-youve-been-affected</link>
                                                                            <description>
                            <![CDATA[ Hackers remained undetected for months and distributed malicious updates to Notepad++ users after breaching the text editor software – here's how to check if you've been affected. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">Z8JWmAJVxKDr3msciCHySN</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/T88XCMBKcwGSg5qaEXtdDR-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 03 Feb 2026 11:15:21 +0000</pubDate>                                                                                                                                <updated>Tue, 03 Feb 2026 11:15:35 +0000</updated>
                                                                                                                                            <category><![CDATA[Cyber Attacks]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ ross.kelly@futurenet.com (Ross Kelly) ]]></author>                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Ross Kelly is ITPro&#039;s News &amp;amp; Analysis Editor, with a keen interest in cyber security, business leadership and emerging technologies.&lt;/p&gt;
&lt;p&gt;He graduated from Edinburgh Napier University in 2016 with a BA (Hons) in Journalism, and joined ITPro in 2022 after four years working in technology conference research.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;In his spare time, Ross enjoys cycling, walking and is an avid reader of history and non-fiction.&lt;/p&gt;
&lt;p&gt;You can contact Ross at ross.kelly@futurenet.com or on &lt;a href=&quot;https://twitter.com/rosswritesetc&quot;&gt;Twitter&lt;/a&gt; and &lt;a href=&quot;https://www.linkedin.com/in/ross-kelly-18a54411a/&quot;&gt;LinkedIn&lt;/a&gt;.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/T88XCMBKcwGSg5qaEXtdDR-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Chinese hackers concept image showing People&#039;s Republic of China (PRC) flag in background with shadowed hands typing on a laptop keyboard in foreground.]]></media:description>                                                            <media:text><![CDATA[Chinese hackers concept image showing People&#039;s Republic of China (PRC) flag in background with shadowed hands typing on a laptop keyboard in foreground.]]></media:text>
                                <media:title type="plain"><![CDATA[Chinese hackers concept image showing People&#039;s Republic of China (PRC) flag in background with shadowed hands typing on a laptop keyboard in foreground.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/T88XCMBKcwGSg5qaEXtdDR-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Threat actors remained undetected for months and distributed malicious updates to Notepad++ users after breaching the popular text editor software, developers have revealed.</p><p>In a <a href="https://notepad-plus-plus.org/news/hijacked-incident-info-update/" target="_blank"><u>blog post</u></a>, lead developer Don Ho said a preliminary investigation into the incident showed hackers went undetected for around six months, with those responsible believed to be a state-affiliated threat group. </p><p>“The incident began from June 2025. Multiple independent security researchers have assessed that the threat actor is likely a <a href="https://www.itpro.com/security/cyber-attacks/state-sponsored-cyber-attacks-the-new-frontier">Chinese state-sponsored group</a>, which would explain the highly selective targeting observed during the campaign,” he wrote. </p><p>Ho added that the “infrastructure-level compromise” allowed threat actors to “intercept and redirect update traffic”, with the source of the incident stemming from a hosting provider rather than vulnerabilities within the <a href="https://www.itpro.com/software/28109/what-is-open-source">open source</a> software itself. </p><p>“Traffic from certain targeted users was selectively redirected to attacker-controlled served malicious update manifests,” Ho explained. </p><p>The confirmation follows several weeks of speculation over a potential breach. In early December, security researcher Kevin Beaumont penned a <a href="https://doublepulsar.com/small-numbers-of-notepad-users-reporting-security-woes-371d7a3fd2d9" target="_blank"><u>blog post</u></a> revealing he’d heard from three separate organizations who’d all experienced security incidents with Notepad++.</p><h2 id="how-notepad-was-breached">How Notepad++ was breached</h2><p>According to Ho, details on the “exact technical mechanism” behind the breach are yet to be determined pending a comprehensive probe. </p><p>What we do know so far is that Notepad++ was operated through a shared hosting server and that the incident began in June 2025. </p><p>Through this compromised server, attackers were able to manipulate requests from WinGUp, Notepad++’s native updater tool. It’s from here that threat actors were able to redirect users to <a href="https://www.itpro.com/security/a-malicious-mcp-server-is-silently-stealing-user-emails">malicious servers</a>. </p><p>The now-former hosting provider confirmed this shared server was compromised until 2 September 2025. Yet despite losing server access, attackers “maintained credentials to internal services” which enabled them to continue distributing malicious updates to users until 2 December. </p><p>“Remediation and security hardening” updates were completed by 2 December, according to Ho, which blocked further activity. </p><h2 id="who-s-behind-the-notepad-breach">Who’s behind the Notepad++ breach?</h2><p>A separate investigation by Rapid7 Labs attributed the breach to a Chinese APT group, Lotus Blossom. </p><p>According to researchers, the state-affiliated group has been active since 2009 and has a reputation for “targeted espionage campaigns” against organizations in Southeast Asia and Central America. </p><p>“Our investigation identified a security incident stemming from a sophisticated compromise of the infrastructure hosting Notepad++, which was subsequently used to deliver a previously undocumented custom backdoor, which we have dubbed Chrysalis,” the company noted in an <a href="https://www.rapid7.com/blog/post/tr-chrysalis-backdoor-dive-into-lotus-blossoms-toolkit/" target="_blank"><u>advisory</u></a>. </p><h2 id="what-users-need-to-know">What users need to know</h2><p>As Beaumont noted in his December blog post, Notepad++ issued an update to release version 8.8.8 in November. This patch aimed to “harden the Notepad++ Updater from being hijacked to deliver something… note Notepad++”.</p><p>While Beaumont advised users to confirm they’re running a version of the software from 8.8.8 or higher, developers have since urged users to ensure they’re running 8.9.1 or higher.</p><p>“I recommend downloading v8.9.1 (which includes the relevant security enhancement) and running the installer to update your Notepad++ manually,” Ho said. </p><p>“With these changes and reinforcements, I believe the situation has been fully resolved. Fingers crossed.”</p><p>In terms of <a href="https://www.itpro.com/security/cyber-security/368481/what-is-threat-hunting">indicators of compromise (IOCs)</a>, Ho noted in his blog post that there are none to share at present. </p><p>That doesn’t mean users are left complete in the dark, however. Rapid7’s advisory on the campaign does include IOCs for users who want to clarify whether devices have been targeted. </p><p>Cassius Edison, COO of Closed Door Security, said the severity of the breach is “hard to understate” and users should take immediate steps to establish if they’re impacted. </p><p>“It’s vital that users ensure their software is updated to the latest version, especially on systems connected to larger networks,” he said. </p><p>“The maintainer for Notepad++ has switched to a new host for updates, and has started to implement stricter verification of update binaries on the client side, which should hopefully mitigate any further hijacking attempts moving forward."</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ The open source ecosystem is booming thanks to AI, but hackers are taking advantage ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/software/open-source/the-open-source-ecosystem-is-booming-thanks-to-ai-but-hackers-are-taking-advantage</link>
                                                                            <description>
                            <![CDATA[ Analysis by Sonatype found that AI is giving attackers new opportunities to target victims ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">FfALgwDHucWYFSL64K8xFV</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/UjWjTqk5HiFp2xWB4yo93k-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 29 Jan 2026 10:46:02 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Open Source]]></category>
                                                    <category><![CDATA[Software]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/UjWjTqk5HiFp2xWB4yo93k-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Insider threat hacker concept image showing man typing on keyboard in a dimly lit room. ]]></media:description>                                                            <media:text><![CDATA[Insider threat hacker concept image showing man typing on keyboard in a dimly lit room. ]]></media:text>
                                <media:title type="plain"><![CDATA[Insider threat hacker concept image showing man typing on keyboard in a dimly lit room. ]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/UjWjTqk5HiFp2xWB4yo93k-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The use of <a href="https://www.itpro.com/software/28109/what-is-open-source">open source</a> software is skyrocketing, according to new research, but threat actors are capitalizing on this boom time to target unsuspecting victims. </p><p>Analysis from Sonatype shows that developers downloaded an array of components 9.8 trillion times last year, spanning popular repositories such as <a href="https://www.itpro.com/software/open-source/cisa-wants-closer-ties-with-open-source-developers-to-stop-the-next-log4shell">Maven Central</a>, PyPi, and <a href="https://www.itpro.com/security/cyber-attacks/hackers-are-using-these-malicious-npm-packages-to-target-developers-windows-macos-and-linux-systems-heres-how-to-stay-safe">npm</a>.</p><p>This not only marked a 67% year-on-year increase, but gave hackers ample opportunity to cause chaos, with researchers finding that many contained <a href="https://www.itpro.com/malware/28076/what-is-malware">malware </a>and vulnerabilities. </p><p>Sonatype identified 454,648 <a href="https://www.itpro.com/security/malware/developers-face-a-torrent-of-malware-threats-as-malicious-open-source-packages-surge-188-percent">malicious open source packages</a> in 2025, bringing the total to 1.23 million. One state-linked group alone was tied to more than 800 malicious packages. </p><p>Automated self-replicating malware is on the rise, for example with incidents like <a href="https://www.itpro.com/security/cyber-attacks/shai-hulud-malware-is-back-with-a-vengeance-and-hit-more-than-19-000-github-repositories-so-far-heres-what-developers-need-to-know">Shai-Hulud</a> and Indonesian Foods. </p><p>Vulnerability risk also persists even when fixes are readily available, largely thanks to gaps in data quality and failure to prioritize. <a href="https://www.itpro.com/security/zero-day-exploit/361819/what-is-log4shell-log4j-vulnerability">Log4Shell</a>, for example, reached 42 million downloads in 2025 despite fixed versions having existed for years. </p><h2 id="ai-is-exacerbating-open-source-risks">AI is exacerbating open source risks</h2><p>According to Sonatype, AI is exacerbating these trends, boosting output but introducing new supply chain failure modes by amplifying bad inputs. </p><p>The firm’s research found that when AI selected open source software components for enterprise applications, <a href="https://www.itpro.com/technology/artificial-intelligence/openai-thought-it-hit-a-home-run-with-gpt-5-users-werent-so-keen">GPT-5</a> hallucinated 27.8% of component versions - and in some cases, even confidently suggested actual malware packages.</p><p>The data used to judge software risk is increasingly unreliable, researchers warned. </p><p>Nearly two-thirds (64.5%) of open-source vulnerabilities lacked an official severity score, while 35% took more than three months to be fully analysed – leaving many serious risks effectively invisible. </p><p>“The commons is production infrastructure now, attackers know it, and AI puts the whole system on fast-forward,” said Brian Fox, co-founder and CTO of Sonatype. </p><h2 id="serious-regulatory-implications">Serious regulatory implications</h2><p>The stakes are raised for enterprises opting for open source software, Sonatype noted. </p><p>Software transparency is becoming a global expectation, with legislation such as the <a href="https://www.itpro.com/business/policy-and-legislation/what-is-the-eus-cyber-resilience-act-cra">Cyber Resilience Act (CRA)</a> and the <a href="https://www.itpro.com/business/policy-and-legislation/how-the-eu-ai-act-compares-to-other-international-regulatory-approaches">EU AI Act</a> converging with customer requirements on proof of provenance, contents, and control across the software lifecycle.</p><p>"The takeaway from what we are seeing in the market is straightforward: AI should accelerate secure decisions, not uncertainty. IDC research indicates that developers accept an average of 39% of AI-generated code without revision, highlighting how often AI output is incorporated as-is,” commented Katie Norton, research manager, DevSecOps and software supply chain security at IDC.</p><p>“When paired with Sonatype's findings, the data suggests that AI-driven recommendations benefit from grounding in current supply chain intelligence and enforceable policy, so that increased development velocity does not expand the attack surface by default.”</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ A torrent of AI slop submissions forced an open source project to scrap its bug bounty program – maintainer claims they’re removing the “incentive for people to submit crap” ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/software/open-source/curl-open-source-bug-bounty-program-scrapped</link>
                                                                            <description>
                            <![CDATA[ Curl isn’t the only open source project inundated with AI slop submissions ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">n6wR9t7x2ixwGavzPPKTCC</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/zv3vruBFEnUUSeim8StmuT-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 22 Jan 2026 11:43:40 +0000</pubDate>                                                                                                                                <updated>Fri, 23 Jan 2026 09:55:52 +0000</updated>
                                                                                                                                            <category><![CDATA[Open Source]]></category>
                                                    <category><![CDATA[Software]]></category>
                                                                                                <author><![CDATA[ ross.kelly@futurenet.com (Ross Kelly) ]]></author>                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Ross Kelly is ITPro&#039;s News &amp;amp; Analysis Editor, with a keen interest in cyber security, business leadership and emerging technologies.&lt;/p&gt;
&lt;p&gt;He graduated from Edinburgh Napier University in 2016 with a BA (Hons) in Journalism, and joined ITPro in 2022 after four years working in technology conference research.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;In his spare time, Ross enjoys cycling, walking and is an avid reader of history and non-fiction.&lt;/p&gt;
&lt;p&gt;You can contact Ross at ross.kelly@futurenet.com or on &lt;a href=&quot;https://twitter.com/rosswritesetc&quot;&gt;Twitter&lt;/a&gt; and &lt;a href=&quot;https://www.linkedin.com/in/ross-kelly-18a54411a/&quot;&gt;LinkedIn&lt;/a&gt;.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/zv3vruBFEnUUSeim8StmuT-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Digitized cross symbol overlaid on a flowing background in red, orange, and blue colors.]]></media:description>                                                            <media:text><![CDATA[Digitized cross symbol overlaid on a flowing background in red, orange, and blue colors.]]></media:text>
                                <media:title type="plain"><![CDATA[Digitized cross symbol overlaid on a flowing background in red, orange, and blue colors.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/zv3vruBFEnUUSeim8StmuT-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>A <a href="https://www.itpro.com/security/should-your-business-start-a-bug-bounty-program">bug bounty program</a> run by a popular <a href="https://www.itpro.com/software/28109/what-is-open-source">open source</a> data transfer service has been shut down amidst an onslaught of AI-generated ‘slop’ contributions. </p><p>Daniel Stenberg, lead maintainer of Curl, a command line interface (CLI) tool which allows developers to transfer data, confirmed the decision to shut down the bug bounty scheme in a <a href="https://github.com/curl/curl/pull/20312/commits/694141a154a7c08e5571a31c911fda80f200fe3f" target="_blank"><u>GitHub commit</u></a> last week. </p><p>In a subsequent <a href="https://lists.haxx.se/pipermail/daniel/2026-January/000143.html" target="_blank"><u>email </u></a>outlining the move, Stenberg revealed seven bug bounty submissions were recorded within a sixteen hour period, with 20 logged since the beginning of the year. </p><p>Although some of these uncovered bugs, not a single one actually detailed a concrete vulnerability. </p><p>“Some of them were true and proper bugs, and taking care of this lot took a good while,” he said. “Eventually we concluded that none of them identified a vulnerability and we now count twenty submissions done already in 2026.”</p><p>Stenberg added that the current volume of submissions is placing a “high load” on the security team, and the decision to shut down the program aims to “reduce the noise” and number of AI-generated reports. </p><p>“The main goal with shutting down the bounty is to remove the incentive for people to submit crap and non-well researched reports to us,” he wrote. </p><p>“We believe, hope really, that we still will get actual security vulnerabilities reported to use even if we do not pay for them. The future will tell.”</p><h2 id="curl-maintainer-names-and-shames-bug-hunter">cURL maintainer names and shames bug hunter</h2><p>Stenberg revealed he had a “lengthy discussion” with an individual who submitted one of the <a href="https://www.itpro.com/technology/artificial-intelligence/ai-generated-code-risks-what-cisos-need-to-know">AI-generated vulnerability</a> reports after publicly ridiculing them on social media site Mastodon. </p><p>“It was useful for me to make me remember that oftentimes these people are just ordinary mislead humans and they might actually learn from this and perhaps even change,” he said. </p><p>The individual in question, however, insists their professional life has been “ruined”. </p><p>According to Stenberg, the naming and shaming approach appears to be the only option for cutting down on this growing issue. </p><p>“This is a balance of course, but I also continue to believe that exposing, discussing, and ridiculing the ones who waste our time is one of the better ways to get the message through: you should NEVER report a bug or vulnerability unless you understand it - and can reproduce it.”</p><h2 id="ai-slop-reports-are-a-major-headache">AI slop reports are a major headache</h2><p>This isn’t Stenberg’s first run-in with this topic. In January 2024, he <a href="https://daniel.haxx.se/blog/2024/01/02/the-i-in-llm-stands-for-intelligence/" target="_blank"><u>aired previous concerns</u></a> over the growing volume of poor reports. A key talking point here lay around the fact that these appeared legitimate and maintainers wasted time dissecting slop.</p><p>"When reports are made to look better and to appear to have a point, it takes a longer time for us to research and eventually discard it. Every security report has to have a human spend time to look at it and assess what it means," he said.</p><p>Curl isn’t alone in contending with AI-generated ‘slop’ security reports, either. As <a href="https://www.itpro.com/software/open-source/ai-slop-security-reports-are-driving-open-source-maintainers-mad"><u><em>ITPro </em></u><u>reported in December 2024</u></a>, another open source maintainer lamented over the strain placed on open source developers and maintainers. </p><p>Seth Larson, a security report triage worker for a handful of open source projects, revealed they were facing an “uptick in extremely low-quality, spammy, and LLM-hallucinated security reports” to open source projects. </p><p>This torrent of <a href="https://www.itpro.com/technology/artificial-intelligence/satya-nadella-microsoft-ai-slop-2026">AI-generated slop</a> was having a huge impact on open source maintainers, wasting time and effort, and leading to higher levels of burnout. As with Stenberg, Larson noted that these seemingly legitimate reports were becoming a major headache.</p><p>“The issue is in the age of LLMs, these reports appear at first glance to be potentially legitimate and thus require time to refute,” he wrote in a <a href="https://www.itpro.com/software/open-source/ai-slop-security-reports-are-driving-open-source-maintainers-mad" target="_blank"><u>blog post</u></a>. </p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Retailers are turning to AI to streamline supply chains and customer experience – and open source options are proving highly popular ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/technology/artificial-intelligence/ai-in-retail-industry-growth-nvidia</link>
                                                                            <description>
                            <![CDATA[ Companies are moving AI projects from pilot to production across the board, with a focus on open-source models and software, as well as agentic and physical AI ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">ckCGJZQqHdcy7JxYnsAdUP</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Ri4wHkXbFAfouiBQMbpR4X-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 08 Jan 2026 12:42:51 +0000</pubDate>                                                                                                                                <updated>Thu, 08 Jan 2026 12:43:44 +0000</updated>
                                                                                                                                            <category><![CDATA[Artificial Intelligence]]></category>
                                                    <category><![CDATA[Technology]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Ri4wHkXbFAfouiBQMbpR4X-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Concept image symbolizing AI in the retail industry with humanoid robot holding shopping bags.]]></media:description>                                                            <media:text><![CDATA[Concept image symbolizing AI in the retail industry with humanoid robot holding shopping bags.]]></media:text>
                                <media:title type="plain"><![CDATA[Concept image symbolizing AI in the retail industry with humanoid robot holding shopping bags.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Ri4wHkXbFAfouiBQMbpR4X-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p><a href="https://www.itpro.com/technology/artificial-intelligence/ai-in-the-retail-industry-is-spreading-beyond-the-it-department">AI in retail</a> is booming, with the vast majority of organizations planning to increase their AI budgets this year, according to new research from Nvidia. </p><p>The chip giant’s third annual <a href="https://www.nvidia.com/en-us/lp/industries/state-of-ai-in-retail-and-cpg/?nvid=nv-int-tblg-141576-vt23" target="_blank"><u><em>State of AI in Retail and Consumer Packaged Goods</em></u></a> report found 91% of respondents are either actively using or assessing AI. Nine-in-ten said they’d build on the success of current projects by <a href="https://www.itpro.com/business/leadership/government-public-sector-cio-it-spending-ai-2026">increasing their AI budgets</a> in 2026.</p><p>Of those using <a href="https://www.itpro.com/strategy/28181/what-is-ai">AI</a>, 89% said it was helping to increase annual revenue, while 95% said it is acting to cut costs. More than half said they'd seen improved employee productivity and operational efficiencies and 41% reported improved customer service.</p><p>“What executives should be focused on is not green-lighting vanity projects at the expense of high-ROI wins,” said Chris Walton, co-CEO of Omni Talk. “The retailers who will succeed will start with boring use cases that solve specific P&L problems, prove the value, then scale.”</p><p><a href="https://www.itpro.com/technology/artificial-intelligence/the-risks-of-open-source-ai-models">Open source AI</a> is extremely popular, the study found, with 79% saying these models and software were moderately to extremely important to their <a href="https://www.itpro.com/technology/artificial-intelligence-ai/358223/why-diversity-is-key-to-a-successful-ai-strategy">AI strategy</a>. </p><p>“Most retailers first started experimenting with AI using proprietary AI vendors. They had the models, but they didn’t own the keys to their own kingdom,” said Jason Goldberg, chief commerce strategy officer of Publicis Groupe. </p><p>“<a href="https://www.itpro.com/software/28109/what-is-open-source">Open source</a> flips that script, allowing retailers to leverage their proprietary data, avoid <a href="https://www.itpro.com/cloud/362542/vendor-lock-in-is-it-worth-worrying-about-in-the-cloud">vendor lock-in</a> and benefit from open-source community innovation.”</p><p>Similarly, agentic AI is an increasing focus, with 47% of respondents saying that their companies were either using or assessing agentic AI in their operations. One-in-five said <a href="https://www.itpro.com/technology/artificial-intelligence/businesses-are-being-taken-for-fools-with-ai-agents">AI agents</a> were already active in their organizations, with another 21% reporting that agents are coming within the next year.</p><p>“The truly disruptive impact of agentic AI will hit retail supply chains and operations first, such as autonomous agents handling real-time inventory rebalancing, dynamic pricing and vendor negotiations at scale, because that’s where the ROI is measurable,” said Walton.</p><h2 id="retailers-tackle-supply-chain-issues-with-ai">Retailers tackle supply chain issues with AI</h2><p>AI is also helping organizations deal with supply chain problems, allowing retailers to optimize inventory at the store and customer level rather than at a regional level. </p><p>They can now incorporate many more factors in their demand forecasts, and more accurately match supply to demand.</p><p>The top pressure valve, Nvidia noted, is using AI for supply chain operational efficiency and throughput, cited by 51% of respondents. Meeting customer expectations was next on the list at 45%, and solving for traceability and transparency was third at 38%.</p><p>Physical AI is gaining ground in the industry, meanwhile, with 17% of respondents using or evaluating the technology.</p><p>“The real transformation will come from AI that makes existing physical infrastructure smarter,” said Walton. “My favorite example is in-store robotics. Through them, you get better pricing, better inventory, management and better presentation quality.”</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ A concerning number of Log4j downloads are still vulnerable four years on ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/software/open-source/a-concerning-number-of-log4j-downloads-are-still-vulnerable-four-years-on</link>
                                                                            <description>
                            <![CDATA[ Despite safe Log4j versions having been available for years, many organizations haven't introduced them ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">xhWiBsHGTC9j6Wemp4xav4</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/keTVGxYZ6S7QMNungRToWP-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 12 Dec 2025 08:25:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Open Source]]></category>
                                                    <category><![CDATA[Software]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/keTVGxYZ6S7QMNungRToWP-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Log4j open source Java library logo pictured on a smartphone with source code in green coloring pictured on screen in background.]]></media:description>                                                            <media:text><![CDATA[Log4j open source Java library logo pictured on a smartphone with source code in green coloring pictured on screen in background.]]></media:text>
                                <media:title type="plain"><![CDATA[Log4j open source Java library logo pictured on a smartphone with source code in green coloring pictured on screen in background.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/keTVGxYZ6S7QMNungRToWP-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Four years on from <a href="https://www.itpro.com/security/zero-day-exploit/361819/what-is-log4shell-log4j-vulnerability">Log4Shell</a>, more than one-in-ten Log4j downloads still contain the vulnerability, according to data from Sonatype.</p><p>Over the last year, 14% of Log4j downloads in the UK were vulnerable, the <a href="https://www.sonatype.com/whitepapers/the-persistence-of-open-source-vulnerabilities" target="_blank"><u>company found</u></a>, with the global figure standing at around 13% despite the availability of safe versions. </p><p>Notably, Sonatype found the problem isn't specific to Log4j, with around 95% of vulnerable <a href="https://www.itpro.com/software/28109/what-is-open-source">open source</a> components downloaded already having a fixed version available.</p><p>"<a href="https://www.itpro.com/security/cyber-security/368554/how-to-protect-against-endemic-log4j-vulnerabilities">The Log4j vulnerability</a> doesn’t even crack the top few anymore. Sonatype Security Research examined some of the most frequently downloaded avoidable vulnerabilities — collectively they have collectively been downloaded more than 2.94 billion times this year or since their patches were released (whichever is more recent)," said the firm. </p><p>"Every one of those downloads represents unnecessary risk: teams pulling vulnerable versions when fixed ones already exist, and have for years."</p><h2 id="how-the-log4shell-incident-unfolded">How the Log4Shell incident unfolded</h2><p>Log4Shell, a critical zero-day flaw in a widely-used <a href="https://www.itpro.com/software/development/why-java-17-growth-is-exploding">Java library</a>, appeared in December 2021, and was immediately and widely exploited. Nearly <a href="https://www.itpro.com/security/zero-day-exploit/361847/log4shell-zero-day-vulnerability-numbers-revealed">one million attack attempts</a> were launched in the first 72 hours of the vulnerability's disclosure.</p><p>It was described at the time by Check Point Security as "clearly one of the most serious vulnerabilities on the internet in recent years, and the potential for damage is incalculable".</p><p>The incident caused upheaval throughout the security industry, kicking off a new era of software supply chain scrutiny and prompting <a href="https://www.itpro.com/security/software-security-overhauled-for-the-better-thanks-to-us-legislation">software bill of materials</a> mandates in US executive order 14028 and tighter oversight in Europe through the <a href="https://www.itpro.com/business/policy-legislation/370403/what-is-the-network-and-information-security-2-nis2-directive">NIS2 Directive</a> and the <a href="https://www.itpro.com/business/policy-and-legislation/what-is-the-eus-cyber-resilience-act-cra">Cyber Resilience Act (CRA)</a>.</p><p>However, Sonatype said that in 2025 alone, there were nearly 300 million total Log4j downloads, of which 40 million were vulnerable.</p><p>In China, the US, India, Japan, Brazil, Germany, the UK, Canada, South Korea, and France, between 8% and 29% of Log4j downloads still contained Log4Shell. India did particularly badly, with 29%, while the figure was 28% for China and 22% for Japan.</p><h2 id="log4j-complacency-persists">Log4j complacency persists</h2><p>According to Sonatype, the reason behind continued vulnerable Log4j downloads lies in a combination of complacency and the simple fact the incident occurred several years ago. </p><p>Moreover, visibility and oversight - or lack thereof - are also key factors in the trend. </p><p>"Once a library is wired in and everything compiles, it tends to stay that way. Versions get pinned, build files get copied from one service to the next, and no one revisits those choices unless something forces the issue — a breach, a compliance audit, or a production outage," said the firm.</p><p>"Without someone explicitly owning ongoing dependency maintenance, those 'temporary' choices turn into long-lived tech debt. Vulnerable versions of Log4j and other libraries stick around not because anyone chose them recently, but because no one chose to replace them."</p><p>Meanwhile, many vulnerable components — including Log4j in some stacks — are pulled in transitively by other libraries and frameworks, creating an ownership vacuum. </p><p>Component choices are typically optimized for speed and familiarity, rather than time-to-fix history, security posture, or the quality of governance and maintenance. </p><p><a href="https://www.itpro.com/security/adopting-more-security-tools-doesnt-keep-you-safe-it-just-overloads-your-teams-and-creates-greater-risks">Security tooling</a> doesn’t always help, either, thanks particularly to alert fatigue.</p><p>"If you’re not sure where you stand today, start by getting the numbers. Run a scan of your applications to find Log4j and other frequently downloaded vulnerable components, calculate what share of their usage is to vulnerable versions, and benchmark your own 'unnecessary risk rate'," said the firm.</p><p>"That’s the first step toward making sure Log4Shell is remembered as a turning point, not just an anniversary."</p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/software/open-source/open-source-security-in-the-spotlight-as-uk-gov-publishes-fresh-guidance">Open source security in the spotlight as UK gov publishes fresh guidance</a></li><li><a href="https://www.itpro.com/software/open-source/open-source-software-attacks-everything-you-need-to-look-out-for">Open source software attacks: Everything you need to look out for</a></li><li><a href="https://www.itpro.com/software/open-source/why-open-source-risks-threaten-all-business-users">Why we need a better understanding of open source software</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Anthropic says MCP will stay 'open, neutral, and community-driven' after donating project to Linux Foundation ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/software/open-source/anthropic-says-mcp-will-stay-open-neutral-and-community-driven-after-donating-project-to-linux-foundation</link>
                                                                            <description>
                            <![CDATA[ The AAIF aims to standardize agentic AI development and create an open ecosystem for developers ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">ridEDkJQbyCkLjL8CC66tZ</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/F544LwcWajpJxKW9GjnkoW-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 10 Dec 2025 14:17:03 +0000</pubDate>                                                                                                                                <updated>Wed, 10 Dec 2025 22:17:31 +0000</updated>
                                                                                                                                            <category><![CDATA[Open Source]]></category>
                                                    <category><![CDATA[Software]]></category>
                                                                                                <author><![CDATA[ ross.kelly@futurenet.com (Ross Kelly) ]]></author>                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Ross Kelly is ITPro&#039;s News &amp;amp; Analysis Editor, with a keen interest in cyber security, business leadership and emerging technologies.&lt;/p&gt;
&lt;p&gt;He graduated from Edinburgh Napier University in 2016 with a BA (Hons) in Journalism, and joined ITPro in 2022 after four years working in technology conference research.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;In his spare time, Ross enjoys cycling, walking and is an avid reader of history and non-fiction.&lt;/p&gt;
&lt;p&gt;You can contact Ross at ross.kelly@futurenet.com or on &lt;a href=&quot;https://twitter.com/rosswritesetc&quot;&gt;Twitter&lt;/a&gt; and &lt;a href=&quot;https://www.linkedin.com/in/ross-kelly-18a54411a/&quot;&gt;LinkedIn&lt;/a&gt;.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/F544LwcWajpJxKW9GjnkoW-1280-80.jpg">
                                                            <media:credit><![CDATA[ITPro/Ross Kelly]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Anthropic logo pictured at the company&#039;s exhibitor stall in the vendor expo at AWS re:Invent 2025, hosted at the Venetian Hotel and Casino in Las Vegas, Nevada.]]></media:description>                                                            <media:text><![CDATA[Anthropic logo pictured at the company&#039;s exhibitor stall in the vendor expo at AWS re:Invent 2025, hosted at the Venetian Hotel and Casino in Las Vegas, Nevada.]]></media:text>
                                <media:title type="plain"><![CDATA[Anthropic logo pictured at the company&#039;s exhibitor stall in the vendor expo at AWS re:Invent 2025, hosted at the Venetian Hotel and Casino in Las Vegas, Nevada.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/F544LwcWajpJxKW9GjnkoW-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Anthropic and OpenAI are set to donate projects to the Linux Foundation following the launch of the <a href="https://www.itpro.com/software/28109/what-is-open-source">open source</a> organization’s new Agentic AI Foundation (AAIF).</p><p>According to the Linux Foundation, the AAIF will act as a “neutral, open foundation” for open source <a href="https://www.itpro.com/technology/artificial-intelligence/practical-ai-the-age-of-agentic-ai">agentic AI</a> projects, providing organizations with an ecosystem of tools, standards, and “community-driven innovation”.</p><p>The duo are among the inaugural backers of the new foundation, with other members including <a href="https://www.itpro.com/cloud/infrastructure-as-a-service-iaas/362608/what-is-aws">Amazon Web Services (AWS)</a>, Cloudflare, Google, Block, and Bloomberg.</p><p>“The advent of agentic AI represents a new era of autonomous decision making and coordination across AI systems that will transform and revolutionize entire industries,” the foundation said in a statement. </p><p>“With founding contributions from Anthropic, Block, and OpenAI, the AAIF unites cutting-edge technology and open source governance to shape the future of open and accessible <a href="https://www.itpro.com/strategy/28181/what-is-ai">AI</a>.”</p><h2 id="anthropic-pledges-to-keep-mcp-open-source">Anthropic pledges to keep MCP open source</h2><p>As part of the launch, Anthropic revealed it will donate the <a href="https://www.itpro.com/technology/artificial-intelligence/what-is-model-context-protocol-mcp">Model Context Protocol (MCP)</a> open standards project. The <a href="https://www.itpro.com/software/development/microsoft-claims-ai-is-augmenting-developers-rather-than-replacing-them">AI developer</a> initially open sourced MCP in November 2024, but Mike Krieger, chief product officer at Anthropic, said this latest move will ensure it stays “open, neutral, and community-driven”.</p><p>MCP has quickly become the standard protocol for connecting AI models to the various external tools, applications, and data enterprises use in daily operations.</p><p>The protocol has been adopted by Claude, <a href="https://www.itpro.com/technology/artificial-intelligence/microsoft-copilot-review-ai-baked-into-your-apps">Microsoft Copilot</a>, Gemini, <a href="https://www.itpro.com/technology/artificial-intelligence-ai/369965/what-is-chatgpt-and-what-does-it-mean-for-businesses">ChatGPT</a>, Cursor, and a range of other popular AI platforms. To date, more than 10,000 MCP servers are in operation, underpinning projects ranging from basic developer tools to AI deployments at large enterprises. </p><p>A key factor behind its popularity lies in the fact it streamlines integration of AI models with tooling, helping boost security controls and faster deployment. </p><p>"MCP started as an internal project to solve a problem our own teams were facing,” Krieger explained. “When we open sourced it in November 2024, we hoped other developers would find it as useful as we did.”</p><p>“A year later, it's become the industry standard for connecting AI systems to data and tools, used by developers building with the most popular agentic coding tools and enterprises deploying on AWS, Google Cloud, and Azure,” he added. </p><p>“Donating MCP to the Linux Foundation as part of the AAIF ensures it stays open, neutral, and community-driven as it becomes critical infrastructure for AI.”</p><h2 id="openai-gets-in-on-the-act">OpenAI gets in on the act</h2><p>Alongside Anthropic, OpenAI has pledged to donate its AGENTS.md tool, which offers an open format for guiding and coordinating coding agents. </p><p>“AGENTS.md is a simple, universal standard that gives AI coding agents a consistent source of project-specific guidance needed to operate reliably across different repositories and toolchains,” according to the foundation.</p><p>This system works essentially by making agent behavior more predictable across multiple repositories, and has already been adopted by around 60,000 open source projects and agentic frameworks. </p><p>Organizations and platforms using this standard include <a href="https://www.itpro.com/security/a-flaw-in-googles-new-gemini-cli-tool-couldve-allowed-hackers-to-exfiltrate-data">Gemini CLI</a>, GitHub Copilot, Cursor, <a href="https://www.itpro.com/software/development/the-worlds-first-ai-software-engineer-isnt-living-up-to-expectations-cognition-ais-devin-assistant-was-touted-as-a-game-changer-for-developers-but-so-far-its-fumbling-tasks-and-struggling-to-compete-with-human-workers">Devin</a>, and OpenAI’s own Codex tool. </p><p>Nick Cooper, member of the technical staff at OpenAI, said the decision to donate AGENTS.md will facilitate more “open, transparent practices” for AI agent development, improving interoperability and safety. </p><p>“OpenAI has long believed that shared, community-driven protocols are essential to a healthy agentic ecosystem, which is why we’ve open sourced key building blocks like the Codex CLI, the Agents SDK, and now AGENTS.md,” he said. </p><p>“We’re proud to work alongside our co-founders to advance a more open and trustworthy future for agentic AI.” </p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/software/open-source/open-source-ai-performance-cost-savings-proprietary-models-linux-foundation">Open source AI models are cheaper than closed source competitors</a></li><li><a href="https://www.itpro.com/software/development/claude-code-is-coming-to-slack-heres-how-to-use-it-what-it-can-do-and-how-to-get-access">Claude Code is coming to Slack</a></li><li><a href="https://www.itpro.com/software/development/anthropic-claude-code-for-web-closed-beta-launch">Anthropic’s new Claude Code web portal aims to make AI coding even more accessible</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Open source AI models are cheaper than closed source competitors and perform on par, so why aren’t enterprises flocking to them? ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/software/open-source/open-source-ai-performance-cost-savings-proprietary-models-linux-foundation</link>
                                                                            <description>
                            <![CDATA[ Open source AI models often perform on-par with closed source options and could save enterprises billions in cost savings, new research suggests, yet uptake remains limited. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">TDCcqRgwYMRE2n3rNBELaH</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Qqk6pii9EWCwxVWtKiWkhY-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 28 Nov 2025 08:45:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Open Source]]></category>
                                                    <category><![CDATA[Software]]></category>
                                                                                                <author><![CDATA[ ross.kelly@futurenet.com (Ross Kelly) ]]></author>                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Ross Kelly is ITPro&#039;s News &amp;amp; Analysis Editor, with a keen interest in cyber security, business leadership and emerging technologies.&lt;/p&gt;
&lt;p&gt;He graduated from Edinburgh Napier University in 2016 with a BA (Hons) in Journalism, and joined ITPro in 2022 after four years working in technology conference research.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;In his spare time, Ross enjoys cycling, walking and is an avid reader of history and non-fiction.&lt;/p&gt;
&lt;p&gt;You can contact Ross at ross.kelly@futurenet.com or on &lt;a href=&quot;https://twitter.com/rosswritesetc&quot;&gt;Twitter&lt;/a&gt; and &lt;a href=&quot;https://www.linkedin.com/in/ross-kelly-18a54411a/&quot;&gt;LinkedIn&lt;/a&gt;.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Qqk6pii9EWCwxVWtKiWkhY-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Open source AI concept image showing artificial human brain imposed over a background showing glowing data points.]]></media:description>                                                            <media:text><![CDATA[Open source AI concept image showing artificial human brain imposed over a background showing glowing data points.]]></media:text>
                                <media:title type="plain"><![CDATA[Open source AI concept image showing artificial human brain imposed over a background showing glowing data points.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Qqk6pii9EWCwxVWtKiWkhY-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p><a href="https://www.itpro.com/software/28109/what-is-open-source">Open source</a> AI models often perform on-par with closed source options and could save enterprises billions each year in cost savings, new research suggests, yet uptake remains limited. </p><p>In a new working paper, <a href="https://papers.ssrn.com/sol3/papers.cfm?abstract_id=5767103" target="_blank"><u><em>The Latent Role of Open Models in the AI Economy</em></u></a>, researchers Frank Nagle and Daniel Yue found closed models from major providers naturally dominate the market. </p><p>Drawing on data from OpenRouter, closed models account for around 80% of overall usage globally while also generating roughly 96% of revenue. This dominance isn’t driven by a “substantial performance gap”, however. </p><p>In fact, open models “routely achieve 90% or more” of the performance of closed counterparts. These models also benefit from “significantly lower prices” compared to closed models, researchers found, with operational costs up to 84% lower. </p><p>“If open models offer comparable performance at substantially lower prices, why do closed models continue to dominate?” the paper notes. </p><p>Simply put, there’s more to open source <a href="https://www.itpro.com/strategy/28181/what-is-ai">AI </a>use than performance and cost factors, particularly for enterprises balancing these aspects alongside security and regulatory considerations. </p><h2 id="open-source-considerations">Open source considerations</h2><p>In a <a href="https://www.linuxfoundation.org/blog/revealing-the-hidden-economics-of-open-models-in-the-ai-era" target="_blank"><u>blog post</u></a> detailing the research, Nagle said developers typically opted for closed options “even when an open model both performs better and costs less” and identified a range of factors that influenced this decision process. </p><p>Switching costs, for example, were among those highlighted as a barrier for teams as many have “optimized workflows around specific model behaviors”. </p><p>“Changing models creates friction,” he noted. </p><p>Brand trust and “perceived safety” were also key factors, with enterprises typically more comfortable opting for models from household names regardless of whether the costs outweigh the benefits of an open model.</p><p>Elsewhere regulatory considerations were a lingering issue. Nagle noted that closed model providers can often provide “contractual assurances” that open alternatives cannot. </p><p>But are closed source models truly more secure? Some industry stakeholders raised concerns about the security implications of open source AI in the wake of the DeepSeek launch in early 2025. </p><p>Speaking to <em>ITPro </em>earlier this year, Andy Ward, SVP International at Absolute Security, equated using the Chinese open source model to essentially “<a href="https://www.itpro.com/security/using-deepseek-at-work-security-risks">printing out and handing over your confidential information</a>”. </p><p>John Smith, EMEA <a href="https://www.itpro.com/strategy/28237/cto-job-description-what-does-a-cto-do">chief technology officer (CTO)</a> at Veracode, echoed these concerns on the security front. </p><p>“Open source models such as <a href="https://www.itpro.com/technology/artificial-intelligence/chinese-ai-firm-deepseek-has-silicon-valley-flustered">DeepSeek</a> and Llama are built on complex ecosystems of external libraries and dependencies,” he told <em>ITPro</em>. </p><p>“While these are essential for functionality, they can introduce significant vulnerabilities, with over 70% of applications containing open source flaws that often go undetected. Hidden backdoors, outdated code and insufficient patching practices are just some of the issues that can arise and are free for attackers to exploit,” Smith added. </p><p>“As we saw with the <a href="https://www.itpro.com/software/open-source/we-got-lucky-what-the-xz-utils-backdoor-says-about-the-strength-and-insecurities-of-open-source">XZ Utils backdoor</a> incident in Linux systems, these types of flaws can have catastrophic consequences, affecting not only individual systems but potentially global networks.”</p><p>Despite some concerns, Amanda Brock, CEO of OpenUK argued that so-called security discrepancies associated with open source models aren’t too dissimilar to those found in closed options. </p><p>“I am yet to be shown how opening this up is worse than black box technology in the hands of a few,” she told <em>ITPro</em>. “Bad actors are equally able to hack into this as we have seen many times”. </p><p>Smith, meanwhile, noted that the context of open source AI use – particularly in terms of control over data – is crucial here when calculating risk.</p><p>“When self-hosting an open source model the business will have more control over where their data resides and how it is used,” he explained. </p><p>“With proprietary models hosted by the provider, businesses will need to thoroughly understand where their data will be stored and how it may be used by the provider in order to make an informed decision about the approach to take.”</p><p>With this in mind, “black box” options from major providers raise the same regulatory compliance and security considerations. According to Tom Finch, engineering leader at Chainguard, organizations in heavily regulated industries are using open source <a href="https://www.itpro.com/technology/artificial-intelligence/amazing-ai-tools-to-try-today">AI tools</a> due to the transparency they afford from a regulatory perspective. </p><p>“When it comes to enterprise AI, open source needs cost and flexibility but also trust. We’re seeing a clear shift: highly regulated industries are turning to open source models because they need transparency and auditability,” he explained. </p><p>“You simply can’t meet compliance standards or anticipate risks if you’re dealing with a black box model. Open source makes it possible to inspect every dependency, which is essential for responsible AI adoption.”</p><h2 id="the-cost-of-not-choosing-open-source">The cost of not choosing open source</h2><p>Notably, the research paper found that hesitancy on the part of enterprises not only means many are missing out on lucrative savings, but raises serious questions for the open source community over how it can emphasize the potential benefits. </p><p>Nagle and Yue found that the global “AI economy” could save anywhere between $20-48 billion each year if users opted for models based solely on price and performance, which tips in favor of the open source ecosystem. </p><p>“Our preferred estimate is $24.8 billion in annual unrealized value, based on an extrapolation of Menlo Ventures’ 2025 estimate of the LLM inference market size and our observed underutilization rates,” Nagle wrote. </p><p>“For Linux Foundation stakeholders, including enterprises considering open model AI adoption, policymakers evaluating market competitiveness, and engineers building tooling atop open ecosystems, this is a critical insight,” he added. </p><p>“Open models are not just philosophically important, they are economically indispensable.”</p><p><a href="https://newsroom.ibm.com/image/IBM_ROI_of_AI_Report-December_2024.pdf">Analysis from IBM and Morning Consult</a> in January this year found enterprises opting for open source AI models typically record a stronger return on investment than those working with proprietary models. </p><p>According to the study, 51% of firms using open source options recorded returns, whereas just 41% of those working with proprietary models saw positive gains. </p><p>IBM noted that these positive returns showcased the appeal of open source for enterprises, with two-in-five <em>not </em>using these models planned to turn to it to unlock financial gains. </p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/technology/artificial-intelligence/just-how-open-are-the-leading-open-source-ai-platforms">Just how 'open' are the leading open source AI models?</a></li><li><a href="https://www.itpro.com/technology/artificial-intelligence/meta-open-source-ai-linux-foundation">Meta faces new ‘open washing’ accusations with AI whitepaper</a></li><li><a href="https://www.itpro.com/software/open-source/new-definition-of-open-source-ai-is-flawed-experts-say">New definition of open source AI is “flawed”, experts say</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Developers face a torrent of malware threats as malicious open source packages surge 188% ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/malware/developers-face-a-torrent-of-malware-threats-as-malicious-open-source-packages-surge-188-percent</link>
                                                                            <description>
                            <![CDATA[ Researchers have identified more than 16,000 malicious open source packages across popular ecosystems ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">jAgGygn4ZH59PBSiZHmgQ9</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/mP59D9NhKL5dmDvk5CMAzZ-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 08 Jul 2025 11:17:33 +0000</pubDate>                                                                                                                                <updated>Tue, 08 Jul 2025 11:17:52 +0000</updated>
                                                                                                                                            <category><![CDATA[Malware]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/mP59D9NhKL5dmDvk5CMAzZ-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Neptune RAT malware concept image showing a skull and crossbones in binary code against a red colored backdrop.]]></media:description>                                                            <media:text><![CDATA[Neptune RAT malware concept image showing a skull and crossbones in binary code against a red colored backdrop.]]></media:text>
                                <media:title type="plain"><![CDATA[Neptune RAT malware concept image showing a skull and crossbones in binary code against a red colored backdrop.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/mP59D9NhKL5dmDvk5CMAzZ-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The number of <a href="https://www.itpro.com/security/open-source-malware-surged-by-156-percent-in-2024">open source malware</a> packages is rising fast, and security researchers are warning <a href="https://www.itpro.com/business-strategy/careers-training/356509/how-to-become-a-software-developer">software developers</a> to remain vigilant.</p><p>Software supply chain security firm Sonatype reports that it uncovered 16,279 malicious open source packages across major ecosystems, including npm and PyPI, over the last quarter.</p><p>Overall, the total volume of malware logged by the firm has surged by 188% compared with the same quarter last year.</p><div class="product"><a data-dimension112="6ad7363c-82bd-4992-b607-fe686f2aabbe" data-action="Deal Block" data-label="30% off Keeper Security's Business Starter and Business plans" data-dimension48="30% off Keeper Security's Business Starter and Business plans" href="https://www.keepersecurity.com/en_GB/affiliate/business/" target="_blank" rel="nofollow"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:310px;"><p class="vanilla-image-block" style="padding-top:52.58%;"><img id="VVXzWjJJrXo7mwL5n5f4mf" name="Keeper Security logo.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/VVXzWjJJrXo7mwL5n5f4mf.png" mos="" align="middle" fullscreen="" width="310" height="163" attribution="" endorsement="" credit="" class=""></p></div></div></figure></a><p><a href="https://www.keepersecurity.com/en_GB/affiliate/business/" data-dimension112="6ad7363c-82bd-4992-b607-fe686f2aabbe" data-action="Deal Block" data-label="30% off Keeper Security's Business Starter and Business plans" data-dimension48="30% off Keeper Security's Business Starter and Business plans" data-dimension25=""><strong>30% off Keeper Security's Business Starter and Business plans</strong></a></p><p>Keeper Security is trusted and valued by thousands of businesses and millions of employees. Why not join them and protect your most important assets while taking advantage of this special offer?<a class="view-deal button" href="https://www.keepersecurity.com/en_GB/affiliate/business/" target="_blank" rel="nofollow" data-dimension112="6ad7363c-82bd-4992-b607-fe686f2aabbe" data-action="Deal Block" data-label="30% off Keeper Security's Business Starter and Business plans" data-dimension48="30% off Keeper Security's Business Starter and Business plans" data-dimension25="">View Deal</a></p></div><p>"Attackers are no longer simply experimenting with open source. The numbers are telling us that threat actors have identified data as the most profitable target, and developers as the easiest way in," said Brian Fox, CTO and co-founder of Sonatype. </p><p>“Developers and security teams must be vigilant, as threats increasingly hide in plain sight within everyday tools and dependencies.”</p><p>The main threat vector was data exfiltration, accounting for 55% of all malicious packages discovered. In the second quarter alone, Sonatype found more than 4,400 packages were specifically designed to steal sensitive data, including secrets, personally identifiable information (PII), passwords, access tokens, and API keys. </p><p>There was also a big rise in <a href="https://www.itpro.com/malware/28076/what-is-malware">malware </a>focused on data corruption, which now accounts for 3% of all malicious packages, twice as many as last year. </p><p>Meanwhile, cryptomining malware accounted for 5% of all packages in the second quarter, slightly down from the previous quarter. Sonatype attributed this to a shift among attackers from resource exploitation to credential theft and long-term infiltration.</p><p>Many of the packages used advanced techniques for exfiltrating sensitive data, including exfiltrating .git-credentials, AWS secrets, and environment variables; targeting developer systems to harvest credentials used in <a href="https://www.itpro.com/development/32887/what-is-continuous-integration">CI/CD</a> pipelines; and using time-delayed payloads and encrypted transmissions to avoid detection.</p><p>"We continue to see a large volume of malware targeting environment variables, config files, and other common places used by CI/CD tools and cloud services to store sensitive information," said Sonatype principal security researcher Garrett Calpouzos. </p><p>"Once attackers collect these credentials, they can attempt unauthorized access to cloud accounts, APIs, databases, and internal systems, opening the door to broader compromise and exploitation."</p><h2 id="open-source-ecosystem-threats-are-growing">Open source ecosystem threats are growing</h2><p>The notorious <a href="https://www.itpro.com/security/malware/369189/lazarus-group-targets-macos-users-with-counterfeit-crypto-job-offers">Lazarus Group</a>, an Advanced Persistent Threat (APT) associated with the North Korean regime, was behind 107 packages, accounting for more than 30,050 known downloads. </p><p>Earlier this year, SecurityScorecard revealed that the group's latest campaign, dubbed Operation Marstech Mayhem, was based on an advanced implant named Marstech1 and designed to compromise software developers and cryptocurrency wallets through manipulated open source repositories. </p><p>By embedding its malware inside NPM packages, researchers said it made it almost impossible for developers to detect without thorough vetting. </p><p>Similarly, Fortinet warned last year it had identified thousands of malicious packages distributed across <a href="https://www.itpro.com/development/open-source/369920/350000-open-source-projects-vulnerable-15-year-old-python-bug">open source repositories</a>. </p><p>The packages included lightweight code designed to evade detection, scripts that execute malware upon installation and packages lacking repository URLs, making them harder to trace.</p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/security/malware-free-attacks-surged-in-2024-as-attackers-drop-malicious-software-for-legitimate-tools">Malware-free attacks surged in 2024 as attackers drop malicious software for legitimate tools</a></li><li><a href="https://www.itpro.com/security/malware/infostealer-malware-exposed-credentials">A ‘significant increase’ in infostealer malware attacks left 3.9 billion credentials exposed to cyber criminals last year</a></li><li><a href="https://www.itpro.com/security/malware/why-malware-as-a-service-is-becoming-a-serious-problem">Why ‘malware as a service’ is becoming a serious problem</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ AI-generated code is in vogue: Developers are now packing codebases with automated code – but they’re overlooking security and leaving enterprises open to huge risks ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/software/development/ai-generated-code-software-developer-security-risk</link>
                                                                            <description>
                            <![CDATA[ While AI-generated code is helping to streamline operations for developer teams, many are overlooking crucial security considerations. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">dLJRYkFr7Ha6x66gpzrgWc</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/9McQShLfT2XqUhUJpDwwYo-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 23 Jun 2025 08:10:00 +0000</pubDate>                                                                                                                                <updated>Tue, 01 Jul 2025 12:49:58 +0000</updated>
                                                                                                                                            <category><![CDATA[Development]]></category>
                                                    <category><![CDATA[Software]]></category>
                                                                                                <author><![CDATA[ ross.kelly@futurenet.com (Ross Kelly) ]]></author>                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Ross Kelly is ITPro&#039;s News &amp;amp; Analysis Editor, with a keen interest in cyber security, business leadership and emerging technologies.&lt;/p&gt;
&lt;p&gt;He graduated from Edinburgh Napier University in 2016 with a BA (Hons) in Journalism, and joined ITPro in 2022 after four years working in technology conference research.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;In his spare time, Ross enjoys cycling, walking and is an avid reader of history and non-fiction.&lt;/p&gt;
&lt;p&gt;You can contact Ross at ross.kelly@futurenet.com or on &lt;a href=&quot;https://twitter.com/rosswritesetc&quot;&gt;Twitter&lt;/a&gt; and &lt;a href=&quot;https://www.linkedin.com/in/ross-kelly-18a54411a/&quot;&gt;LinkedIn&lt;/a&gt;.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/9McQShLfT2XqUhUJpDwwYo-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Quality assurance concept image showing female software developer examining and assessing AI-generated code on a desktop computer while sitting in an open plan office space with colleagues nearby.]]></media:description>                                                            <media:text><![CDATA[Quality assurance concept image showing female software developer examining and assessing AI-generated code on a desktop computer while sitting in an open plan office space with colleagues nearby.]]></media:text>
                                <media:title type="plain"><![CDATA[Quality assurance concept image showing female software developer examining and assessing AI-generated code on a desktop computer while sitting in an open plan office space with colleagues nearby.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/9McQShLfT2XqUhUJpDwwYo-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Nearly half of developers using AI to support operations say their codebases are now largely AI-generated, new research shows. </p><p>A survey from Cloudsmith found 42% of developers admitted to having AI-filled codebases, with respondents noting that the use of AI has helped them markedly improve productivity and efficiency. </p><p>Yet despite the influx of AI-generated code, long-standing best practices are being overlooked, the study warned. Just over two-thirds (67%) of developers said they review code before deployments, raising concerns over software security. </p><p>Glenn Weinstein, CEO at Cloudsmith, said the use of <a href="https://www.itpro.com/technology/artificial-intelligence/ai-in-software-engineering-six-ways-the-profession-is-changing">AI in software development</a> does present opportunities for development teams, but warned against placing complete faith in <a href="https://www.itpro.com/strategy/28181/what-is-ai">AI</a>. </p><p>“Software development teams are shipping faster, with more AI-generated code and AI agent-led updates,” he said. </p><p>“<a href="https://www.itpro.com/technology/artificial-intelligence/amazing-ai-tools-to-try-today">AI tools</a> have had a huge impact on <a href="https://www.itpro.com/software/development/ai-tools-software-development-workforce-layoffs">developer productivity</a>, which is great. That said, with potentially less human scrutiny on generated code, it’s more important that leaders ensure the right automated controls are in place for the software supply chain.”</p><p>The study noted that a growing number of developers are not only becoming reliant on AI-generated code, but are also placing a greater degree of trust in code written by <a href="https://www.itpro.com/technology/artificial-intelligence/ai-tools-critical-thinking-reliance">AI tools</a>. </p><p>Around 20% said they trust AI-generated code “completely”, the study found. </p><p>Notably, there are those in the profession taking a more considered approach to the use of AI in code generation. More than half (59%) said they apply additional scrutiny to AI-generated packages, for example, but a gap on enforcement is emerging at some enterprises. </p><p>Around 17% said they have no control policies in place over the use of AI in development processes, or for the use of AI-generated code. Similarly, roughly one-third (34%) noted they use tools that enforce policies specific to AI-generated packages, but this still leaves a glaring gap and could leave them open to threats. </p><p>The rise of <a href="https://www.itpro.com/technology/artificial-intelligence-ai/369959/what-is-generative-ai">generative AI</a> and its use in <a href="https://www.itpro.com/business-strategy/careers-training/356509/how-to-become-a-software-developer">software development</a> has been mirrored by a significant rise in “AI-specific exploits”, Cloudsmith noted. Among those highlighted in the study were ‘slopsquatting’, whereby attackers weaponize hallucinated package names suggested by coding assistants. </p><p>Developers and security practitioners alike also voiced concerns over their ability to spot potential exploits of flaws, with just 29% stating they feel “very confident” in their ability to detect vulnerabilities. </p><p>This is particularly risky when working with <a href="https://www.itpro.com/software/28109/what-is-open-source">open source</a> libraries, the study warned, where AI tools are likely to draw suggestions. </p><h2 id="ai-generated-code-is-in-vogue">AI-generated code is in vogue</h2><p>The use of AI-generated code has become a big talking point in the tech industry over the last year, with some leading companies having turned to the trend to speed up development. </p><p>In November last year, Google CEO Sundar Pichai revealed that <a href="https://www.itpro.com/technology/artificial-intelligence/sundar-pichai-says-more-than-25-percent-of-googles-code-is-now-generated-by-ai-and-its-a-big-hint-at-the-future-of-software-development"><u>around a quarter of the tech giant’s internal source code was AI-generated</u></a>, and that’s likely increased since then. </p><p>Speaking during an earnings call at the time, Pichai said Google was using AI across development teams both to speed up coding processes and to <a href="https://www.itpro.com/software/development/developer-burnout-has-reached-epidemic-proportions-and-manual-toil-is-a-key-factor">reduce manual toil</a> for developers. </p><p>Notably, Pichai insisted that all AI-generated code was subject to robust safety checks by human workers. Engineers are often kept in the loop to review this code, he noted. </p><p>Microsoft has also jumped on the bandwagon in this regard. During an appearance at Meta’s <em>LlamaCon</em> conference in April, CEO <a href="https://www.itpro.com/software/development/developers-will-need-to-adapt-microsoft-ceo-satya-nadella-joins-googles-sundar-pichai-in-revealing-the-scale-of-ai-generated-code-at-the-tech-giants-and-its-a-stark-warning-for-software-developers"><u>Satya Nadella told Mark Zuckerberg up to 30% of its code was written with AI</u></a>. </p><p>“I’d say maybe 20%, 30% of the code that is inside of our repos today and some of our projects are probably all written by software,” Nadella told Zuckerberg.</p><p>Nadella expects the volume of AI-generated code at the company to also steadily increase in the coming years. </p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/software/development/half-of-developers-want-to-quit-over-embarrassing-tech-stack">Half of developers want to quit over "embarrassing" tech stack</a></li><li><a href="https://www.itpro.com/software/development/software-security-shift-left-developer-overload">Shifting left might improve software security, but developers are becoming overwhelmed</a></li><li><a href="https://www.itpro.com/software/development/ai-coding-tools-are-finally-delivering-results-for-enterprises-developers-are-saving-so-much-time-theyre-able-to-collaborate-more-focus-on-system-design-and-learn-new-languages">AI coding tools are finally delivering results for enterprises</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Meta faces new ‘open washing’ accusations with AI whitepaper ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/technology/artificial-intelligence/meta-open-source-ai-linux-foundation</link>
                                                                            <description>
                            <![CDATA[ The tech giant has faced repeated criticism for describing its Llama AI model family as "open source". ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">daNDBHDjARag6rMQNMdhrC</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/hagZyYLKSTyZo9UPd9PZo6-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 30 May 2025 08:30:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Artificial Intelligence]]></category>
                                                    <category><![CDATA[Technology]]></category>
                                                                                                <author><![CDATA[ ross.kelly@futurenet.com (Ross Kelly) ]]></author>                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Ross Kelly is ITPro&#039;s News &amp;amp; Analysis Editor, with a keen interest in cyber security, business leadership and emerging technologies.&lt;/p&gt;
&lt;p&gt;He graduated from Edinburgh Napier University in 2016 with a BA (Hons) in Journalism, and joined ITPro in 2022 after four years working in technology conference research.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;In his spare time, Ross enjoys cycling, walking and is an avid reader of history and non-fiction.&lt;/p&gt;
&lt;p&gt;You can contact Ross at ross.kelly@futurenet.com or on &lt;a href=&quot;https://twitter.com/rosswritesetc&quot;&gt;Twitter&lt;/a&gt; and &lt;a href=&quot;https://www.linkedin.com/in/ross-kelly-18a54411a/&quot;&gt;LinkedIn&lt;/a&gt;.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/hagZyYLKSTyZo9UPd9PZo6-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Meta CEO Mark Zuckerberg pictured during the Meta Connect event in Menlo Park, California, next to a screen promoting open source AI. ]]></media:description>                                                            <media:text><![CDATA[Meta CEO Mark Zuckerberg pictured during the Meta Connect event in Menlo Park, California, next to a screen promoting open source AI. ]]></media:text>
                                <media:title type="plain"><![CDATA[Meta CEO Mark Zuckerberg pictured during the Meta Connect event in Menlo Park, California, next to a screen promoting open source AI. ]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/hagZyYLKSTyZo9UPd9PZo6-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p><a href="https://www.itpro.com/business/business-strategy/forget-the-metaverse-ai-is-the-money-spinner-at-meta-reality-labs-lost-usd4-4-billion-this-quarter-but-mark-zuckerbergs-razor-sharp-ai-focus-is-delivering-results-and-theres-more-to-come-with-llama-4-on-the-horizon">Meta </a>is facing fresh accusations of “open washing” after sponsoring a <a href="https://www.itpro.com/software/open-source/linux-foundation-unveils-redis-alternative-valkey-with-backing-from-aws-google-cloud-and-oracle">Linux Foundation</a> research paper detailing the growth of open source AI solutions.</p><p>The <a href="https://www.linuxfoundation.org/research/economic-impacts-of-open-source-AI" target="_blank"><u>study</u></a>, published earlier this month, highlights the benefits of open source AI systems, noting that they represent the most cost-effective options for enterprises of all sizes—particularly small businesses. </p><p>Notably, the study found organizations using <a href="https://www.itpro.com/business/sam-altman-open-source-ai-deepseek">closed source AI</a> models could expect to spend around three and a half times more on software compared to open source options. </p><p>The research is the latest in a slew of studies touting the benefits of open source AI. A <a href="https://www.itpro.com/software/open-source/open-source-AI-return-on-investment"><u>survey from IBM and Morning Consult</u></a> in January this year showed over half of enterprises using open source AI tools are more likely to see a positive return on investment (ROI). </p><p>Two-in-five respondents not yet using open source AI solutions revealed they plan to adopt these tools for <a href="https://www.itpro.com/technology/artificial-intelligence/are-most-ai-projects-destined-to-fail">AI projects</a> over the next year. </p><p>Meta’s involvement in the Linux Foundation study has proved to be controversial in this instance, with critics suggesting that it’s essentially been used to market the company’s <a href="https://www.itpro.com/technology/artificial-intelligence/meta-llama-4-model-launch-benchmarks">‘Llama’ AI models</a>. </p><p>OpenUK chief executive Amanda Brock said these models don’t meet the prerequisites to be classed as truly ‘open source’, yet neither Meta nor the study acknowledge this. </p><p>“Llama isn’t ‘<a href="https://www.itpro.com/software/28109/what-is-open-source">open source</a>’, whatever definition you chose to use for open source,” she said. </p><p>“Personally, I prefer the Open Source Software Definition (OSD) from the Open Source Initiative (OSI). Llama doesn’t meet its standard of open source for a number of reasons including the inclusion of a commercial restriction in its licensing,” Brock added. </p><p>“This restriction interrupts the free flow at the heart of open source licensing and creates friction. We rely on open source being usable by anyone for any purpose and Llama is not.”</p><h2 id="what-s-the-problem-with-meta-s-open-source-claims">What’s the problem with Meta’s open source claims?</h2><p>Meta’s flagship Llama model range is described as ‘open source’, but the company has faced repeated pushback from industry stakeholders on this claim, mainly due to disagreements over what actually constitutes ‘open source’.</p><p>This point of contention centers around licensing terms imposed upon users once they reach a certain level of commercialization. Essentially, Llama models are open access, but there are limitations imposed upon users in certain circumstances. </p><p>Earlier this year, the Open Source Initiative <a href="https://opensource.org/blog/metas-llama-license-is-still-not-open-source"><u>hit out at the company</u></a> on this topic, insisting that Meta “keeps on falsely promoting Llama as open source”.</p><p>While Brock commends Meta for its work with the Llama range as a “step in the right direction” in terms of open source awareness, the promotion of its models here still shows there’s a long way to go before “open washing” can be fully tackled in the tech industry. </p><p>“With Meta’s website listing a key takeaway of their report as <em>‘Linux Foundation Research shows how open source AI models, like Llama, are driving economic growth, innovation and competition by making crucial tech solutions more accessible’</em>, it’s hardly surprising that the OSI is up in arms and accusing the Linux Foundation of supporting open washing,” said Brock.</p><p>“Open washing isn’t just an open source issue today. With regulators like the EU using the term open source as the basis of exceptions to liability in AI and the standards that must be met in AI, the impact of open washing has become a societal one.”</p><p>Meta isn’t the only industry developer to have fallen foul of the open source definition debate in recent years. </p><p>In March 2024, <a href="https://www.itpro.com/technology/artificial-intelligence/databricks-just-launched-an-open-source-large-language-model-to-compete-with-llama-2-mixtral-and-gpt-35">Databricks launched its own large language model</a>, DBRX, which experts at the time also claimed didn’t meet open source standards. This was because it included an external acceptable use policy and operated on a license outside the jurisdiction of the OSI framework. </p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/software/open-source/why-open-source-risks-threaten-all-business-users">Open source risks threaten all business users – it’s clear we must get a better understanding of open source software</a></li><li><a href="https://www.itpro.com/software/open-source/new-definition-of-open-source-ai-is-flawed-experts-say">New definition of open source AI is “flawed”, experts say</a></li><li><a href="https://www.itpro.com/software/open-source/the-open-source-industry-is-booming-as-firms-invest-billions-in-ecosystem-each-year">The open source industry is booming as firms invest billions in ecosystem each year</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Redis unveils new tools for developers working on AI applications ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/software/redis-unveils-new-tools-for-developers-working-on-ai-applications</link>
                                                                            <description>
                            <![CDATA[ Redis has announced new tools aimed at making it easier for AI developers to build applications and optimize large language model (LLM) outputs. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">9UcNngoq7iTAMvyWAAgQeJ</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/rRhHjEWyHMzoLBHV9Q5zu8-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 11 Apr 2025 11:46:03 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Software]]></category>
                                                                                                <author><![CDATA[ ross.kelly@futurenet.com (Ross Kelly) ]]></author>                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Ross Kelly is ITPro&#039;s News &amp;amp; Analysis Editor, with a keen interest in cyber security, business leadership and emerging technologies.&lt;/p&gt;
&lt;p&gt;He graduated from Edinburgh Napier University in 2016 with a BA (Hons) in Journalism, and joined ITPro in 2022 after four years working in technology conference research.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;In his spare time, Ross enjoys cycling, walking and is an avid reader of history and non-fiction.&lt;/p&gt;
&lt;p&gt;You can contact Ross at ross.kelly@futurenet.com or on &lt;a href=&quot;https://twitter.com/rosswritesetc&quot;&gt;Twitter&lt;/a&gt; and &lt;a href=&quot;https://www.linkedin.com/in/ross-kelly-18a54411a/&quot;&gt;LinkedIn&lt;/a&gt;.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/rRhHjEWyHMzoLBHV9Q5zu8-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Open source AI concept image showing digitized human brain contained within a lightbulb, placed on top of a circuit board with binary code in background.]]></media:description>                                                            <media:text><![CDATA[Open source AI concept image showing digitized human brain contained within a lightbulb, placed on top of a circuit board with binary code in background.]]></media:text>
                                <media:title type="plain"><![CDATA[Open source AI concept image showing digitized human brain contained within a lightbulb, placed on top of a circuit board with binary code in background.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/rRhHjEWyHMzoLBHV9Q5zu8-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Redis has announced new tools aimed at making it easier for <a href="https://www.itpro.com/strategy/28181/what-is-ai">AI </a>developers to build applications and optimize <a href="https://www.itpro.com/technology/artificial-intelligence/generative-ai-vs-large-language-models">large language model (LLM)</a> outputs. </p><p>The new tools include LangCache, a fully-managed semantic caching service for applications and AI Agents that Redis said will help improve accuracy and speed. </p><p>Vector sets, meanwhile, are a new native data type that allows developers to more easily work with and scale vectors. </p><p>"Both give developers a simpler way to work with the complex data needed to build agentic apps," said Redis CEO Rowan Trollope in a <a href="https://redis.io/blog/spring-release-2025/"><u>blog post</u></a>. </p><p>LangCache looks to help developers integrate large language model (LLM) response caching into applications, with a REST API interface for easy implementation and optimizations included for accurate caching performance, the company said. </p><p>"Semantic caching is essential for GenAI applications, as it significantly reduces response latency and improves cost efficiency while maintaining high-quality user interactions," said Trollope in the blog post. </p><p>LangCache lets developers take a user query that's been asked before and return a relevant response that was cached, helping to save on costly calls to LLMs while also speeding up apps. </p><p>Redis said the tool will also help improve the accuracy of LLM cache retrieval using custom models and configurable search criteria, allow developers to choose a model provider of choice, and govern responses so apps bring back the right data approved for the current user. </p><p>"LangCache and vector sets give developers a simple way to handle the complex data needs that come with building agent-based AI apps," said Trollope in a statement. </p><p>“Just as traditional apps need a cache that stores frequently accessed data, agents need fast access to the data that helps them make decisions to complete their tasks. LangCache speeds up responses and provides more accurate answers, while vector sets give them a simple, elegant way to store and retrieve the data."</p><h2 id="vector-sets">Vector sets</h2><p>The other new announcement from Redis is vector sets: a new native data type that lets developers more easily work with vectors. Vector sets allow the storage and querying of high dimensional vector embeddings — crucial for AI and machine learning, the company said. </p><p>Vector sets were initially developed by Redis creator Salvatore Sanfilippo.</p><p>"They take inspiration from sorted sets, and extend this concept to store and query vector embeddings to search data semantically," Trollope wrote. </p><p>"Like a sorted set, a vector set has string elements, but now they’re associated with a vector instead of a score. The fundamental goal of vector sets is to make it possible to add items, and later get a subset of the added items that are the most similar to a specified vector."</p><p>They come with "exciting additional capabilities," the company said, including quantization, dimensionality reduction, filtering, and multi-threading. </p><p>Vector sets are currently <a href="https://redis.io/blog/announcing-vector-sets-a-new-redis-data-type-for-vector-similarity/"><u>available in beta</u></a> with Redis 8, which is itself available as a release candidate ahead of general availability in the next few weeks.</p><p>Last year Redis <a href="https://www.itpro.com/software/open-source/why-redis-license-changes-arent-the-end-of-the-world-for-open-source"><u>announced changes to its licensing</u></a> that would shift it to a more restrictive software distribution approach that would see cloud providers required to enter into commercial agreements with the company. The move sparked the Linux Foundation to create rival <a href="https://www.itpro.com/software/open-source/linux-foundation-unveils-redis-alternative-valkey-with-backing-from-aws-google-cloud-and-oracle"><u>Valkey</u></a>. </p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/software/development/red-teaming-comes-to-the-fore-as-devs-tackle-ai-application-flaws">Red teaming comes to the fore as devs tackle AI application flaws</a></li><li><a href="https://www.itpro.com/hardware/storage/ai-is-causing-a-data-storage-crisis-for-enterprises">AI is causing a data storage crisis for enterprises</a></li><li><a href="https://www.itpro.com/software/development/developers-are-struggling-to-build-generative-ai-applications-heres-why">Developers are at their wits end trying to build generative AI applications</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Open source risks threaten all business users – it’s clear we must get a better understanding of open source software ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/software/open-source/why-open-source-risks-threaten-all-business-users</link>
                                                                            <description>
                            <![CDATA[ Open source technology brings advantages to businesses but unless IT teams understand where code is coming from and how to maintain it, they face a number of unquantifiable risks ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">K5zzUfTxjCpMEawttCcRa3</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/TeTemFzsXKP9wv3C8GriNJ-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 26 Mar 2025 11:41:46 +0000</pubDate>                                                                                                                                <updated>Mon, 31 Mar 2025 13:04:43 +0000</updated>
                                                                                                                                            <category><![CDATA[Open Source]]></category>
                                                    <category><![CDATA[Software]]></category>
                                                                                                                    <dc:creator><![CDATA[ Stephen Pritchard ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/TeTemFzsXKP9wv3C8GriNJ-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Open source vulnerabilities concept image showing HTML code on a computer screen.]]></media:description>                                                            <media:text><![CDATA[Open source vulnerabilities concept image showing HTML code on a computer screen.]]></media:text>
                                <media:title type="plain"><![CDATA[Open source vulnerabilities concept image showing HTML code on a computer screen.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/TeTemFzsXKP9wv3C8GriNJ-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Open source systems are now deeply embedded across technology stacks, from Android devices to mission-critical enterprise systems and, of course, AI. There are businesses built on <a href="https://www.itpro.com/software/28109/what-is-open-source"><u>open source</u></a>, and organisations that have an open source first policy. And there are countless other businesses that use at least some open source, somewhere, in their operations.</p><p>Other surveys show that open source use is holding up. The <a href="https://www.openlogic.com/resources/state-of-open-source-report" target="_blank"><u>2024 State of Open Source survey</u></a> from vendor OpenLogic puts the use of open source technology at 95%. Recent research from the Linux Foundation, GitHub, and the Laboratory for Innovation Science at Harvard (LISH) found that businesses invest $7.7 billion into the open source ecosystem per year.</p><p>But the sheer ubiquity of open source, though, raises its own problems. All too often, IT teams lack a complete picture of how they use open source software (OSS), and where.</p><p>They are unlikely to know all the dependencies between open source components and other parts of their infrastructure.</p><p>In some cases, they might not even know they have OSS at all, usually because they have bought software, or services, where the vendor has used open source. One estimate, from <a href="https://www.blackduck.com/content/dam/black-duck/en-us/reports/rep-ossra.pdf" target="_blank"><u>Black Duck [PDF]</u></a>, is that 70-90% of the code in software as service offerings is, in fact, open source.</p><p>This lack of oversight causes issues, as we saw with the <a href="https://www.itpro.com/security/log4j-nearly-4000-organizations-still-vulnerable-two-years-on"><u>Log4J vulnerability</u></a> in which organizations scrambled to assess their exposure to a vulnerability in the widely-used open source library. Security is not the only concern. Licensing and support issues around open source can cause real problems for enterprises, if they lack proper visibility into how they use OSS, and where.</p><h2 id="taking-a-frank-look-at-open-source-risks">Taking a frank look at open source risks</h2><p>Enterprises use open source software for a host of good reasons: cost, flexibility, and the ability to view the source code are just some. <a href="https://www.itpro.com/software/open-source/how-leaders-can-ensure-open-source-adoption-is-a-success"><u>Adopted properly, open source</u></a> solutions can be more economical, and at least as robust and secure as proprietary applications. Open source advocates argue that OSS is actually more secure and more reliable.</p><p>But that does not remove all the risks.</p><p>“Open source is both a blessing and a liability,” Tomislav Ljubas, managing director for corporate IT and cyberSecurity at Gruppe Deutsche Börse / Stoxx tells <em>ITPro</em>. </p><p>“It gives flexibility, but that freedom comes at a cost: trust. The fundamental issue is the accountability, whom to ring when things go wrong? With proprietary software, there’s at least a vendor on the hook… With open source, you’re often betting on a maintainer who never signed up for 24/7 incident response.”</p><p>There is a danger that a well-meaning developer used, or reused, code created by an equally well-meaning contributor to the open source community. And, as Ljubas warns, that software can end up unsupported, leading to weaknesses and <a href="https://www.itpro.com/security/patch-management-why-firms-ignore-vulnerabilities-at-their-own-risk"><u>vulnerabilities</u></a> in systems that depend on it.</p><p>“Risk isn’t just about security vulnerabilities. It’s about operational resilience and legislation such as <a href="https://www.itpro.com/business/policy-and-legislation/dora-and-why-resilience-once-again-matters-to-the-board"><u>DORA</u></a>,” he says. “A critical dependency can disappear overnight due to burnout, license shifts, or outright hostility; see recent incidents where maintainers <a href="https://www.itpro.com/software/linux/359300/researchers-criticised-for-project-that-added-flaws-linux"><u>intentionally sabotaged projects</u></a>. Do you have a plan for that?”</p><p>“Open source is like all software,” says Matt Middleton-Leal, managing director for EMEA North at security vendor Qualys. “It is not the software itself that is problematic, but how it is kept up to date and managed. </p><p>“Open source software is often used within larger enterprise software deployments, whether those are from commercial suppliers or for internally developed applications, and those tools should be kept up to date to protect against issues or potential vulnerabilities.</p><p>“Where this falls down is when those tools are either overlooked, or ignored - this is where vulnerabilities creep in, and then can lead to potential attacks. The biggest example of this is Log4J - this tool was used widely across applications, but it contained a vulnerability. Fixing that issue was a huge issue for some companies.”</p><h2 id="using-oss-safely">Using OSS safely</h2><p>Better awareness among CIOs and software development teams was one result of Log4J, as experts worked to better manage open source software in order to reduce risk. Changes within the open source community itself have also reduced some of its core risks.</p><p>As Amanda Brock, CEO of open source industry group OpenUK points out, <a href="https://www.itpro.com/software/development/359246/how-to-download-from-github#:~:text=Forking%20allows%20you,pull%20request%20features."><u>“forking” open source projects</u></a> have removed some of the risks around OSS, including those from licence changes. Forking is hard work, but it maintains the open nature of code, Brock tells <em>ITPro</em>. But users still need to be on their guard.</p><p>“Despite the power of the fork, a wise user will check out the contributing community of a project to ensure that it is not employee-only, and become familiar with the health of a project, before it becomes dependent on that project,” Brock says. “This kind of process is increasingly a part of the ‘curation’ of open source by corporate users.”</p><p>Integrating open source into projects needs that extra effort, if enterprises are to keep their systems robust and secure. Tools such as <a href="https://www.itpro.com/security/software-inventories-may-give-hackers-clearer-route-for-attacks"><u>software bills of materials (SBOMs)</u></a> help with traceability and visibility but developer teams need to keep monitoring their code as well. Using software from an open source foundation, such as <a href="https://www.itpro.com/cloud/cloud-computing/what-is-cloud-native-and-how-can-it-generate-business-value"><u>Cloud Native</u></a> Computing Foundation (CNCF) or <a href="https://www.itpro.com/software/a-new-critical-vulnerability-in-apache-ofbiz-has-been-uncovered-heres-what-you-need-to-know"><u>Apache</u></a>, provides additional assurance.</p><p>“Adopting open source software should be taken as seriously as adopting proprietary code,” says Matt Barker, VP at Venafi. “Just because the open source code is ‘free’ you need to understand the motivations of the people behind the code and work out if you trust them.</p><p>“This applies just as much to the security of the code as well as the commercial considerations, and if they may end up ‘pulling the rug’ with a <a href="https://www.itpro.com/software/open-source/redis-insists-license-changes-were-the-only-way-to-compete-with-amazon-and-google-now-it-could-face-a-user-exodus"><u>license change</u></a> or some other change in business model. If you adopt open source, you have to accept it is not just one and done.”</p><p>It’s clear IT leaders will need to establish clear guidelines for open source within their organization, if they are to avoid future pain.</p><p>“Open source is powerful – but power without control is a risk,” adds Ljubas. “If you don’t have a structured approach to managing OSS in your supply chain, you’re not mitigating risk. You’re accumulating technical debt with an unpredictable interest rate.”</p><iframe allow="" height="200px" width="100%" data-lazy-priority="low" data-lazy-src="https://player.captivate.fm/episode/f5c88f0e-e192-4242-a16e-01865d65685b/"></iframe>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Open source security in the spotlight as UK gov publishes fresh guidance ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/software/open-source/open-source-security-in-the-spotlight-as-uk-gov-publishes-fresh-guidance</link>
                                                                            <description>
                            <![CDATA[ The UK government has issued guidance on how organizations should manage their use of open source software components and mitigate supply chain risks. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">ciDBjdLRdVnW5FTnkTeXai</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Mt73GCvpagJEey7k9cGfCA-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 14 Mar 2025 11:21:32 +0000</pubDate>                                                                                                                                <updated>Fri, 14 Mar 2025 17:05:06 +0000</updated>
                                                                                                                                            <category><![CDATA[Open Source]]></category>
                                                    <category><![CDATA[Software]]></category>
                                                                                                <author><![CDATA[ solomon.klappholz@futurenet.com (Solomon Klappholz) ]]></author>                    <dc:creator><![CDATA[ Solomon Klappholz ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/pjZQRW2qWqQNjxubC6SUQ5.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Solomon Klappholz is a Staff Writer at ITPro. He has experience writing about the technologies that facilitate industrial manufacturing which led to him developing a particular interest in IT regulation, industrial infrastructure applications, and machine learning.&lt;/p&gt;&lt;p&gt;Before he joined ITPro, Solomon graduated from the University of Warwick in 2021 with a BA (Hons) in Philosophy, Politics, and Economics which included an intercalated year studying Philosophy at the Erasmus University, Rotterdam.&lt;/p&gt;&lt;p&gt;Outside of the office, Solomon enjoys reading, visiting new art exhibitions, and playing football.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Mt73GCvpagJEey7k9cGfCA-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Programming code and big data wave on a black background.]]></media:description>                                                            <media:text><![CDATA[Programming code and big data wave on a black background.]]></media:text>
                                <media:title type="plain"><![CDATA[Programming code and big data wave on a black background.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Mt73GCvpagJEey7k9cGfCA-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The <a href="https://www.itpro.com/technology/uk-government-quantum-investment-welcomed-by-industry">UK government</a> has issued guidance on how organizations should manage their use of open source software (OSS) components and mitigate supply chain risks, as thousands of open source vulnerabilities leave businesses at risk.</p><p>Combining guidance from international governments, industry, and academia, the report from the <a href="https://www.itpro.com/security/uk-cybersecurity-sector-economic-value">Department of Science, Information, and Technology</a> (DSIT) offers advice on the usage, production, security, and licensing of open source software.</p><p>The recommendations, which the report said were selected as the most appropriate for organizations of any size and sector, comprise four best practices it claimed constitute a ‘proportionate and reasonable approach to <a href="https://www.itpro.com/software/28109/what-is-open-source">OSS</a> risk management”.</p><p>Firstly, DSIT recommends that businesses should establish an internal OSS policy around managing the adoption of OSS components. Creating a <a href="https://www.itpro.com/security/software-security-overhauled-for-the-better-thanks-to-us-legislation">software bill of materials</a> (SBOM) is also essential for tracking OSS components and their various dependencies.</p><p>Similarly, organizations should ensure they are continuously monitoring their software supply chain using <a href="https://www.itpro.com/software/368809/gartner-software-businesses-must-adopt-devsecops-before-it-becomes-mainstream">software composition analysis</a> (SCA) tools to identify vulnerabilities in their codebase or any potential licensing issues.</p><p>The report also urged businesses to actively engage with the OSS community, which it says will “attract new talent, level the competitive playing field, foster innovation, improve reputation, and ensure high-quality OSS components and a sustainable <a href="https://www.itpro.com/software/open-source/the-open-source-industry-is-booming-as-firms-invest-billions-in-ecosystem-each-year">OSS ecosystem</a>”.</p><p>In addition, DSIT strongly recommends adopting tools to automate OSS management to alleviate time and resource constraints that may fall on smaller organizations.</p><h2 id="dsit-report-lacks-detail-on-vulnerability-management">DSIT report lacks detail on vulnerability management </h2><p>Chris Hughes, chief security advisor at <a href="https://www.itpro.com/channel/370262/endor-labs-launches-100-channel-commitment-with-new-partner-programme">Endor Labs</a> and cyber innovation fellow at CISA, said he was impressed by the broad and comprehensive range of guidance it has distilled from various resources.</p><p>However, he cautioned that some organizations may be overwhelmed by the measures the report suggests and advised they should start with the most basic recommendations before moving forward.</p><p>Hughes also noted that the report did not provide specific details on  vulnerability management practices that firms will have to familiarize themselves with to mitigate flaws and <a href="https://www.itpro.com/software/software-supply-chain-attacks-are-rife-this-is-what-developers-need-to-watch-out-for">software supply risks</a>.</p><p>“While it touches on <a href="https://www.itpro.com/security/vulnerability-management-complexity-is-leaving-enterprises-at-serious-risk">vulnerability management</a> and <a href="https://www.itpro.com/security/ruthlessly-prioritize-whats-critical-check-point-expert-on-cisos-and-the-evolving-attack-surface">prioritization</a> it didn’t go into much depth in terms of key modern specifics. Examples such as reachability, known exploitation, exploitation probability and organizational context were lacking,” he explained.</p><p>“Organizations need to make these improvements to be able to sift through the noisy nature of the vulnerability landscape, especially when it comes to OSS.”</p><h2 id="open-source-security-concerns-linger">Open source security concerns linger</h2><p>Open source security has become a growing risk exposing organizations to cyber attacks - and one that has traditionally been neglected by many businesses.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED WHITEPAPER</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="tvawFkCaNr5vdotoTDCE6Z" name="The life sciences guide to AI-driven innovations.jpg" caption="" alt="The life sciences guide to AI-driven innovations" src="https://cdn.mos.cms.futurecdn.net/tvawFkCaNr5vdotoTDCE6Z.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: AWS)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/infrastructure/the-life-sciences-guide-to-ai-driven-innovations"><em>Reinvent your business with data and AI</em></a></p></div></div><p>A recent <a href="https://www.blackduck.com/resources/analyst-reports/open-source-security-risk-analysis.html" target="_blank">study</a> from <a href="https://www.itpro.com/business/leadership/black-duck-continues-leadership-expansion-with-double-hire">Black Duck</a> found that 86% of codebases contained open source vulnerabilities, with 81% being classified as critical risks, marking a 7% increase on last year’s figures.</p><p>The report concluded that the growth in open source vulnerabilities suggests developer organizations are unable to track the vast number of software dependencies they’re using, and not <a href="https://www.itpro.com/security/patch-management-why-firms-ignore-vulnerabilities-at-their-own-risk">prioritizing the remediation of these flaws</a> accordingly.</p><p>This underscores the importance of implementing SCA tools, SBOMs, and similar measures to track and identify vulnerabilities in your organization, Black Duck noted.</p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/security/cyber-attacks/github-malvertising-campaign-microsoft">Nearly a million devices were infected in a huge GitHub malvertising campaign</a></li><li><a href="https://www.itpro.com/software/development/java-developer-productivity-challenges">Java developers are facing serious productivity issues</a></li><li><a href="https://www.itpro.com/security/cyber-crime/gitvenom-campaign-uses-dodgy-github-repositories-to-spread-malware">'GitVenom' campaign uses dodgy GitHub repositories to spread malware</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ ‘Awesome for the community’: DeepSeek open sourced its code repositories, and experts think it could give competitors a scare ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/software/open-source/deepseek-open-source-code-repository</link>
                                                                            <description>
                            <![CDATA[ Challenger AI startup DeepSeek has open-sourced some of its code repositories in a move that experts told ITPro puts the firm ahead of the competition on model transparency. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">No9W2iv5dRAXGbPwvTwLFU</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/MUZbb2FPBJsBCiUyGvvfAo-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 07 Mar 2025 05:00:00 +0000</pubDate>                                                                                                                                <updated>Fri, 07 Mar 2025 08:51:20 +0000</updated>
                                                                                                                                            <category><![CDATA[Open Source]]></category>
                                                    <category><![CDATA[Software]]></category>
                                                                                                <author><![CDATA[ george.fitzmaurice@futurenet.com (George Fitzmaurice) ]]></author>                    <dc:creator><![CDATA[ George Fitzmaurice ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/N4xHCjSAXKcijjt3oiQtfc.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/MUZbb2FPBJsBCiUyGvvfAo-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Landing page for the DeepSeek R1 website pictured on a smartphone held in a person&#039;s hand.]]></media:description>                                                            <media:text><![CDATA[Landing page for the DeepSeek R1 website pictured on a smartphone held in a person&#039;s hand.]]></media:text>
                                <media:title type="plain"><![CDATA[Landing page for the DeepSeek R1 website pictured on a smartphone held in a person&#039;s hand.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/MUZbb2FPBJsBCiUyGvvfAo-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Challenger <a href="https://www.itpro.com/strategy/28181/what-is-ai">AI </a>startup DeepSeek has open-sourced some of its code repositories in a move that experts told <em>ITPro</em> puts the firm ahead of the competition on model transparency.</p><p><a href="https://x.com/deepseek_ai/status/1892786555494019098" target="_blank"><u>In a post to </u><u><em>X</em></u><u> late last month</u></a>, DeepSeek said it would be open sourcing five of its code repositories in a bid to share what it called its “small but sincere progress with full transparency.”</p><p>“These humble building blocks in our online service have been documented, deployed, and battle-tested in production,” DeepSeek wrote.</p><p>“As part of the open-source community, we believe that every line shared becomes collective momentum that accelerates the journey,” the firm added. </p><p><a href="https://www.itpro.com/technology/artificial-intelligence/chinese-ai-firm-deepseek-has-silicon-valley-flustered"><u>DeepSeek caused ripples of panic earlier this year</u></a> when its sudden release raised questions about the value of previously unchallenged US competitors - DeepSeek’s models are competitive with the likes of OpenAI despite costing only a fraction of the price to build.  </p><p>Its openness also stood in stark contrast to some large proprietary US models, industry analysts noted at the time. Now, DeepSeek has gone even further by promising to open-source the code behind its model. <a href="https://www.itpro.com/technology/artificial-intelligence/just-how-open-are-the-leading-open-source-ai-platforms"><u>Its only competition in this regard is the likes of Meta’ Llama</u></a>, which has only open-sourced the weights of its models.</p><p>“To be clear, Llama has open weights, not open code - you can't see the training code or the actual training datasets. DeepSeek has gone a step further by open sourcing a lot of the code they use, which is awesome for the community,” Alistair Pullen, co-founder and CEO of Cosine, told <em>ITPro</em>. </p><p>“I think DeepSeek can probably feel comfortable giving their competitors a scare by doing stuff others won't do - it does diminish their edge, but they're not wholly a model company,” Pullen added. </p><h2 id="how-open-is-deepseek">How open is DeepSeek?</h2><p>DeepSeek is out ahead when it comes to open source AI, though that doesn’t mean it’s fully open in the traditional sense of the term. The firm hasn’t open-sourced the entirety of its code, nor key aspects of its model development such as training datasets.</p><p>The firm could gain an edge if it decides to share more of its code, according to Peter Schneider, senior product manager at Qt Group. </p><p>Code transparency is a big sticking point in terms of security and increased levels could create more community engagement, Schneider told <em>ITPro</em>. </p><p>“If they wanted to go the extra mile differentiating themselves, releasing their full training data and methodologies would certainly set a new standard for transparency in the AI race," Schneider added. </p><h2 id="industry-positive-about-open-source-move">Industry positive about open source move</h2><p>Experts have been largely positive about DeepSeek’s decision, with Pullen saying this move gives users a greater level of control and access. He referenced the ‘reinforcement learning algorithm’ that DeepSeek released, a far less memory intensive approach than others. </p><p>“Open-source AI models appeal to users because they offer greater flexibility, fine-tuning capabilities, and fewer vendor restrictions. But beyond that, the real advantage comes from the collective intelligence of the global open-source community,” Dirk Alshuth, cloud evangelist at emma, told <em>ITPro</em>. </p><p>“The number of contributors can grow to thousands, which ultimately leads to more robust models, innovative use cases, and applications built on top,” Alshuth said.</p><p>Continued transparency on this front will boost community engagement and give DeepSeek a unique selling point when compared to its largely closed-source competitors, Alshuth added. </p><p>“DeepSeek’s decision to share some of its AI model code is a welcome step toward greater openness in AI development,” Schneider said. </p><iframe allow="" height="200px" width="100%" data-lazy-priority="low" data-lazy-src="https://player.captivate.fm/episode/ac00050e-c9d3-4cc3-a3b9-a7b9947df5c1/"></iframe><h2 id="open-source-ai-is-a-tough-nut-to-crack">Open source AI is a tough nut to crack</h2><p>DeepSeek has pushed the definition of open source AI further, though this is just the latest in an ongoing conversation about how open source is defined in the AI arena when the technology is so fundamentally different from what’s gone before.</p><p><a href="https://www.itpro.com/technology/artificial-intelligence/just-how-open-are-the-leading-open-source-ai-platforms"><u>Speaking to </u><u><em>ITPro</em></u><u> at the time of Llama 3’s release</u></a> in 2024, Open UK CEO Amanda Brock said that current conversations around open source AI are stretching historic definitions of open source to their limits. </p><p>While elements of an AI application may be made open under a typical open source license, Brock said, other elements of an AI application may not lend themselves as easily to this definition. </p><p>Gradients, or “shades of openness,” could be the solution, Brock added, whereby different elements of an AI application are assigned different licenses. </p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/technology/artificial-intelligence/deepseek-r1-model-jailbreak-security-flaws"><strong>DeepSeek R1 has taken the world by storm, but security experts claim it has 'critical safety flaws' that you need to know about</strong></a></li><li><a href="https://www.itpro.com/technology/artificial-intelligence/the-deepseek-bombshell-has-been-a-wakeup-call-for-us-tech-giants"><strong>The DeepSeek bombshell has been a wakeup call for US tech giants</strong></a></li><li><a href="https://www.itpro.com/technology/artificial-intelligence/looking-to-use-deepseek-r1-in-the-eu-this-new-study-shows-its-missing-key-criteria-to-comply-with-the-eu-ai-act"><strong>Looking to use DeepSeek R1 in the EU? This new study shows it’s missing key criteria to comply with the EU AI Act</strong></a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ 86% of enterprise codebases contain open source vulnerabilities ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/software/open-source/86-percent-of-enterprise-codebases-contain-open-source-vulnerabilities</link>
                                                                            <description>
                            <![CDATA[ Research from Black Duck’s annual open source security report found 86% of codebases contained open source vulnerabilities. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">WagfcNH246LPC2Zf9nhtY7</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/qH4rSgzMX6EfrTyVvDH7aB-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 26 Feb 2025 12:33:29 +0000</pubDate>                                                                                                                                <updated>Fri, 14 Mar 2025 10:05:32 +0000</updated>
                                                                                                                                            <category><![CDATA[Open Source]]></category>
                                                    <category><![CDATA[Software]]></category>
                                                                                                <author><![CDATA[ solomon.klappholz@futurenet.com (Solomon Klappholz) ]]></author>                    <dc:creator><![CDATA[ Solomon Klappholz ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/pjZQRW2qWqQNjxubC6SUQ5.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Solomon Klappholz is a Staff Writer at ITPro. He has experience writing about the technologies that facilitate industrial manufacturing which led to him developing a particular interest in IT regulation, industrial infrastructure applications, and machine learning.&lt;/p&gt;&lt;p&gt;Before he joined ITPro, Solomon graduated from the University of Warwick in 2021 with a BA (Hons) in Philosophy, Politics, and Economics which included an intercalated year studying Philosophy at the Erasmus University, Rotterdam.&lt;/p&gt;&lt;p&gt;Outside of the office, Solomon enjoys reading, visiting new art exhibitions, and playing football.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/qH4rSgzMX6EfrTyVvDH7aB-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Cyber security concept image showing digitized padlock on a network interface with source code.]]></media:description>                                                            <media:text><![CDATA[Cyber security concept image showing digitized padlock on a network interface with source code.]]></media:text>
                                <media:title type="plain"><![CDATA[Cyber security concept image showing digitized padlock on a network interface with source code.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/qH4rSgzMX6EfrTyVvDH7aB-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Security vulnerabilities in <a href="https://www.itpro.com/software/28109/what-is-open-source">open source</a> projects have been a major threat to enterprises for years – and new research shows the issue is still causing havoc.</p><p>Research from Black Duck’s annual open source security <a href="https://www.blackduck.com/resources/analyst-reports/open-source-security-risk-analysis.html" target="_blank">report</a> found 86% of codebases contained <a href="https://www.itpro.com/software/open-source/open-source-vulnerabilities-dominated-2023-and-this-year-looks-no-different">open source vulnerabilities</a>. The report added that 81% of those were classified as high or critical risk, compared to 74% identified in the previous year.</p><p>Black Duck said this likely signals an inability among developer organizations to keep track of the vast number of software dependencies they’re using and <a href="https://www.itpro.com/security/ruthlessly-prioritize-whats-critical-check-point-expert-on-cisos-and-the-evolving-attack-surface">prioritize the remediation of vulnerabilities</a>.</p><p>As increasingly common software supply chain requirements such as <a href="https://www.itpro.com/security/software-inventories-may-give-hackers-clearer-route-for-attacks">SBOM</a> require organizations to get their software estate in order, getting on top of their dependency management is essential.</p><p>For example, Black Duck found the average application contains 911 open source dependencies, many of which are out of date or have lost community support.</p><p>It also discovered 91% of all codebases contained outdated open source software (OSS) components, with 90% featuring components more than ten versions behind the most current.</p><p><a href="https://www.itpro.com/business/leadership/black-duck-continues-leadership-expansion-with-double-hire">Black Duck</a> warned that by failing to properly clean codebases of these dependencies, firms are only giving themselves more work when they have to put together software bill of materials (SBOM) reports and risk evaluations.</p><p>The study also suggested that a shift towards web-based multi-tenant <a href="https://www.itpro.com/cloud/saas">SaaS</a> applications was responsible for the higher proportion of high severity vulnerabilities.</p><p>The jQuery <a href="https://www.itpro.com/development/30202/what-is-javascript-and-why-should-i-learn-it">JavaScript</a> library was identified as a particularly common area for weaknesses, accounting for eight of the top ten high-risk vulnerabilities Black Duck spotted.</p><p>It warned this is not necessarily indicative of a particular vulnerability with jQuery but the fact that an increasing number of organizations are adopting applications that leverage <a href="https://www.itpro.com/626203/jquery-gets-the-mobile-touch">jQuery</a>.</p><h2 id="transitive-dependencies-will-bring-new-licensing-headaches-for-businesses">Transitive dependencies will bring new licensing headaches for businesses</h2><p>One of the biggest differences the report observed between this year’s and last year’s study was license conflicts between open source components in the same codebase, noting this has increased the average number of license conflicts from 20 to 69.</p><p>The report found 56% of the audited codebases featured license conflicts, adding that ‘transitive dependencies’ were responsible for 30% of the license conflicts it found.</p><p>Transitive dependencies describe a situation where different software components indirectly rely on one another to properly function. This creates a complex web of interdependencies within and across codebases that can be very hard to manually keep track of.</p><p>Overall, 64% of OSS components in the audited application codebases were transitive dependencies.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED WHITEPAPER</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="Nx8bhk2AEsJ5MxCgQqcxgj" name="The business value of aligning cost optimization, observability, and automation (1).jpg" caption="" alt="Blue sky with stadium roof rails" src="https://cdn.mos.cms.futurecdn.net/Nx8bhk2AEsJ5MxCgQqcxgj.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: IBM)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/technology/artificial-intelligence/the-business-value-of-aligning-cost-optimization-observability-and-automation"><em>Reduce complexity when managing hybrid applications</em></a></p></div></div><p>In addition, the report noted that a third of codebases contained open source components with no license or a customized license, which would likely require legal review.</p><p>Black Duck emphasized that if one transitive dependency in the chain uses a restrictive license, this can potentially affect the licensing of the entire application even if the direct dependency has a more permissive license.</p><p>The firm predicted that businesses can expect to see an increase in license conflicts in the coming years, with <a href="https://www.itpro.com/software/ai-coding-assistants-might-speed-up-software-development-but-are-they-actually-helping-produce-better-code">AI coding assistants</a> introducing another way for open source components to be introduced into applications without proper source attribute and thus licensing.</p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/security/open-source-malware-surged-by-156-percent-in-2024">Open source malware surged by 156% in 2024</a></li><li><a href="https://www.itpro.com/security/ransomware/warning-issued-over-prolific-ghost-ransomware-group">Warning issued over prolific 'Ghost' ransomware group</a></li><li><a href="https://www.itpro.com/software/development/mongodb-third-party-app-flaws">Flaws in a popular dev library could let hackers run malicious code in your MongoDB database</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Flaws in a popular dev library could let hackers run malicious code in your MongoDB database ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/software/development/mongodb-third-party-app-flaws</link>
                                                                            <description>
                            <![CDATA[ A popular third party library of MongoDB could allow attackers to execute malicious code on company servers. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">9hWqUhGeqY4WWJ5TNSeu3B</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/yv2B6wyTLnGx24LDUYny8Z-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 20 Feb 2025 14:00:00 +0000</pubDate>                                                                                                                                <updated>Fri, 21 Feb 2025 12:59:21 +0000</updated>
                                                                                                                                            <category><![CDATA[Development]]></category>
                                                    <category><![CDATA[Software]]></category>
                                                                                                <author><![CDATA[ solomon.klappholz@futurenet.com (Solomon Klappholz) ]]></author>                    <dc:creator><![CDATA[ Solomon Klappholz ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/pjZQRW2qWqQNjxubC6SUQ5.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Solomon Klappholz is a Staff Writer at ITPro. He has experience writing about the technologies that facilitate industrial manufacturing which led to him developing a particular interest in IT regulation, industrial infrastructure applications, and machine learning.&lt;/p&gt;&lt;p&gt;Before he joined ITPro, Solomon graduated from the University of Warwick in 2021 with a BA (Hons) in Philosophy, Politics, and Economics which included an intercalated year studying Philosophy at the Erasmus University, Rotterdam.&lt;/p&gt;&lt;p&gt;Outside of the office, Solomon enjoys reading, visiting new art exhibitions, and playing football.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/yv2B6wyTLnGx24LDUYny8Z-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[MongoDB logo and branding pictured on a handheld tablet device by man sitting in coffee shop.]]></media:description>                                                            <media:text><![CDATA[MongoDB logo and branding pictured on a handheld tablet device by man sitting in coffee shop.]]></media:text>
                                <media:title type="plain"><![CDATA[MongoDB logo and branding pictured on a handheld tablet device by man sitting in coffee shop.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/yv2B6wyTLnGx24LDUYny8Z-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>A researcher has uncovered two related vulnerabilities in a popular <a href="https://www.itpro.com/software/development/356827/how-to-become-a-developer-a-beginners-guide">developer</a> library used to connect applications and MongoDB that could allow hackers to sneak into your database.</p><p>Mongoose is an object data modeling (ODM) library for MongoDB that connects it to the Node.js runtime environment, essentially simplifying interactions between applications and MongoDB <a href="https://www.itpro.com/tag/databases">databases</a></p><p>The flaws were discovered by Dat Phung, a member of OPSWAT’s fellowship program, who chose examining Mongoose due to its widespread use in <a href="https://www.itpro.com/software/development/358382/red-hat-launches-free-rhel-for-small-production-workloads">production environments</a>.</p><p><a href="https://www.itpro.com/security/24826/why-a-vulnerable-mac-is-not-necessarily-an-insecure-one">OPSWAT</a> explained the potential severity of the flaws in a blog, noting the number of businesses that use Mongoose for their <a href="https://www.itpro.com/databases/28899/mongodb-helps-developers-stitch-services-together">MongoDB</a> databases.</p><p>“Many businesses use Mongoose and MongoDB to build their apps. If hackers break in, they could cause serious functionality problems and, worse, put critical data at risk of theft, manipulation, or destruction.”</p><p>During his analysis, Phung discovered <a href="https://nvd.nist.gov/vuln/detail/CVE-2024-53900" target="_blank">CVE-2024-53900</a>, a <a href="https://www.itpro.com/security/32215/remote-code-execution-flaw-found-in-cisco-webex">remote code execution</a> (RCE) flaw that exploits Mongoose’s $where operator that enables JavaScript execution directory on the MongoDB server.</p><p>Phung warned that the flaw could be used by attackers to query the database to run <a href="https://www.itpro.com/security/hacking/358754/malicious-dependency-confusion-packages-are-stealing-password-files">malicious commands</a> on the Node.js application server, which thereafter could allow them to steal data or even take control of part of the application itself.</p><p>He submitted a security report disclosing the flaw to Snyk on 7 November and Mongoose released a new version of 8.8.3 which addressed the issue later that month.</p><p>But when Phung took a closer look at the patch he found a potential bypass that would still enable <a href="https://www.itpro.com/security/358041/microsoft-teams-wormable-rce-flaw">RCE</a> on the application server.</p><p>With the new flaw, <a href="https://nvd.nist.gov/vuln/detail/CVE-2025-23061" target="_blank">CVE-2025-23061</a>, Phung demonstrated that by nesting the $where operator inside an $or clause, he was able to bypass the new single-level checks introduced by Mongoose to mitigate CVE-2024-53900 and achieve RCE.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED WHITEPAPER</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="3cvMNbN3QogMsPACwHfYdc" name="Making cloud accessible and affordable for small businesses" caption="" alt="Making cloud accessible and affordable for small businesses" src="https://cdn.mos.cms.futurecdn.net/3cvMNbN3QogMsPACwHfYdc.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: ANS)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/cloud/cloud-computing/making-cloud-accessible-and-affordable-for-small-businesses"><em>Removing the barriers to growth</em></a></p></div></div><p>The proof-of-concept exploit developed by Phung showed that CVE-2025-23061, which was assigned a 9.0 severity rating under the <a href="https://www.itpro.com/hardware/361437/mitre-reveals-10-worst-hardware-security-weaknesses-in-2021">MITRE framework</a>, could be triggered in Mongoose versions prior to 8.9.5 (later than 8.8.3) and disclosed the new vulnerability via Tidelift. </p><p>OPSWAT warned that these vulnerabilities could be exploited by attackers to embed malicious code inside the organization's MongoDB database, as well as steal or corrupt data stored in MongoDB.</p><p>It advised businesses to update their instances of Mongoose immediately to the latest version immediately.</p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/software/open-source/open-source-vulnerabilities-dominated-2023-and-this-year-looks-no-different">Open source vulnerabilities dominated 2023, and this year looks no different</a></li><li><a href="https://www.itpro.com/security/open-source-malware-surged-by-156-percent-in-2024">Open source malware surged by 156% in 2024</a></li><li><a href="https://www.itpro.com/security/cyber-crime/the-zservers-takedown-is-another-big-win-for-law-enforcement">The Zservers takedown is another big win for law enforcement</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Want a return on your AI investment? Open source could be the key to success ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/software/open-source/open-source-AI-return-on-investment</link>
                                                                            <description>
                            <![CDATA[ Organizations using open source AI tools are more likely to report a return on investment ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">8j7sMd7qLNQMDU3FR6jesb</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/rRhHjEWyHMzoLBHV9Q5zu8-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 09 Jan 2025 13:37:22 +0000</pubDate>                                                                                                                                <updated>Tue, 14 Jan 2025 12:27:58 +0000</updated>
                                                                                                                                            <category><![CDATA[Open Source]]></category>
                                                    <category><![CDATA[Software]]></category>
                                                                                                                    <dc:creator><![CDATA[ Nicole Kobie ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/8Y8JDDTQ7XDEk49FoAFP2S.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Nicole Kobie first started writing for ITPro in 2007. As a freelance journalist covering technology and business, Nicole&#039;s work includes  bylines in New Scientist, Wired, PC Pro and many more. &lt;/p&gt;&lt;p&gt;Nicole the author of a book about the history of technology, The Long History of the Future.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/rRhHjEWyHMzoLBHV9Q5zu8-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Open source AI concept image showing digitized human brain contained within a lightbulb, placed on top of a circuit board with binary code in background.]]></media:description>                                                            <media:text><![CDATA[Open source AI concept image showing digitized human brain contained within a lightbulb, placed on top of a circuit board with binary code in background.]]></media:text>
                                <media:title type="plain"><![CDATA[Open source AI concept image showing digitized human brain contained within a lightbulb, placed on top of a circuit board with binary code in background.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/rRhHjEWyHMzoLBHV9Q5zu8-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Almost half of companies have seen a <a href="https://www.itpro.com/technology/artificial-intelligence/ai-is-causing-headaches-in-the-boardroom-as-cfos-and-cios-struggle-for-clarity-on-roi"><u>return on investment (ROI) on their AI strategy</u></a>, according to new research, and those using open source tools are more likely to see a positive result. </p><p>In a recent <a href="https://newsroom.ibm.com/image/IBM_ROI_of_AI_Report-December_2024.pdf"><u>survey from IBM and Morning Consult</u></a>, the vast majority (89%) said their organization plans to increase or maintain their AI investments in 2025, a vote of confidence in the technology despite growing complaints about the costs and utility of AI. </p><p>Indeed, the report found that only 5% of respondents intended to reduce spending on AI, and none planned to make cuts of more than 50%. </p><p>Instead, some companies plan to refocus their AI efforts, choosing to focus on IT operations, data quality management, and then product or services innovation, the report found. </p><p>Half of respondents said their strategic changes included shifting to managed cloud, hiring AI-skilled specialist talent, and ramping up the use of open source tools. </p><p>"Companies now recognize the value of defining specific use cases and optimizing AI projects," said Maribel Lopez of Lopez Research, which developed the study. </p><p>"They are leveraging hybrid cloud strategies and open source to drive AI innovation and deliver financial returns.”</p><h2 id="the-appeal-of-open-source-ai-is-growing">The appeal of open source AI is growing</h2><p>The study found nearly half (47%) of respondents reported ROI on their AI investments to date, which was more likely for those using open source tools. </p><p>Of those surveyed, 51% of open source users reported positive ROI versus 41% using proprietary systems. </p><p>No wonder then that two-in-five respondents not yet embracing open source plan to turn to it for AI projects this year. </p><p>But even those already making use of open source ecosystems plan to expand their use of AI, with 38% saying they plan to launch 21 or more  pilots this year versus 26% for companies using proprietary AI tooling, the report said. </p><div  class="fancy-box"><div class="fancy_box-title">RELATED WHITEPAPER</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="ua6RFTRFq9gPVy2x7bmwaK" name="Put AI to work for IT operations" caption="" alt="Put AI to work for IT operations" src="https://cdn.mos.cms.futurecdn.net/ua6RFTRFq9gPVy2x7bmwaK.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: IBM)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/technology/artificial-intelligence/put-ai-to-work-for-it-operations"><em>Boost your IT operations with genAI</em></a></p></div></div><p><a href="https://www.itpro.com/software/28109/what-is-open-source">Open source</a> is already heavily used by organizations when it comes to <a href="https://www.itpro.com/strategy/28181/what-is-ai">AI</a>, the research suggests. Six-in-ten respondents said they turn to open source ecosystems as an AI tool source, for example. </p><p>The study also predicted a slight rise in the use of open source AI solutions in the coming year. </p><p>More than 80% of those surveyed said at least a quarter of AI solutions or platforms are based on open source systems, and that's particularly true for the largest companies, with half of their AI solutions likely to be open source. </p><h2 id="not-all-about-roi">Not all about ROI</h2><p>The report suggests that ROI isn't the only metric for progress with regard to AI adoption and deployment.</p><p>Companies are also considering how AI speeds up software development and innovation, with those metrics ranked as most important by 25% and 23% of respondents, followed by productivity at 22%. Direct financial benefits were ranked fourth, at 15%. </p><p>"As organizations begin to implement AI at scale, many are placing greater stock in success metrics such as productivity gains, in part because traditional hard dollar <a href="https://www.itpro.com/business/leadership/poor-roi-is-no-deterrent-for-ai-obsessed-cios">ROI</a> benefits have yet to show up on the balance sheets,” said Lopez. </p><p>"Yet, companies continue to rapidly advance their AI strategies, with no sign of slowing down."</p><p>That said, while a third of companies said their AI investments are driven by innovation, 28% said <a href="https://www.itpro.com/technology/artificial-intelligence/cio-frustration-grows-as-firms-prioritize-ai-investment-over-digital-transformation-projects">AI investment</a> targeted boosted revenue — and 41% said they desired both. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ The open source industry is booming as firms invest billions in ecosystem each year ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/software/open-source/the-open-source-industry-is-booming-as-firms-invest-billions-in-ecosystem-each-year</link>
                                                                            <description>
                            <![CDATA[ Four-in-ten firms contribute open source code on a daily basis ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">8mdvZwrvDwJFXoQgYq26Cb</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/m8LD3ENwxn3C9qP6jjPzb3-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 03 Jan 2025 11:24:52 +0000</pubDate>                                                                                                                                <updated>Mon, 06 Jan 2025 17:12:11 +0000</updated>
                                                                                                                                            <category><![CDATA[Open Source]]></category>
                                                    <category><![CDATA[Software]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/m8LD3ENwxn3C9qP6jjPzb3-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Software developer using AI coding tools on a desktop computer in an open plan office space.]]></media:description>                                                            <media:text><![CDATA[Software developer using AI coding tools on a desktop computer in an open plan office space.]]></media:text>
                                <media:title type="plain"><![CDATA[Software developer using AI coding tools on a desktop computer in an open plan office space.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/m8LD3ENwxn3C9qP6jjPzb3-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The <a href="https://www.itpro.com/software/28109/what-is-open-source">open source</a> software industry is booming, according to recent analysis, with organizations now investing around $7.7 billion in the ecosystem each year. </p><p>Researchers from <a href="https://www.itpro.com/open-source/31833/what-is-github">GitHub</a>, the <a href="https://www.itpro.com/software/open-source/linux-foundation-unveils-redis-alternative-valkey-with-backing-from-aws-google-cloud-and-oracle">Linux Foundation</a>, and the Laboratory for Innovation Science at Harvard (LISH) found the median investment in open source now stands at $520,600 on a business-by-business basis. </p><p>This isn't all direct funding, however, with only 14% of this coming from direct financial contributions. Instead, the study showed 86% of investment comes in the form of labor contributions by employees and contractors working for organizations. </p><p>In fact, more than half of direct funding went to contractors, with 17% for specific projects and 16% to foundations. Communities and maintainers accounted for 4% each, and bounty platforms 1%. </p><p>Beyond code contributions, funding was most likely to be through donations, at 21%, foundation membership at 17%, or event sponsorship at 14%.</p><p>In a <a href="https://www.linuxfoundation.org/blog/understanding-the-state-of-open-source-funding-in-2024" target="_blank"><u>blog post</u></a> via the Linux Foundation in December, authors Hilary Carter and Martin Woodward said identifying funding sources within the <a href="https://www.itpro.com/security/the-open-source-community-relies-on-a-loyal-army-of-committed-developers-but-their-security-practices-are-putting-the-whole-ecosystem-at-risk">open source community</a> was challenging. </p><p>This has been a long-running issue, they noted, with investment remaining an “opaque subject with limited visibility”.</p><p>"Organizations have blind spots when it comes to the specifics of their contributions. Many respondents knew where they contribute, but only a portion of those could answer how many labor hours went into their OSS contributions or the percentage of budget that went to OSS," they said. </p><p>"Second, the decentralized nature of organizational contributions, without explicit policies or centralized groups that encourage and organize this effort, make reporting even more challenging."</p><p>Organizations have varying levels of open source experience, the researchers found, with nearly 44% either having or wanting to create an open source program office. Only 21% contribute to projects, 18% release projects, and 16% influence projects via leadership or maintainer roles. </p><p>Four-in-ten firms contribute open source code daily and six-in-ten at least weekly. There doesn't appear to be any strong correlation between company size and frequency of code contribution, the study noted. </p><div  class="fancy-box"><div class="fancy_box-title">RELATED WHITEPAPER</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="DxfdkcSG88yomGNA3SoVTK" name="Looking to Streamline IT Transformation? Here's How." caption="" alt="Looking to Streamline IT Transformation? Here's How." src="https://cdn.mos.cms.futurecdn.net/DxfdkcSG88yomGNA3SoVTK.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Dell)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/infrastructure/looking-to-streamline-it-transformation-here-s-how"><em>Improve data security across the enterprise</em></a></p></div></div><p>"Very seldom do we contribute. We are a non-profit. If we were better funded we would allocate more resources to contribute back to the community but we already serve an underrepresented community," said one respondent.</p><p>Organizations are most likely to contribute in the form of bug reports (19%), features (19%), general maintenance (18%), and documentation (16%), with governance accounting for 7%, cybersecurity audits for 6%, and legal advice for just 3%.</p><p>Four-in-ten contributors are developers or software engineers with 17% being community or developer advocates and 11% in IT, sysadmin or DevOps roles. For most of these, open source is just part of their job.</p><p>Respondents were keen to access long-term open source funding streams for all aspects of project development - and said they weren't always getting it.</p><p>"We have created several popular and useful open source tools over the years. It is always a struggle to find funding for basic maintenance for these projects," said one. </p><p>"Funding sources like to pay for new features but not closing issues and basic maintenance. It would be good if the Linux Foundation had funding streams for this type of work for projects."</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ AI 'slop security reports' are driving open source maintainers mad ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/software/open-source/ai-slop-security-reports-are-driving-open-source-maintainers-mad</link>
                                                                            <description>
                            <![CDATA[ Low-quality, LLM-generated reports should be treated as if they are malicious, according to one expert ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">3t4KXC2tGxQAQgXbeX8yES</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/JevpqxDB83LXATDRFYDhUB-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 24 Dec 2024 11:02:17 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Open Source]]></category>
                                                    <category><![CDATA[Software]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/JevpqxDB83LXATDRFYDhUB-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Software developer looking stressed at desk in a dark room with monitor light illuminating face.]]></media:description>                                                            <media:text><![CDATA[Software developer looking stressed at desk in a dark room with monitor light illuminating face.]]></media:text>
                                <media:title type="plain"><![CDATA[Software developer looking stressed at desk in a dark room with monitor light illuminating face.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/JevpqxDB83LXATDRFYDhUB-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p><a href="https://www.itpro.com/software/28109/what-is-open-source">Open source</a> project maintainers are drowning in a sea of AI-generated 'slop security reports', according to security report triage worker Seth Larson.</p><p>Larson said he’s witnessed an increase in poor-quality reports that are wasting maintainers' time and contributing to burnout.</p><p>"Recently I've noticed an uptick in extremely low-quality, spammy, and LLM-hallucinated security reports to open source projects. The issue is in the age of <a href="https://www.itpro.com/technology/artificial-intelligence/generative-ai-vs-large-language-models">LLMs</a>, these reports appear at first-glance to be potentially legitimate and thus require time to refute," he wrote in a <a href="https://sethmlarson.dev/slop-security-reports"><u>blog post</u></a>.</p><p>"This issue is tough to tackle because it's distributed across thousands of open source projects, and due to the security-sensitive nature of reports open source maintainers are discouraged from sharing their experiences or asking for help."</p><p>Larson wants to see platforms adding systems to prevent automated or abusive creation of security reports, and allow them to be made public without publishing a vulnerability record - essentially letting maintainers name-and-shame offenders.</p><p>They should remove the public attribution of reporters that abuse the system, take away any positive incentive to reporting security issues, and limit the ability of newly registered users to report security issues.</p><p>Meanwhile, Larson called on reporters to stop using LLM systems for detecting vulnerabilities, and to only submit reports that have been reviewed by a human being. Don't spam projects, he said, and show up with patches, not just reports.</p><p>As for maintainers, he said low-quality reports should be treated as if they are malicious.</p><p>"Put the same amount of effort into responding as the reporter put into submitting a sloppy report: ie, near zero," he suggested. </p><p>"If you receive a report that you suspect is AI or LLM generated, reply with a short response and close the report: 'I suspect this report is AI-generated/incorrect/spam. Please respond with more justification for this report'."</p><p>Larson isn't the only maintainer to raise the issue of low-quality AI-generated security reports.</p><p>Earlier this month, Daniel Stenberg <a href="https://daniel.haxx.se/blog/2024/01/02/the-i-in-llm-stands-for-intelligence/" target="_blank"><u>complained</u></a> that, while the Curl project had always received a certain number of poor reports, AI was now making them look more plausible - and thus taking more time to check out.</p><p>"When reports are made to look better and to appear to have a point, it takes a longer time for us to research and eventually discard it. Every security report has to have a human spend time to look at it and assess what it means," he said.</p><p>"The better the crap, the longer time and the more energy we have to spend on the report until we close it. A crap report does not help the project at all. It instead takes away developer time and energy from something productive."</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Open source malware surged by 156% in 2024 ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/open-source-malware-surged-by-156-percent-in-2024</link>
                                                                            <description>
                            <![CDATA[ Hackers are taking advantage of lax verification and surging demand to distribute and scale malware in record time ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">Pxw3S5fvo9zuN4rU6Htq8i</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/qG3459Gnf43CVyu33sP7si-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 11 Dec 2024 13:48:09 +0000</pubDate>                                                                                                                                <updated>Thu, 12 Dec 2024 11:15:28 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ solomon.klappholz@futurenet.com (Solomon Klappholz) ]]></author>                    <dc:creator><![CDATA[ Solomon Klappholz ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/pjZQRW2qWqQNjxubC6SUQ5.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Solomon Klappholz is a former Staff Writer at ITPro and ChannelPro. He has experience writing about the technologies that facilitate industrial manufacturing which led to him developing a particular interest in IT regulation, industrial infrastructure applications, and machine learning.&lt;/p&gt;&lt;p&gt;Before he joined ITPro, Solomon graduated from the University of Warwick in 2021 with a BA (Hons) in Philosophy, Politics, and Economics which included an intercalated year studying Philosophy at the Erasmus University, Rotterdam.&lt;/p&gt;&lt;p&gt;Outside of the office, Solomon enjoys reading, visiting new art exhibitions, and playing football.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/qG3459Gnf43CVyu33sP7si-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Malware Detected Warning Screen with abstract binary code 3d digital concept]]></media:description>                                                            <media:text><![CDATA[Malware Detected Warning Screen with abstract binary code 3d digital concept]]></media:text>
                                <media:title type="plain"><![CDATA[Malware Detected Warning Screen with abstract binary code 3d digital concept]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/qG3459Gnf43CVyu33sP7si-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The growth of open source <a href="https://www.itpro.com/malware/28076/what-is-malware">malware</a> has continued apace in 2024, according to new <a href="https://www.sonatype.com/resources/whitepapers/2024-open-source-malware-threat-report" target="_blank">research</a>, with cyber criminals taking advantage of the proliferation of open source software.</p><p>A report from software <a href="https://www.itpro.com/strategy/28710/what-is-the-supply-chain-1">supply chain management</a> firm Sonatype found there was a 156% increase in malicious packages identified on open source repositories over the past year.</p><p><a href="https://www.itpro.com/channel/370378/sonatype-expands-partner-benefits-with-new-partner-acceleration-program">Sonatype</a> has identified 778,529 malicious open source packages since it began tracking them in 2019, which it noted was an increase of 70,000 since its annual report was published in October.</p><p><a href="https://www.itpro.com/software/28109/what-is-open-source">Open source</a> malware are malicious packages that disguise themselves as legitimate open source software (OSS) to infiltrate software supply chains.</p><p>The three distinct characteristics of open source malware listed in the report were their intentional insertion into <a href="https://www.itpro.com/development/open-source/369920/350000-open-source-projects-vulnerable-15-year-old-python-bug">open source repositories</a> for malicious purposes, their specific targeting of developers, and ability to evade conventional detection methods.</p><p>Sonatype said this approach is able to circumvent <a href="https://www.itpro.com/security/endpoint-security/356810/bios-security-the-next-frontier-for-endpoint-protection">traditional security measures</a> and poses a unique threat to enterprises.</p><p>“This unique distribution method — compromised open source repositories — exploits gaps in <a href="https://www.itpro.com/software/development/red-hat-adds-trio-of-new-tools-to-its-trusted-software-supply-chain">dependency management tooling</a> and development build pipelines, bypassing conventional security mechanisms in order to attack software developers directly,” the report warned.</p><h2 id="npm-accounts-for-over-98-of-malicious-open-source-packages">Npm accounts for over 98% of malicious open source packages</h2><p>Sonatype noted that software repositories like npm and <a href="https://www.itpro.com/security/cyber-attacks/pypi-attack-targeting-of-repository-shows-no-sign-of-stopping">PyPI</a> process trillions of open source package requests each year, featuring a publishing model that is designed to ensure speed of delivery with the aim of helping foster agile development and innovation.</p><p>The unintended consequence of this model is that it makes it far easier for hackers to smuggle their malicious packages onto the platforms unnoticed. </p><p>For example, the report noted that npm, the world’s largest <a href="https://www.itpro.com/development/30202/what-is-javascript-and-why-should-i-learn-it">JavaScript</a> package registry, was disproportionately impacted by the plague of malicious packages.</p><p>Overall, npm accounted for 98.5% of the malicious packages identified by Sonatype over the course of 2024; whereas PyPI, the official package repository for <a href="https://www.itpro.com/software/development/368919/programming-with-python-time-to-upgrade-to-fancy-ansi">Python</a>, represented just 1% of open source malware Sonatype detected.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED WHITEPAPER</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="tvawFkCaNr5vdotoTDCE6Z" name="The life sciences guide to AI-driven innovations.jpg" caption="" alt="The life sciences guide to AI-driven innovations" src="https://cdn.mos.cms.futurecdn.net/tvawFkCaNr5vdotoTDCE6Z.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: AWS)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/infrastructure/the-life-sciences-guide-to-ai-driven-innovations"><em>Why 9 out of the top 10 pharma companies choose AWS</em></a></p></div></div><p>In total, Sonatype found over 540,000 malicious components hosted on npm, dwarfing the roughly 5,000 <a href="https://www.itpro.com/security/three-million-docker-hub-repositories-are-being-used-to-spread-malware">malicious assets</a> identified on PyPI.</p><p>Sonatype said the ease of publishing on <a href="https://www.itpro.com/development/programming-languages/355022/microsoft-plans-to-integrate-npm-with-github-following">npm</a>, which allows devs to publish packages with minimal verification, means they can “upload malicious components quickly and at scale”.</p><p>The report added that npm has been a victim of surges of <a href="https://www.itpro.com/security/phishing/368899/pypi-packages-succumb-to-mailchimp-phishing-scam">spam packages</a> in recent years. </p><p>A significant proportion of this spam looks to simply <a href="https://www.itpro.com/technology/monetization-strategies-for-digital-content-creators">monetize</a> a high volume of downloads using protocols like Tea.xyz, whereas others are seeking to <a href="https://www.itpro.com/security/hackers-have-found-yet-another-way-to-trick-devs-into-downloading-malware-from-github">embed malware</a> into projects for more nefarious purposes.</p><p>Finally, the sheer scale of demand on the npm platform, which will have received an expected 4.5 trillion requests in 2024 – up 70% compared to 2023 – makes it an ideal target for threat actors looking to maximize their impact.</p><p>Speaking to <em>ITPro, </em>Steve Sandford, partner and head of digital forensics & incident response at CyXcel, outlined why npm is drawing the attention of cyber criminals over other popular open source repositories, and what businesses should be doing to mitigate the threat.</p><p>“The rise of open source malware is a growing concern as open source software becomes more integral to <a href="https://www.itpro.com/644149/gartner-enterprise-it-spending-to-show-scant-growth-in-2013">enterprise IT</a>. NPM is a popular target due to its dominance and high download volume, with minimal verification processes allowing malicious actors to introduce compromised packages easily,” he explained.</p><p>“In contrast, PyPI has a smaller user base. As technology evolves and uses increase, the threat of malware will likely grow. To mitigate these threats, enterprises should implement automated scanning tools, maintain an updated inventory of open source components, ensure regular updates and patching, conduct <a href="https://www.itpro.com/business-operations/managed-service-provider-msp/359166/the-definitive-guide-to-it-security">security assessments</a>, train employees, and develop an <a href="https://www.itpro.com/security/building-an-incident-response-strategy">incident response plan</a>.”</p><h2 id="over-15-billion-unvetted-shadow-downloads-in-2024">Over 15 billion unvetted shadow downloads in 2024</h2><p>But the report added that it discovered a large number of <a href="https://www.itpro.com/security/hackers-are-taking-advantage-of-ai-hallucinations-to-sneak-malicious-software-packages-onto-enterprise-repositories">malicious packages</a> that were bypassing repository managers altogether, and were being directly downloaded onto dev machines or shared build infrastructures.</p><p>Referred to as shadow downloads, Sonatype defines this trend as open source components taken  from a public repository but bypassing the artifact <a href="https://www.itpro.com/security/a-leaked-github-access-token-could-have-led-to-a-catastrophic-supply-chain-attack">repository manager</a>.</p><p>“This practice introduces unvetted and unobservable dependencies into projects, bypassing established <a href="https://www.itpro.com/security/data-governance-for-data-driven-organizations">governance</a>, review, and security processes," Sonatype explained</p><p>“While precise numbers vary by organization, recent insights indicate a surprising percentage in production environments originated from shadow downloads, escaping security review entirely.”</p><p>Sonatype warned that shadow downloads, which saw a 15.6 billion increase in downloads between December 2023 and November 2024, undermine <a href="https://www.itpro.com/software/software-supply-chain-attacks-are-rife-this-is-what-developers-need-to-watch-out-for">software supply chain vulnerabilities</a> in several ways.</p><p>Firstly the lack of visibility of shadow downloads means they often go unnoticed, making it far more difficult to <a href="https://www.itpro.com/software/34583/avast-business-patch-management-review-don-t-give-up-the-day-job-just-yet">manage updates</a>. </p><p>Secondly, they expose systems to unvetted components, increasing the likelihood of introducing malicious packages, such as those associated with dependency confusion or typosquatting, Sonatype added.</p><p>Finally, bypassing repository managers means organizations no longer have the ability to enforce policies, such as release integrity checks or <a href="https://www.itpro.com/security/penetration-testing/357806/how-cyber-attack-simulations-differ-from-penetration-tests-and">vulnerability scans</a>, on the components.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ The open source community relies on a loyal army of committed developers – but their security practices are putting the whole ecosystem at risk ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/the-open-source-community-relies-on-a-loyal-army-of-committed-developers-but-their-security-practices-are-putting-the-whole-ecosystem-at-risk</link>
                                                                            <description>
                            <![CDATA[ The security of individual developer accounts poses a serious threat to open source ecosystem,  according to a new report from the Linux Foundation ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">ypN9kRgtzEegdeKYgPstc</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/D6VBHPEccR7fu3ohsXvnKA-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 04 Dec 2024 14:00:00 +0000</pubDate>                                                                                                                                <updated>Wed, 04 Dec 2024 16:08:58 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ solomon.klappholz@futurenet.com (Solomon Klappholz) ]]></author>                    <dc:creator><![CDATA[ Solomon Klappholz ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/pjZQRW2qWqQNjxubC6SUQ5.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Solomon Klappholz is a former Staff Writer at ITPro and ChannelPro. He has experience writing about the technologies that facilitate industrial manufacturing which led to him developing a particular interest in IT regulation, industrial infrastructure applications, and machine learning.&lt;/p&gt;&lt;p&gt;Before he joined ITPro, Solomon graduated from the University of Warwick in 2021 with a BA (Hons) in Philosophy, Politics, and Economics which included an intercalated year studying Philosophy at the Erasmus University, Rotterdam.&lt;/p&gt;&lt;p&gt;Outside of the office, Solomon enjoys reading, visiting new art exhibitions, and playing football.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/D6VBHPEccR7fu3ohsXvnKA-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Confident young woman using computer against dark background]]></media:description>                                                            <media:text><![CDATA[Confident young woman using computer against dark background]]></media:text>
                                <media:title type="plain"><![CDATA[Confident young woman using computer against dark background]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/D6VBHPEccR7fu3ohsXvnKA-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Insufficient security on individual developer accounts maintaining some of the most popular packages poses a significant threat to the <a href="https://www.itpro.com/software/28109/what-is-open-source">open source</a> community and beyond, according to a report from the <a href="https://www.itpro.com/software/open-source/linux-foundation-unveils-redis-alternative-valkey-with-backing-from-aws-google-cloud-and-oracle">Linux Foundation</a>.</p><p>The Linux Foundation Census is the third report of its kind looking into the widespread use of free and <a href="https://www.itpro.com/software/open-source/open-source-software-attacks-everything-you-need-to-look-out-for">open source software</a> (FOSS), aggregating data from over 12 million observations of FOSS libraries used in production applications at over 10,000 companies.</p><p>The report argued that FOSS has become a critical part of the modern economy, citing estimates that 96% of codebases include FOSS, and as a result the security of the <a href="https://www.itpro.com/open-source/26353/linux-foundation-the-internet-is-crumbling">developers maintaining these projects</a> needs to be reassessed.</p><p>A significant proportion of the top 500 packages identified in the investigation are hosted under individual developer accounts, according to the Linux Foundation.</p><p>The foundation warned that the implications of this fact may not be fully appreciated in the <a href="https://www.itpro.com/software/development/burnout-is-now-rife-across-the-software-community-with-almost-half-of-developers-turning-to-self-help-apps">software community</a>.</p><p>“The consequences of such heavy reliance upon individual developer accounts must not be discounted. For legal, bureaucratic, and security reasons, individual developers accounts have fewer protections associated with them than organizational accounts in a majority of cases.”</p><p>For example, the report noted many individual accounts fail to even have the most basic security protections, like <a href="https://www.itpro.com/security/cyber-security/369745/what-is-mfa-fatigue">multifactor authentication</a> (MFA), leaving them vulnerable to attack.</p><p>In addition, the granularity of <a href="https://www.itpro.com/cloud/370347/multi-cloud-over-permissioning-causing-cyber-risk-headaches-for-businesses">permissioning</a> and other publishing controls often found on organizational accounts are lacking on most accounts.</p><p>developer accounts are significantly easier to make. Further, a related issue could occur if the individual developer went on a long hiatus, or was hit by the proverbial bus, preventing updates to the code from occurring,” the report added.</p><h2 id="compromised-developer-accounts-pose-significant-threat">Compromised developer accounts pose “significant” threat </h2><p>The threat posed by lax security is not hypothetical, however, with the report warning that developer <a href="https://www.itpro.com/security/cyber-attacks/361074/account-takeovers-rise-nearly-threefold-during-pandemic">account takeovers</a> are increasing in frequency, both on platforms such as <a href="https://www.itpro.com/open-source/31833/what-is-github">GitHub</a> as well as in repositories including <a href="https://www.itpro.com/security/cyber-attacks/pypi-attack-targeting-of-repository-shows-no-sign-of-stopping">PyPI</a>.</p><p>One popular method used to infiltrate accounts detailed in the report is backdooring, where hackers insert <a href="https://www.itpro.com/malware/28076/what-is-malware">malicious code</a> into popular packages that give them an easy entry point once the package is installed on systems.</p><p>The report cited an example in 2019 an account of a <a href="https://www.itpro.com/hacking/19903/ruby-rails-security-hole-still-being-exploited-hackers">Ruby</a> developer was compromised and used to insert backdoors in eleven packages. </p><p>The Linux Foundation noted that while account takeovers remain a significant risk to software security, there are other less obvious issues concerning individual developers <a href="https://www.itpro.com/development/open-source/370035/open-source-leaders-call-for-permanent-government-funding-package">maintaining packages</a> that are widely depended upon.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED WHITEPAPER</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="qwMMd9uXVQSi64kNizDQhB" name="ai-technology-microchip-background-digital-transformation-concept.png" caption="" alt="Digital strategies in the era of AI" src="https://cdn.mos.cms.futurecdn.net/qwMMd9uXVQSi64kNizDQhB.png" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: HPE Intel )</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/technology/artificial-intelligence/digital-strategies-in-the-era-of-ai"><em>Unlock endless opportunities and ground breaking advances</em></a></p></div></div><p>For example, developers that decide to remove or ‘delete’ their projects can cause serious disruption, such as in the case of the ‘left-pad’ package, which left the internet ‘broken’ for several hours after being removed in 2015.</p><p>The disgruntled developer responsible for the package removed their code in protest, which broke hundreds of downstream packages that depended on the “seemingly minor piece of code”.</p><p>The report also referred to the more recent case of <a href="https://www.itpro.com/software/open-source/we-got-lucky-what-the-xz-utils-backdoor-says-about-the-strength-and-insecurities-of-open-source">XZ Utils</a>, which it described as an even more serious problem, where a developer intentionally subeverts the software they maintain</p><p>In February 2024, a <a href="https://www.itpro.com/security/29486/malicious-wordpress-plugin-installed-backdoor-on-thousands-of-websites">malicious backdoor</a> was introduced into the popular data compression library, used across a number of major Linux distributions that put potentially millions of systems at risk.</p><p>The threat actor responsible for the attack, known as Jia Tan, conducted a years-long social engineering campaign to gain the trust of the utility’s original author Lasse Colin using fake GitHub accounts to flood him with requests and pressure him into making Tan a co-maintainer of the project..</p><p>It was only due to the keen eye of a <a href="https://www.itpro.com/software/microsoft">Microsoft</a> developer Andres Freund, who spotted the backdoor and reported it to the Openwall Project’s security mailing list, bringing the issue to the attention of a number of major software vendors and preventing the <a href="https://www.itpro.com/security/fears-over-copycat-xz-style-attacks-mount-as-open-source-devs-targeted-with-suspicious-emails">incident from spiralling out of control</a>.</p><p>The report concluded that in the context of both security and general risk management, it is critical that developer accounts are better understood and strongly protected.</p><p>Moving towards this goal, the Linux Foundation encouraged the use of MFA tokens and also suggested that some individual accounts hosting critical projects should be transitioned to organizational accounts with added layers of security.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ "Markets do not stand still": The UK needs to up its game to fend off open source competition ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/software/open-source/markets-do-not-stand-still-the-uk-needs-to-up-its-game-to-fend-off-open-source-competition</link>
                                                                            <description>
                            <![CDATA[ Investment in the open source ecosystem needs to increase alongside broader government support ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">Uc7oM7rAt5Sx79X9EQ7qbj</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/JvFEHz3W8DCoZC4MakWaVo-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 12 Nov 2024 10:00:00 +0000</pubDate>                                                                                                                                <updated>Tue, 12 Nov 2024 15:01:48 +0000</updated>
                                                                                                                                            <category><![CDATA[Open Source]]></category>
                                                    <category><![CDATA[Software]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/JvFEHz3W8DCoZC4MakWaVo-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[UK map concept art showing digitized UK landmass outline in blue.]]></media:description>                                                            <media:text><![CDATA[UK map concept art showing digitized UK landmass outline in blue.]]></media:text>
                                <media:title type="plain"><![CDATA[UK map concept art showing digitized UK landmass outline in blue.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/JvFEHz3W8DCoZC4MakWaVo-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>While <a href="https://www.itpro.com/software/28109/what-is-open-source">open source</a> software has had a particularly strong impact in the UK, the country risks losing its prominent position in the global ecosystem, according to a new <a href="https://usw2.nyl.as/t1/223/5xhn3pdc2csvk4hdwev6kvsdl/0/87d0f0aa5065080f38148b7fcc9c83712c95ab7baa27743891557bbc57b44a1c" target="_blank"><u>report</u></a> from OpenUK.</p><p>Governments in France and Germany have expanded their investment and support for open source <a href="https://www.itpro.com/software/development/367842/the-four-major-software-development-lifecycle-models-and-how-they-work">software development</a> and contributions, meaning the growth of <a href="https://www.itpro.com/strategy/28181/what-is-ai">AI</a> projects and companies in France has pushed the UK down the list. </p><p>If the UK wants to keep up, it must not only continue supporting <a href="https://www.itpro.com/software/what-is-fair-source-the-new-software-licensing-structure">open source software</a> development, but also ensure that policies reflect a true understanding of open source software’s nuances in governance, community engagement, and market impact.</p><p>"The UK has contributed a huge amount to the technologies and infrastructure that underpin today’s economy. But markets do not stand still - other countries in Europe have increased their level of investment and incentives, putting the UK’s leadership position in jeopardy in future," said <a href="https://www.itpro.com/development/open-source/370035/open-source-leaders-call-for-permanent-government-funding-package">Amanda Brock, CEO at OpenUK</a>. </p><p>"In our report, we detail the considerations to be dealt with for the new UK government to support open source more effectively generating better returns on investment from any new projects, whether those are public sector organizations using open source or releasing new software as open source for others to use and importantly ensuring its adoption and maintenance."</p><p>This, Brock noted, is particularly important for <a href="https://www.itpro.com/business/public-sector/public-sector-ai-adoption-could-save-workers-millions-of-hours-in-admin-each-week">public sector AI</a> developments that aim to deliver on digital public good goals.</p><p>More generally, there needs to be a commitment from both public and private sectors to support open source foundational communities, invest in its infrastructure, and foster policies that embrace the open, collaborative nature of open source software. </p><p>It’s not all bad news for the ecosystem, however. The report from OpenUK specifically highlighted some good moves showcasing innovation and best practices in open source.</p><p>These include the UK AI Safety Institute’s Inspect Testing Platform, which supports AI safety testing and collaboration among researchers, with an open source model that encourages more widespread participation and reduced barriers to entry.</p><p>Standardizing healthcare records with OpenEHR using open source also reduces the fragmentation of healthcare data, OpenUK noted, helping improve global research collaboration and overcomes potential data siloes or lock-in.</p><p>The British Library has adopted an open source and open standard approach to make collections more accessible for researchers, it said, while BT Group and Canonical are using open source to modernize and innovate around 5G networks, based on the telco-grade distribution of OpenStack to deliver a software-defined network.</p><p>The challenges, according to the report, include opening up the market - particularly in the NHS, where large, closed contracts have tended to be awarded to a small number of providers.</p><h2 id="uk-open-source-needs-to-go-global">UK open source needs to go global</h2><p>An area of particular concern highlighted by OpenUK included international markets, where the UK ecosystem is failing to leverage its substantial skills. </p><p>Mike Bracken, founding partner of Public Digital noted that accepting supplier conditions “would make mafiosi blush”. </p><p>Meanwhile, public data sets - land registries, health data and geo-spatial data - are locked in siloes without common standards or reasonable  market access. </p><p>"As <a href="https://www.itpro.com/software/what-is-fair-source-the-new-software-licensing-structure">open source software</a> reshapes industries, it also presents challenges that require careful governance and regulatory understanding,” said Dr Jennifer Barth, research director at OpenUK and Founder of Symmetry. </p><div  class="fancy-box"><div class="fancy_box-title">RELATED WHITEPAPER</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="LjWdHEMBU3LCLK4bVET7Rg" name="Understanding Least Privileges.jpg" caption="" alt="Understanding Least Privileges" src="https://cdn.mos.cms.futurecdn.net/LjWdHEMBU3LCLK4bVET7Rg.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: CyberFox)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/reduce-cyber-risk-stay-in-business"><em>The guide to cyber insurance</em></a></p></div></div><p>“Unlike proprietary software, open source software operates through open licensing, decentralized contribution, and community-driven management, which can create complexity in legal and operational standards. </p><p>Looking ahead, Barth said driving successful open source software adoption will be “contingent on comprehending the interplay of governance, technology, and community”. </p><p>“For legislators and market participants alike, a nuanced understanding of open source software is essential, as this ecosystem relies on transparency, the protection of intellectual property, and an ethos of equitable use.”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ New definition of open source AI is “flawed”, experts say ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/software/open-source/new-definition-of-open-source-ai-is-flawed-experts-say</link>
                                                                            <description>
                            <![CDATA[ The terms compel open source AI projects to reveal information around training data – but there are a few key caveats ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">qEz6nwg35gBLWXz6uQnn3h</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/po9LCVDA2Zi2tAURPcUur8-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 08 Oct 2024 11:22:17 +0000</pubDate>                                                                                                                                <updated>Wed, 09 Oct 2024 13:49:32 +0000</updated>
                                                                                                                                            <category><![CDATA[Open Source]]></category>
                                                    <category><![CDATA[Software]]></category>
                                                                                                <author><![CDATA[ george.fitzmaurice@futurenet.com (George Fitzmaurice) ]]></author>                    <dc:creator><![CDATA[ George Fitzmaurice ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/N4xHCjSAXKcijjt3oiQtfc.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/po9LCVDA2Zi2tAURPcUur8-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Open source large language model concept art showing digital brain on a circuit board.]]></media:description>                                                            <media:text><![CDATA[Open source large language model concept art showing digital brain on a circuit board.]]></media:text>
                                <media:title type="plain"><![CDATA[Open source large language model concept art showing digital brain on a circuit board.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/po9LCVDA2Zi2tAURPcUur8-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>A new definition for ‘<a href="https://www.itpro.com/technology/artificial-intelligence/just-how-open-are-the-leading-open-source-ai-platforms">Open Source AI</a>’ has been <a href="https://opensource.org/blog/the-open-source-ai-definition-v-1-0-rc1-is-available-for-comments"><u>launched by the Open Source Initiative (OSI)</u></a>, though experts have told <em>ITPro </em>that the terms lack nuance and may be under the wrong management.</p><p>The new definition has <a href="https://www.itpro.com/strategy/28181/what-is-ai">AI</a> training data as its focus, clarifying that <a href="https://www.itpro.com/technology/artificial-intelligence/who-owns-the-data-used-to-train-ai">training data</a> must be shared and disclosed. It also states that code must be complete to the extent that recipients understand how the training was done.</p><p>“In my opinion, OSI continues with its flawed ‘one size fits all’ approach rather than helping to better define the ‘spectrum’ for open source and AI.” Peter Zaitsev, founder of Percona, told <em>ITPro</em>. </p><p>The OSI’s new definition considers four types when it comes to training data - open, public, obtainable, or unshareable. It noted that, while the legal requirements are different for each, all must be shared in a form allowed by law to adhere to the new terms.  </p><p>It highlights two key features, the first of which demands that the code used to train and process data in AI development must be complete to the extent that open source recipients understand how the training was done. </p><p>Training is where the innovation is taking place, the OSI said, so transparency around the code used in training is necessary to allow <a href="https://www.itpro.com/software/open-source">open source</a> users to study and modify AI systems. </p><p>Another feature of the definition acknowledges that requirements of ‘copyleft-like terms’ are admissible. This is where the training code and a dataset are bundled together in a legal sense. The OSI’s new definition is at the ‘release candidate’ stage, meaning no new features will be added going forward, only bug fixes. </p><h2 id="a-contentious-definition">A contentious definition </h2><p>Zaitsev takes issue with several terms in the definition, particularly the triaging of data types into obtainable and unshareable. <a href="https://opensource.org/blog/the-open-source-ai-definition-v-1-0-rc1-is-available-for-comments"><u>In a linked FAQ</u></a>, the OSI clarified that obtainable data can be revealed for a cost while unshareable data can only be revealed in the form of a detailed description. </p><p>“While it makes a lot of difference for actual users, if training data is not freely available for everyone, it is not the same as ‘open source’,” Zaitsev said. </p><p>"I think it would make sense for OSI to lead the effort to properly define the standard classification for these free-to-use models which, in my opinion, and in particular due to massive training costs, is where potential value for competition will be massive,” he added. </p><p>Amanda Brock, CEO of OpenUK, told <em>ITPro</em> that the issues here are even broader and that the problem is more deeply entrenched in the OSI’s position as an institution. </p><div  class="fancy-box"><div class="fancy_box-title">RELATED WHITEPAPER</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="XXjzkN96kJfYDq8jVEVFpL" name="BT AI Healthcare.png" caption="" alt="whitepaper from BT on AI Security" src="https://cdn.mos.cms.futurecdn.net/XXjzkN96kJfYDq8jVEVFpL.png" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: BT)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/technology/artificial-intelligence/where-will-ai-take-security-and-are-we-ready"><em>Optimize your security by adopting AI</em></a></p></div></div><p>“This is not only concern about the content of any definition, but whether there should be an 'open source AI definition,’ and, if there is one, whether the OSI is the right organization to create it and whether the broader open source software community support its changed role as the custodian of two definitions,” Brock said. </p><p>“The OSI’s stated purpose is around open source software - yes, advocating for open source principles is a part of that purpose, but it’s questionable whether managing a whole new definition in AI falls under that purpose,” she added.  </p><p>Brock’s thinking is that the OSI should maintain its focus on open source software, more than enough work for one small organization to manage, in her opinion. The OSI’s role as a guardian of the Open Source Definition (OSD) is critical, she added. </p><p>“The open source software community is being split and fractured by the new Open Source AI definition,” Brock said. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Redis insists license changes were the “only way to compete with Amazon and Google” — now it could face a user exodus ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/software/open-source/redis-insists-license-changes-were-the-only-way-to-compete-with-amazon-and-google-now-it-could-face-a-user-exodus</link>
                                                                            <description>
                            <![CDATA[ Redis sparked controversy when it announced licensing changes in March this year – but the company believes the move was warranted ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">4vCsHyS2wj9q7iMdfgyQkj</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/5cbsVxxfYtcKVNsoawsqah-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 25 Sep 2024 12:53:15 +0000</pubDate>                                                                                                                                <updated>Wed, 25 Sep 2024 16:34:04 +0000</updated>
                                                                                                                                            <category><![CDATA[Open Source]]></category>
                                                    <category><![CDATA[Software]]></category>
                                                                                                <author><![CDATA[ ross.kelly@futurenet.com (Ross Kelly) ]]></author>                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Ross Kelly is ITPro&#039;s News &amp;amp; Analysis Editor, with a keen interest in cyber security, business leadership and emerging technologies.&lt;/p&gt;
&lt;p&gt;He graduated from Edinburgh Napier University in 2016 with a BA (Hons) in Journalism, and joined ITPro in 2022 after four years working in technology conference research.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;In his spare time, Ross enjoys cycling, walking and is an avid reader of history and non-fiction.&lt;/p&gt;
&lt;p&gt;You can contact Ross at ross.kelly@futurenet.com or on &lt;a href=&quot;https://twitter.com/rosswritesetc&quot;&gt;Twitter&lt;/a&gt; and &lt;a href=&quot;https://www.linkedin.com/in/ross-kelly-18a54411a/&quot;&gt;LinkedIn&lt;/a&gt;.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/5cbsVxxfYtcKVNsoawsqah-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Big data storage platform concept image with files and programming code representing Redis data storage platform.]]></media:description>                                                            <media:text><![CDATA[Big data storage platform concept image with files and programming code representing Redis data storage platform.]]></media:text>
                                <media:title type="plain"><![CDATA[Big data storage platform concept image with files and programming code representing Redis data storage platform.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/5cbsVxxfYtcKVNsoawsqah-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Redis shocked the <a href="https://www.itpro.com/software/28109/what-is-open-source">open source</a> community when it unveiled a shift to a more restrictive licensing approach earlier this year, but a senior company figure has told <em>ITPro </em>it was the “only way to compete with Amazon and Google” and claw back commercial value. </p><p>CEO Rowan Trollope <a href="https://www.itpro.com/software/open-source/why-redis-license-changes-arent-the-end-of-the-world-for-open-source"><u>first announced the decision in March</u></a>, confirming that future Redis releases were to be made available under RSALv2 (Redis Source Available License) and SSPLv1 (Server Side Public License) licenses.</p><p>This dual licensing setup equates to a ‘source available’ approach and marked a departure from the company’s Berkeley Software Distribution (BSD) model, which enables developers to use source code even for commercial purposes</p><p>The in-memory data store provider justified its decision at the time, claiming that while it had sponsored “the bulk” of development, the majority of commercial sales were being “channeled through the largest cloud service providers”. </p><p>Trollope noted that these major players - which includes Amazon and Google - had more or less “commoditized Redis’ investments” and therefore the licensing approach was no longer delivering commercial value.</p><p>The company isn’t the first to have altered its licensing scheme, with MongoDB and HashiCorp also having announced changes over the years to the dismay of the open source community. </p><p>However, this particular decision sparked controversy among members of the ecosystem, some of whom described the move as a “bait and switch” tactic whereby vendors are “intentionally opaque about their long-term goals”. </p><p>In this instance, the sheer scale of the alleged commoditization by big tech players appears to have warranted drastic action at Redis. </p><p>In a statement given to <em>ITPro</em>, Redis’ chief marketing officer Keith Messick defended the move, noting it has since enabled the company to unlock significant commercial gains and to better compete with the aforementioned big tech providers. </p><p>“Redis, like many other companies, changed our license because it’s the only way to compete with Amazon and Google,” Messick told <em>ITPro</em>. </p><iframe allow="" height="200px" width="100%" data-lazy-priority="low" data-lazy-src="https://widget.spreaker.com/player?episode_id=59045718&theme=light&playlist=false&playlist-continuous=false&chapters-image=true&episode_image_position=right&hide-logo=true&hide-likes=true&hide-comments=true&hide-sharing=true&hide-download=true"></iframe><p>“Open source software is important, but traditional OSS licensing makes increasingly less sense in a world where Google and Amazon use their superior monopolistic advantages to make money off of it without giving much back,” he added. </p><p>“It’s not just startups dealing with this. Meta’s Llama license basically says ‘Hey, this is open source unless you’re Google, Amazon, etc’.”</p><p>Reinforcing Redis’ position, Messick revealed that last week a major US company discovered it had been using Redis for years, but had in fact been paying Google instead. </p><p>This could point to a severe imbalance within the broader marketplace, with industry heavyweights being given free rein to lap up financial gains off the back of developer toil.</p><p>“They can do things like that because they own the gears and levers of the market,” he added. “The license change was us clawing back one little piece of that.”</p><p>“Since we changed the license, we’ve had record revenue growth, but there’s a much more relevant question that I never see asked: what’s Amazon or Google’s revenue from reselling Redis or other open source software? That’s the only question that really matters in my opinion, and good luck getting them to answer.”</p><h2 id="redis-commercial-gains-could-be-scuppered-by-growing-user-exodus">Redis commercial gains could be scuppered by growing user exodus</h2><p>While Messick insisted the move has made Redis more competitive, recent research suggests the provider could be facing an exodus of users. </p><p>Research from Percona found 70% of respondents with Redis deployments are looking elsewhere, with a number of leading options already on their radars. </p><p>Among these are DragonflyDB, KeyDB, and Skytable, according to Percona. However, the study noted that the “most likely usurper” comes in the form of Valkey. </p><p><a href="https://www.itpro.com/software/open-source/linux-foundation-unveils-redis-alternative-valkey-with-backing-from-aws-google-cloud-and-oracle"><u>Unveiled by the Linux Foundation earlier this year</u></a>, the Valkey Project is a Redis fork developed specifically to provide Redis users with access to an open source alternative. </p><div  class="fancy-box"><div class="fancy_box-title">RELATED WHITEPAPER</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="8Vm695nuAZyomreNYWgKoL" name="Enhance End-to-End Data Security with Microsoft SQL Server, Dell™ PowerEdge™ Servers and Windows Server 2022 (1)" caption="" alt="Enhance End-to-End Data Security with Microsoft SQL Server, Dell™ PowerEdge™ Servers and Windows Server 2022" src="https://cdn.mos.cms.futurecdn.net/8Vm695nuAZyomreNYWgKoL.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Dell)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/infrastructure/case-study-optimized-performance-and-energy-efficiency-in-cosmology-using-amd-genoa-cpus"><em>Improve data security across the enterprise</em></a></p></div></div><p>Percona’s study found that three-quarters of surveyed users are either testing, considering, or have already adopted Valkey in the wake of the Redis shift. </p><p>Notably, the report found that organizations spanning a range of sizes have made the shift away from Redis in recent months. One “clear trend” emerged, however, especially concerning organizations with a broader data footprint. </p><p>“While companies of all sizes have embraced or are investigating a transition to Valkey, organizations with larger data footprints were significantly more likely than their smaller counterparts to have already begun the shift,” Percona said. </p><iframe allow="" height="200px" width="100%" data-lazy-priority="low" data-lazy-src="https://widget.spreaker.com/player?episode_id=53920802&theme=light&playlist=false&playlist-continuous=false&chapters-image=true&episode_image_position=right&hide-logo=false&hide-likes=true&hide-comments=true&hide-sharing=true&hide-download=true"></iframe><p>Around 83% of large enterprises have adopted – or are actively exploring – Valkey. </p><p>“Modestly sized” companies are following suit, with 70% of mid-market players making the shift and 77% of small businesses switching to Valkey, or considering the shift. </p><p>Cost, Percona found, has been a major contributing factor to whether or not organizations abandon Redis since the licensing changes, with many seeking cost-free options. </p><p>However, Interest in the Valkey project could also be due to what Percona described as its “impressive roster” of supporting organizations. When the Linux Foundation unveiled Valkey this year, a host of major industry players including Amazon Web Services (AWS), Google Cloud, Oracle, and Ericsson endorsed the project. </p><p>Percona’s study noted that awareness of Valkey has grown significantly since its launch, with nearly two-thirds (63%) of respondents revealing they have been aware of the project since its debut. </p><p>Jonathan Wright, Infrastructure Lead at AlmaLinux, which has made the switch to Valkey, told <em>ITPro </em>the transition has been both smooth and made sense given the restrictive nature of the licensing changes. </p><p>"Valkey continues the open source legacy of Redis prior to its license change,” Wright said. </p><p>“As both a user of Redis (now Valkey) within critical parts of our infrastructure and as an OS which ships it to others, the active development, OSI-approved license, and performance improvements made it a no-brainer for us."</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Elastic returns to open source, but can it regain the community’s trust? Some industry players aren’t holding their breath ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/software/open-source/elastic-returns-to-open-source-but-can-it-regain-the-communitys-trust-some-industry-players-arent-holding-their-breath</link>
                                                                            <description>
                            <![CDATA[ Elastic has announced the addition of the OSI-approved AGPL open source license for its Elasticsearch and Kibana products ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">mt9zdr72HBysno4jwv5XiS</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/3npp8FU6s3wANXTBF6TL6f-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 06 Sep 2024 12:09:50 +0000</pubDate>                                                                                                                                <updated>Fri, 06 Sep 2024 15:12:07 +0000</updated>
                                                                                                                                            <category><![CDATA[Open Source]]></category>
                                                    <category><![CDATA[Software]]></category>
                                                                                                <author><![CDATA[ solomon.klappholz@futurenet.com (Solomon Klappholz) ]]></author>                    <dc:creator><![CDATA[ Solomon Klappholz ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/pjZQRW2qWqQNjxubC6SUQ5.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Solomon Klappholz is a former Staff Writer at ITPro and ChannelPro. He has experience writing about the technologies that facilitate industrial manufacturing which led to him developing a particular interest in IT regulation, industrial infrastructure applications, and machine learning.&lt;/p&gt;&lt;p&gt;Before he joined ITPro, Solomon graduated from the University of Warwick in 2021 with a BA (Hons) in Philosophy, Politics, and Economics which included an intercalated year studying Philosophy at the Erasmus University, Rotterdam.&lt;/p&gt;&lt;p&gt;Outside of the office, Solomon enjoys reading, visiting new art exhibitions, and playing football.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/3npp8FU6s3wANXTBF6TL6f-1280-80.jpg">
                                                            <media:credit><![CDATA[Elastic]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Elastic logo and branding pictured on a white background.]]></media:description>                                                            <media:text><![CDATA[Elastic logo and branding pictured on a white background.]]></media:text>
                                <media:title type="plain"><![CDATA[Elastic logo and branding pictured on a white background.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/3npp8FU6s3wANXTBF6TL6f-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>AI search company Elastic has announced a return to its open source beginnings with the addition of a new license for its Elasticsearch and Kibana products.</p><p>Elastic has added the GNU affero general public license v3 (AGPL), an open source license approved by the Open Source Initiative (OSI).</p><p>AGPL will now be available as an option for users to license the free part of the Elasticsearch and Kibana source code that is available under the server side public license 1.0 (SSPL 1.0) and Elastic license 2.0 (EL v2).</p><p>The addition of AGPL will mean Elasticsearch and Kibana will be officially considered open source, allowing the Elastic community to use, modify, redistribute, and collaborate on Elastic’s source code.</p><p>“We’re delighted to reintroduce an OSI-approved open source license to Elasticsearch and Kibana. Elastic has always strongly believed in the ethos of open source and the clarity and transparency that it enables,” said Shay Banon, founder and CTO at Elastic.</p><p>Banon claimed adding AGPL will allow for more engagement and adoption from users, and boost the popularity of Elasticsearch as the runtime platform for retrieval augmented generation (RAG) and building generative AI applications.</p><p>Elastic stated that the introduction of AGPL as a license option will not impact existing users working with either SSPL or ELv2, and there will be no changes to Elastic’s binary distributions, nor for developers building applications using plugins on Elasticsearch or Kibana.</p><h2 id="why-elastic-s-decision-is-important">Why Elastic’s decision is important</h2><p>Speaking to <em>ITPro, </em>Amanda Brock, CEO at OpenUK, welcomed the announcement, noting a there have been a number of license changes away from open source in the previous month,</p><p>“Ending August, a month that has become associated with license changes away from open source, by welcoming Elastic back to the fold is great news. Shay Banon is a long term open source contributor, and Elastic’s move away from open source allegedly in response to strip mining really hurt the open source community,” she said.</p><p>“OpenUK and I am sure the entire open source community welcome Elastic’s inferred acknowledgement that SSPL is not an open source license and their return to a real open source license. It's pleasing to see this move in the right direction of travel, i.e. to open source.”</p><p>Brock expanded on why the open source community is invested in licenses actually meeting the true definition of open source. The lines are often blurred in this ecosystem, she noted, and so clarity and transparency is critical. </p><div  class="fancy-box"><div class="fancy_box-title">RELATED WHITEPAPER</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="UX5eKpSaWBCowTCo8nEtZm" name="Metrics That Matter ebook (1).jpg" caption="" alt="Metrics That Matter ebook" src="https://cdn.mos.cms.futurecdn.net/UX5eKpSaWBCowTCo8nEtZm.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Proofpoint)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/malware/metrics-that-matter"><em>Identify key areas that require new cybersecurity investment</em></a></p></div></div><p>“Why do we care so much about the license meeting the open source definition?  This isn't out of nerdiness or desire to control. Only an open source license meeting the Open Source Definition guarantees the free flow of code we rely on at the heart of open source. This enables use and relicensing of the code with confidence,” she explained. </p><p>“The friction of requiring commercial payment, patent licenses etc - which cannot happen with a true open source license – interrupts that free flow and jeopardizes the ability to use and reuse code in the free flow of true open source.”</p><p>The debate over what constitutes ‘true’ open source has once again come to the fore due to the generative AI trend, Brock noted. A host of major industry players have positioned themselves as ‘open source’ AI providers, yet there are still restrictions placed on the use of models at times. </p><p>“This issue is the same issue at the heart of the meaning of open source in AI today – whether there is a restriction that interrupts the free flow. In AI as with the SPPL and Elastic, the free flow has generally been to require payment for commercialisation at some level, which the OSD does not allow for.”</p><h2 id="can-elastic-regain-the-trust-of-the-open-source-community">Can Elastic regain the trust of the open source community</h2><p>Peter Zaitsev, founder of open source database software company Percona, told <em>ITPro </em>the move may be a reaction to the recent success of competing offering OpenSearch.</p><p>“So Elastic has [had] a change of heart and is now once again available under an Open Source License - this time AGPLv3. Could it be a response to OpenSearch success and proof that forking works, at least to influence vendor behavior ?”</p><p>Zaitsev was not convinced that Elastic’s switch back toward open source licensing will be enough to rebuild community trust, suggesting the firm could easily turn its back on open source developers in the near-term.</p><p>“I wonder though, if community trust can be repaired as quickly? Can we count on Elastic to stick to open source  this time, or is this license likely to be changed again in future to serve the need of the moment?” he speculated.</p><p>“The OpenSearch Permissive license – and what is even more important, the open governance model for the project – will continue to be a differentiator, though I think it will be even more important for the project to reassert independence from AWS.”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Open source AI just got a major seal of approval from US regulators — but will it push developers in the right direction? ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/software/open-source/open-source-ai-just-got-a-major-seal-of-approval-from-us-regulators-but-will-it-push-developers-in-the-right-direction</link>
                                                                            <description>
                            <![CDATA[ Regulators in the US appear very  keen on supporting open source AI developers ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">mruZ7ziq2LcjM9vTY9y4uV</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/VBqn2J5kcKMXXeboZJS47n-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 30 Jul 2024 20:00:00 +0000</pubDate>                                                                                                                                <updated>Thu, 01 Aug 2024 07:59:25 +0000</updated>
                                                                                                                                            <category><![CDATA[Open Source]]></category>
                                                    <category><![CDATA[Software]]></category>
                                                                                                                    <dc:creator><![CDATA[ Nicole Kobie ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/8Y8JDDTQ7XDEk49FoAFP2S.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Nicole Kobie first started writing for ITPro in 2007. As a freelance journalist covering technology and business, Nicole&#039;s work includes  bylines in New Scientist, Wired, PC Pro and many more. &lt;/p&gt;&lt;p&gt;Nicole the author of a book about the history of technology, The Long History of the Future.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/VBqn2J5kcKMXXeboZJS47n-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Open source AI concept image showing digitized brain hovering over a circuit board.]]></media:description>                                                            <media:text><![CDATA[Open source AI concept image showing digitized brain hovering over a circuit board.]]></media:text>
                                <media:title type="plain"><![CDATA[Open source AI concept image showing digitized brain hovering over a circuit board.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/VBqn2J5kcKMXXeboZJS47n-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p><a href="https://www.itpro.com/software/open-source/the-debate-over-open-source-ai-has-reached-boiling-point-this-new-osi-initiative-looks-to-set-the-record-straight">Open source AI</a> may dodge the worst of looming US regulation — and that could make it a popular alternative to the closed systems in development.</p><p>According to reports from the <a href="https://abcnews.go.com/Technology/wireStory/white-house-restrict-open-source-artificial-intelligence-now-112389863"><em>Associated Press</em></a>, published in <em>ABC News</em>, the US government is set to argue that open source AI systems are less of a risk than their closed counterparts, suggesting there&apos;s less need to restrict companies making open systems.</p><p>That&apos;s the result of President Joe Biden last year asking for the US Commerce Department to consider the merits of open models, which are not open source but have publicly available details such as the weights in the model. For example, Meta&apos;s <a href="https://www.itpro.com/software/open-source/i-find-it-a-pretty-big-turnoff-why-mark-zuckerberg-thinks-closed-source-ai-competitors-are-harming-the-industry">Mark Zuckerberg has argued for AI to be more open</a>, while OpenAI prefers to keep the workings of its systems locked down.</p><p>“A year ago, there was a strong narrative about risk and long-term concerns about AI systems being too powerful,” Alan Davidson, an assistant secretary of the U.S. Commerce Department, told <em>AP</em>.</p><p>"We continue to have concerns about AI safety, but this report reflects a more balanced view that shows that there are real benefits in the openness of these technologies."</p><h2 id="open-source-ai-vs-closed-source-ai">Open source AI vs closed source AI</h2><p>The US report highlights the debate between open and closed systems. Notably, proponents of the former not only believe transparency can help mitigate risks such as bias but also help spur innovation, versus closed-box systems that don&apos;t allow ideas to be shared or improved upon — but do keep key technologies from being used in dangerous ways by those outside the company.</p><p>Angus Allan, Senior Product Manager at CreateFuture, told ITPro that while the early days of the <a href="https://www.itpro.com/technology/artificial-intelligence-ai/369959/what-is-generative-ai">generative AI</a> ‘boom’ have been dominated by closed source, proprietary models, <a href="https://www.itpro.com/software/28109/what-is-open-source">open source</a> development is beginning to gain traction.</p><p>"Until recently, &apos;state of the art&apos; AI models have almost exclusively been the product of closed source models like <a href="https://www.itpro.com/technology/artificial-intelligence-ai/369965/what-is-chatgpt-and-what-does-it-mean-for-businesses">ChatGPT</a>, Gemini, and Claude," he said.</p><p>"Open source models have lagged behind their peers, meaning there has been no motivation to strictly regulate them."</p><p>That changed with Meta, which has taken a more open approach, he noted.</p><p>"Meta has been a trailblazer in advocating for open sourced AI model development, and their latest model, <a href="https://www.itpro.com/technology/artificial-intelligence/metas-llama-31-promises-to-compete-with-closed-source-competition">Llama 3.1</a>, is on-par with its closed source counterparts, even beating the original GPT-4 in many benchmarks.”</p><p>But Chris Black, AI evangelist at broadcast company Vizrt, told ITPro that there are risks to open models — and that means some regulation may be warranted.</p><p>"The impending <a href="https://www.itpro.com/technology/artificial-intelligence/eu-ai-act-everything-you-need-to-know-about-the-legislation-including-rules-requirements-and-who-will-be-forced-to-comply">EU AI Act</a> shows that reasonable safety guardrails can be put in place without hindering innovation, making exceptions for some open-sourced models that are developed with full transparency," Black said.</p><p>"With this in mind, the US placing little to no regulation on open source models poses a degree of risk… The free rein of <a href="https://www.itpro.com/technology/artificial-intelligence/three-open-source-large-language-models-you-can-use-today">open source AI models</a> could set a dangerous precedent of easy access to powerful technologies by bad actors."</p><p>Indeed, while transparency offered by open systems can mitigate some problems, it doesn&apos;t solve every danger raised by AI, said Ilia Kolochenko, CEO at ImmuniWeb.</p><p>"Technically speaking, while open-source AI – however we define it – may provide a higher degree of transparency compared to proprietary AI technologies, other risks including hallucinations and inaccuracies, capacity to cause harm, infringement of intellectual property, and privacy risks are not necessarily mitigated in any manner by the fact that AI is an open source AI," he said.</p><h2 id="should-businesses-favor-open-source-ai-too-xa0">Should businesses favor open source AI too? </h2><p>Dodging potential restrictive regulatory action could be one reason to look at using open source models in your business — but it&apos;s not the only factor to consider, according to Allan. </p><p>This latest seal of approval from US officials is likely “signaling to industry” that their preference is to spur open innovation. Crucially, Allan said, this could “tip the scale in terms of industry adoption of open source models”.</p><p>"For businesses, though, the focus shouldn&apos;t be on a difference in regulatory regime, the difference is on performance, safety, and cost,” he added. “And open source models are now competing strongly on these metrics."</p><p>Paul Henninger, head of connected technology for KPMG UK, argued that open systems can be more cost effective to begin with, but rise in cost when adapted to specific tasks. Henninger advised companies to consider how well any AI can be tailored to meet the businesses objectives.</p><p>“Open systems are the best way to maintain access to the latest research on AI problem solving because they benefit from the community’s collective knowledge and improvements," he added.</p><p>"The democratic nature of the technology means that long-term transformation depends on broad access to the tools. On the flip side, participating in the open system means sharing innovation and advancements with competitors."</p><h2 id="what-even-is-open-source-ai">What even is open source AI?</h2><p>Problematically, various government reports haven&apos;t defined what they mean by open source AI. While open source software has specific definitions and licenses, that&apos;s not the case for open AI, Kolochenko warned,</p><p>“First and foremost, one needs to give a crystal-clear definition of open-source AI. Does it mean that, say, the LLM will be publicly accessible? Does it mean that the model’s architecture and underlying algorithms will be publicly documented or otherwise disclosed?</p><p>“Does it mean that the model’s training data will be publicly available or at least described in a comprehensive manner? Finally, does it mean that the model is lawfully trained on data in public access? These are all separate and complex but interrelated questions, which are frequently conflated by people."</p><p>Amanda Brock, CEO of OpenUK, agreed that the terminology matters — if open source AI will be restricted less than closed systems, we need to define what each means and <a href="https://www.itpro.com/technology/artificial-intelligence/just-how-open-are-the-leading-open-source-ai-platforms">stop calling it "open source"</a>.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED WHITEPAPER</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="TuSX3xC9JcqpfhiVkvtiCf" name="Consulting client briefing.jpg" caption="" alt="Consulting client briefing" src="https://cdn.mos.cms.futurecdn.net/TuSX3xC9JcqpfhiVkvtiCf.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: IBM)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/technology/artificial-intelligence/consulting-client-briefing"><em>Launch a generative AI pilot in just 4-6 weeks</em></a></p></div></div><p>"The real question for every government is of course what are AI &apos;open systems’ — which the press and Meta insist on calling open source AI," she says. "At the moment despite the <a href="https://www.itpro.com/business/policy-and-legislation/the-clock-is-ticking-for-firms-to-comply-with-the-eu-ai-act-heres-what-you-need-to-know">EU AI Act</a> giving exclusions to ‘free and open-source AI, neither term has a meaning."</p><p>Brock noted there are efforts to define open source AI, but warned any definition must include all aspects of AI, with a full understanding of what it means for each to be partly or totally open and the benefits and risks of each — she pointed to the recent <a href="https://www.ru.nl/en/research/research-news/open-alternatives-to-chatgpt-are-on-the-rise-but-how-open-is-ai-really" target="_blank">Radboud University Report</a> that breaks systems down into 14 key components as an example.</p><p>"Understanding the principles of open source software at the heart of the Open Source Software Definition is key — the free flow where anyone can use it for any purpose removes the friction of other licensing or payment," Brock added.</p><p>"Meta’s Llama, whilst a great step in the right direction of openness, is limited in what is opened and introduces friction with commercial restrictions in the license."</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ New UK government should embrace open source, says industry non-profit ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/software/open-source/new-uk-government-should-embrace-open-source-says-industry-non-profit</link>
                                                                            <description>
                            <![CDATA[ Open source ideals could help drive digital uptake in the sluggish public sector, according to OpenUK ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">q4gukNP4a3ntBEQ2ymHqVY</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/vkzdKz4uQMWCrTivfYkZH8-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 08 Jul 2024 09:35:48 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Open Source]]></category>
                                                    <category><![CDATA[Software]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/vkzdKz4uQMWCrTivfYkZH8-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Keir Starmer, UK prime minister, speaks during a news conference following his first cabinet meeting, at Downing Street in London, UK, on Saturday, Jul. 6, 2024.]]></media:description>                                                            <media:text><![CDATA[Keir Starmer, UK prime minister, speaks during a news conference following his first cabinet meeting, at Downing Street in London, UK, on Saturday, Jul. 6, 2024.]]></media:text>
                                <media:title type="plain"><![CDATA[Keir Starmer, UK prime minister, speaks during a news conference following his first cabinet meeting, at Downing Street in London, UK, on Saturday, Jul. 6, 2024.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/vkzdKz4uQMWCrTivfYkZH8-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The UK government should make better use of <a href="https://www.itpro.com/software/28109/what-is-open-source">open source</a> technologies in the <a href="https://www.itpro.com/business/public-sector">public sector</a> and adopt a more open approach to <a href="https://www.itpro.com/strategy/28181/what-is-ai">AI</a> development, according to OpenUK. </p><p>The non-profit group, which represents the country’s open source community, made the call to action just hours before polls closed ahead of the 2024 general election last week in its latest manifesto launch.</p><p>A key talking point in the new manifesto centers around fostering closer ties between the open source ecosystem and government, which the group has been keen to push in recent years.</p><p>Open source could, the organization says, supercharge the UK economy and unlock marked benefits for public sector bodies.</p><p>"The Open Manifesto is a rallying cry to develop skills that will enable jobs in our left-behind rural communities. It’s also a call to seize our late-mover advantage in the public sector, to build the next generation of open source skills and management across the UK public sector," said Amanda Brock, CEO of OpenUK.</p><p>"Only by doing this will the digital infrastructure we all rely on today be allowed to flourish. This will both revolutionize the UK’s public services and bolster our already strong homegrown community."</p><p>Based on data mined from <a href="https://www.itpro.com/open-source/31833/what-is-github">GitHub</a> on a quarterly basis, OpenUK said that with 3.6 million GitHub account holders - 5% of the UK’s population - the UK has the highest per capita number of any country in the world.</p><p>But while the UK is still number one in Europe in open source, France is now the fastest adopter nation thanks to Macron’s pro-open source approach. As such, the new government must look to support its open source community to ensure the UK’s digital economy doesn&apos;t lose its position of strength.</p><p>Leaders and founders frequently leave to work and build businesses in the US, the report warned, while Brexit, delays in policy, and lack of understanding have left the UK trailing behind.</p><h2 id="driving-open-source-in-the-public-sector">Driving open source in the public sector</h2><p>In particular, the UK public sector must use its late-mover advantage to structure its curation - the good practices in management - of open source, and funding should be increased. </p><p>Mike Bracken, founder of Public Digital, said public sector technology investment approaches have focused on closed technology supply chains for too long, adding that this “has to stop immediately” to deliver benefits for workers, reduce costs, and drive productivity.</p><p>"The UK has a solid body of open source in operation and a talented, committed set of professionals curating it,” he said. “What is lacking is open governance, with a central standards body capable of driving adoption and control across the public estate."</p><p>In terms of AI, the manifesto calls for greater openness to more effectively manage risk. The government should utilize open source in <a href="https://www.itpro.com/technology/artificial-intelligence/concerns-raised-over-lack-of-open-source-representation-on-homeland-security-ai-safety-board">AI safety</a> and management tooling, building on work by the <a href="https://www.itpro.com/business/policy-and-legislation/us-and-uk-sign-deal-to-steer-global-ai-safety-standards">UK AI Safety Institute</a>.</p><p>"Open source software is typically safer and more secure, as well as more compute efficient to operate, due to all the ongoing feedback, scrutiny, and development from the community," the report said. "This is a big deal because safety is one of the most important issues in AI."</p><h2 id="open-source-could-have-a-friend-in-labour">Open source could have a friend in Labour</h2><p>With the Labour Party securing a landslide victory in the general election, the open source community could have a friend in the new government. </p><p>The Labour Party specifically highlighted engagement with the open source ecosystem as a key focus as part of its broader technology industry strategy earlier this year.</p><p>Speaking at <em>State of Open Con 2024</em> in February this year, former shadow minister for science and innovation Chi Onwurah <a href="https://www.itpro.com/business/policy-and-legislation/a-future-labour-government-looks-to-pin-its-tech-sector-hopes-on-open-source">told attendees the party is a strong supporter of the open source industry</a>.</p><p>Onwurah said boosting support for the ecosystem represented an “opportunity to democratize technology”. Core to Labour’s mission with open source would be engendering a sense of empowerment across the UK tech workforce, Onwurah said at the time.</p><p>Onwurah suggested open source values and practices could help provide a greater level of access to the skills and materials needed to thrive in software development, particularly in rural areas.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ ‘I find it a pretty big turnoff’ — Why Mark Zuckerberg thinks closed source AI competitors are harming the industry  ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/software/open-source/i-find-it-a-pretty-big-turnoff-why-mark-zuckerberg-thinks-closed-source-ai-competitors-are-harming-the-industry</link>
                                                                            <description>
                            <![CDATA[ Mark Zuckerberg framed Meta as the leading open source alternative on the AI market in a recent interview ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">vaqmnN4ia35m5tjcaEgmFR</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/GCsGe3GknekAADBVCPPCHE-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 28 Jun 2024 11:28:36 +0000</pubDate>                                                                                                                                <updated>Fri, 28 Jun 2024 12:45:54 +0000</updated>
                                                                                                                                            <category><![CDATA[Open Source]]></category>
                                                    <category><![CDATA[Software]]></category>
                                                                                                <author><![CDATA[ george.fitzmaurice@futurenet.com (George Fitzmaurice) ]]></author>                    <dc:creator><![CDATA[ George Fitzmaurice ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/N4xHCjSAXKcijjt3oiQtfc.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/GCsGe3GknekAADBVCPPCHE-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Meta CEO Mark Zuckerberg speaks about the new Facebook News feature at the Paley Center For Media on October 25, 2019 in New York City.]]></media:description>                                                            <media:text><![CDATA[Meta CEO Mark Zuckerberg speaks about the new Facebook News feature at the Paley Center For Media on October 25, 2019 in New York City.]]></media:text>
                                <media:title type="plain"><![CDATA[Meta CEO Mark Zuckerberg speaks about the new Facebook News feature at the Paley Center For Media on October 25, 2019 in New York City.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/GCsGe3GknekAADBVCPPCHE-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Meta CEO Mark Zuckerberg took shots at competitors for pursuing a ‘closed source’ approach to AI development in a <a href="https://www.youtube.com/watch?v=m88OV10vRLA" target="_blank"><u>recent interview</u></a>, even though experts have been skeptical of defining the company&apos;s Llama large language model (LLM) as fully open source.</p><p>Sitting down with entrepreneur-focused YouTube channel <em>Kallaway</em>, Zuckerberg covered ground on Meta’s AI game plan and its vision for the space, taking a moment to express his concerns about other attitudes to the technology.</p><p>Zuckerberg said he doesn’t think AI technology should be “hoarded” so that individual companies can take ownership and keep hold of it to “build whatever central, single, product that they’re building”.</p><p>“I find it a pretty big turnoff when people in the tech industry kind of talk about building this one true AI,” he said.</p><p>For Zuckerberg, the future is “not going to be one AI” but rather many different options with different people and alternative possibilities for creation. </p><p>"That&apos;s partially why I believe so much in open source,” he added. </p><p>Expanding on this point, Zuckerberg hinted at the role AI developers and providers play in empowering users to add to the busy ecosystem of models and tools currently available.</p><p>While part of this role involves AI companies “building tools for creators and for users” that will allow them to build their own versions of AI, part of the role is “the open source thing too”.</p><p>Open source creates an environment where “other companies out there can create different things and people can just hack on it themselves”, he said.</p><h2 id="is-meta-pursuing-a-apos-true-apos-open-source-approach-to-ai">Is Meta pursuing a &apos;true&apos; open source approach to AI?</h2><p>Despite being a strong proponent of <a href="https://www.itpro.com/software/open-source/the-future-of-generative-ai-lies-in-open-source">open source AI development</a>, some industry stakeholders have questioned whether the tech giant can fully argue its offerings are <a href="https://www.itpro.com/software/28109/what-is-open-source">open source</a> by definition.</p><p><a href="https://www.itpro.com/technology/artificial-intelligence/just-how-open-are-the-leading-open-source-ai-platforms"><u>Speaking to </u><u><em>ITPro </em></u><u>in April</u></a>, OpenUK CEO Amanda Brock described the firm’s most recent model, <a href="https://www.itpro.com/technology/artificial-intelligence/metas-llama-3-will-force-openai-and-other-ai-giants-to-up-their-game">Llama 3</a>, as “not truly, 100% open source”. </p><p>This is because its terms and conditions stipulate cooperation with Meta upon reaching certain levels of commercialization. </p><p>While Brock commended Meta’s movement in the “direction of openness”, she argued that the firm&apos;s AI models are not open source in the truest sense of the phrase.</p><div class="youtube-video" data-nosnippet ><div class="video-aspect-box"><iframe data-lazy-priority="high" data-lazy-src="https://www.youtube-nocookie.com/embed/m88OV10vRLA" allowfullscreen></iframe></div></div><p>Arun Chandrasekaran, distinguished VP analyst at Gartner, told <em>ITPro </em>that Meta has certain competitive desires in the AI market that ultimately restrict the openness of its models. </p><p>The company doesn&apos;t want its core competitors to benefit from its models, Chandrasekaran suggested, which is why it has certain limitations built in.</p><h2 id="ai-and-open-source-is-an-ongoing-talking-point">AI and open source is an ongoing talking point</h2><p>Meta isn&apos;t the only firm touting its open source AI credentials, either. Most notably, French-based startup <a href="https://www.itpro.com/technology/artificial-intelligence/why-mistral-ai-could-be-europes-answer-to-us-dominance">Mistral AI</a> has framed itself as a leading proponent of open source AI development in Europe. </p><p>The company has imposed some restrictions on its offerings, however.</p><p>In May, <a href="https://www.itpro.com/software/development/mistral-ai-just-launched-codestral-its-own-competitor-to-code-llama-and-github-copilot-and-its-fluent-in-over-80-programming-languages">Mistral unveiled the launch of its new &apos;Codestral&apos; coding assistant</a> in a direct bid to compete with platforms such as Meta&apos;s own <a href="https://www.itpro.com/technology/artificial-intelligence/meta-just-released-its-answer-to-github-copilot-and-its-free">Code Llama</a>. In this instance, Mistral described Codestral as an “open-weight” <a href="https://www.itpro.com/technology/artificial-intelligence-ai/369959/what-is-generative-ai">generative AI</a> model in its blog post, meaning it’s not strictly ‘open source’ by most definitions. </p><div  class="fancy-box"><div class="fancy_box-title">RELATED WHITEPAPER</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="SU8mq7Gcbbhf2CuG9KFeoP" name="Innovate faster with GPU-accelerated AI.jpg" caption="" alt="Innovate faster with GPU-accelerated AI" src="https://cdn.mos.cms.futurecdn.net/SU8mq7Gcbbhf2CuG9KFeoP.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Dell)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/technology/artificial-intelligence/innovate-faster-with-gpu-accelerated-ai"><em>Gain a competitive edge with AI-optimized solutions</em></a></p></div></div><p>Elsewhere, Databricks released its own open source DBRX model <a href="https://www.itpro.com/technology/artificial-intelligence/databricks-just-launched-an-open-source-large-language-model-to-compete-with-llama-2-mixtral-and-gpt-35">earlier this year</a> as part of efforts to “democratize” the training and tuning of LLMs.</p><p>Once again, Brock was skeptical of the open source claim, telling <em>ITPro</em> at the time that this operates on a license separate from the Open Systems Interconnection (OSI) jurisdiction. </p><p>The Linux Foundation announced the Open Platform for Enterprise AI (OPEA) earlier this year, which will look at creating a gradient system for standardizing open source definitions in AI.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ It’s time to face the open source security problem ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/software/open-source/its-time-to-face-the-open-source-security-problem</link>
                                                                            <description>
                            <![CDATA[ Software companies have built on open source for decades. Now they need to give back ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">g4XbK8ArR2YuYnksoTkYJK</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/N4WVcRaCErmRhmpfH6yn96-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 14 Jun 2024 09:11:09 +0000</pubDate>                                                                                                                                <updated>Fri, 14 Jun 2024 13:30:05 +0000</updated>
                                                                                                                                            <category><![CDATA[Open Source]]></category>
                                                    <category><![CDATA[Software]]></category>
                                                                                                                    <dc:creator><![CDATA[ Steve Ranger ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/gFeXmAxutpTpGN7c98ZAwJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/N4WVcRaCErmRhmpfH6yn96-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Cyber security debt concept image showing multi-colored padlock on top of a circuit board.]]></media:description>                                                            <media:text><![CDATA[Cyber security debt concept image showing multi-colored padlock on top of a circuit board.]]></media:text>
                                <media:title type="plain"><![CDATA[Cyber security debt concept image showing multi-colored padlock on top of a circuit board.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/N4WVcRaCErmRhmpfH6yn96-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p><a href="https://www.itpro.com/software/open-source">Open source</a> is one of the greatest strengths of the software industry. It’s the vast ocean of code, features, applications and <a href="https://www.itpro.com/tag/operating-systems">operating systems</a> that allows the smallest startups to compete with the mightiest tech giants. </p><p><a href="https://www.itpro.com/software/28109/what-is-open-source">Open source</a> code – most often written by small groups of enthusiasts– can be used freely by anyone. It’s the secret ingredient in most software projects, which means developers don’t have to start from scratch every time. </p><p>Each of these individual open source projects might be small, but together they make up the vast majority of the software we use.</p><p>It embodies a couple of pretty noble concepts: that we gain more by sharing knowledge than by hoarding it, and that even the smallest contribution to the sum of knowledge can make a difference.</p><p>The trouble is, a lot of people in the <a href="https://www.itpro.com/software">software</a> industry don&apos;t see it that way.</p><p>They just see open source as a really handy source of free software that they can use as they like. Increasingly that’s an attitude that is causing problems for all of us.</p><p>Open source isn’t always perfect. Some developers are building projects that they think are fun or cool, without too much interest or experience in making sure the project is also super-secure. Projects may also stop getting updates or simply be abandoned because the maintainers lose interest or just run out of steam.</p><h2 id="more-than-a-passtime">More than a passtime</h2><p>These things might not seem like much of a big deal. Who cares if a little hobby project gets abandoned? </p><p>Well, it becomes a problem if one of those open source projects has been used to build another piece of software that is used by a lot of people, or which props up a piece of critical national infrastructure. </p><p>This happens more than many people realize. According to research by Synopsys, 91% of codebases contained components that were 10 or more versions out-of-date, while 49% of codebases contained open source components that had <a href="https://news.synopsys.com/2024-02-27-New-Synopsys-Report-Finds-74-of-Codebases-Contained-High-Risk-Open-Source-Vulnerabilities,-Surging-54-Since-Last-Year"><u>no development activity</u></a> within the past two years. </p><p>We’ve already seen examples of where the impact of flaws in open source can cause a crisis across the tech industry, with <a href="https://www.itpro.com/security/log4j-nearly-4000-organizations-still-vulnerable-two-years-on"><u>Log4j being perhaps the most high profile</u></a>. The problem is magnified by mysterious bad actors who actively seek to add backdoors to open source for their own (almost certainly malicious) reasons, like in the case of the near miss with <a href="https://www.itpro.com/software/open-source/we-got-lucky-what-the-xz-utils-backdoor-says-about-the-strength-and-insecurities-of-open-source"><u>XZ Utils</u></a> <a href="https://www.itpro.com/security/fears-over-copycat-xz-style-attacks-mount-as-open-source-devs-targeted-with-suspicious-emails"><u>and others</u></a>. It’s a very bad sign that attackers have identified open source components as a weak point in tech security – and it’s a development that makes it all the more urgent to fix the bigger problem.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED WHITEPAPER</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="LLknV3zUwteEHmrfX7EWDN" name="Modern adversaries and evasion techniques.jpg" caption="" alt="Modern adversaries and evasion techniques" src="https://cdn.mos.cms.futurecdn.net/LLknV3zUwteEHmrfX7EWDN.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Crowdstrike)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/modern-adversaries-and-evasion-techniques"><em>Discover why legacy AV is an easy target</em></a></p></div></div><p>All software is built on other software projects, but a lot of software companies are building profitable products by standing on the shoulders of exhausted volunteers or hobbyists who need more money and more help. At the moment, it’s the people who have helped the tech industry to ‘move fast and break things’ who are themselves being left bruised and broken.</p><p>As the <a href="https://openjsf.org/blog/openssf-openjs-alert-social-engineering-takeovers"><u>OpenJS Foundation noted recently</u></a>: “The pressure to sustain a stable and secure open source project creates pressure on maintainers. For example, many projects in the JavaScript ecosystem are maintained by small teams or single developers who are overwhelmed by commercial companies who depend on these community-led projects yet contribute very little back.”</p><p>So what needs to change? </p><p>To my mind it’s hard to blame the individuals or teams who contribute their time and skills for free to build these projects. Certainly they need help, but the burden should not fall on them alone. Instead, the software industry needs to take more responsibility for the open source software it uses – and profits from. </p><p>Software companies have long been reluctant to provide a software bill of materials – a list of ingredients – for their products. That makes it hard to know what is really inside their products, making it harder to mitigate flaws. Being clearer about what is included in their products will help make the impact of open source clearer. </p><p>Software companies also need to do more to support the open source they build on by feeding back security improvements to make everyone safer.</p><h2 id="a-step-in-the-right-direction">A step in the right direction</h2><p>There’s grounds for some limited optimism that that state of open source security might be about to improve. There are a number of initiatives underway that each aim to tackle the problem from different directions. Some big tech companies got engineers who work directly with widely used open source projects to improve security one fix at a time. </p><p>There are other broader efforts like the recently launched ‘Protobom’ – a project from <a href="https://openssf.org/"><u>the Open Source Security Foundation</u></a> (OpenSSF), along with the US Cybersecurity and Infrastructure Security Agency (CISA). This is an open source software supply chain tool that allows developers to create a standard software bill of materials. There are also a number <a href="https://www.itpro.com/software/open-source/openssf-malicious-packages-repository-launches-in-bid-to-counter-security-threats"><u>of other tools</u></a> out there and in development.</p><p>These steps are positive but more would help; the tech industry can’t continue to consider open source projects indispensable, but treat their maintainers as irrelevant. </p><p>While tech executives can enjoy the benefits of open source without much of the responsibility for now, that may be about to change. </p><p>In the US top executives are now required to <a href="https://www.itpro.com/software/development/new-secure-software-development-rules-mean-us-tech-execs-will-have-to-sign-safety-guarantees"><u>sign off on the safety of their software</u></a>. That may focus their minds on exactly what is inside the products they are selling and, as a result, the responsibility for making sure software is secure may finally be shared in the way it always should have been.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Red Hat confirms channel-centric changes and says more partner-focused initiatives are on the horizon ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/software/open-source/red-hat-confirms-channel-centric-changes-and-says-more-partner-focused-initiatives-are-on-the-horizon</link>
                                                                            <description>
                            <![CDATA[ Just last month at the firm’s annual conference, Red Hat stressed the importance of its partner ecosystem… ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">qwf3N995NYmXk7kytdNpFG</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/fHX2LUvngcn4RWVQKNrsTo-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Sun, 02 Jun 2024 07:41:45 +0000</pubDate>                                                                                                                                <updated>Wed, 05 Jun 2024 09:20:06 +0000</updated>
                                                                                                                                            <category><![CDATA[Open Source]]></category>
                                                    <category><![CDATA[Software]]></category>
                                                                                                <author><![CDATA[ Maggie.holland@futurenet.com (Maggie Holland) ]]></author>                    <dc:creator><![CDATA[ Maggie Holland ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/yR3aBSQeNTZZ8SzoXbFEQ3.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Maggie has been a journalist since 1999. She started her career as an editorial assistant on then-weekly magazine Computing, before working her way up to senior reporter level. After several years on the magazine, she moved to &#039;the other side of the fence&#039; to work as a copywriter for a marketing agency, writing case studies and working on ad and website copy for companies such as eBay, Dell, Microsoft and more. In 2006, just weeks before&amp;nbsp;ITPro&amp;nbsp;was launched, Maggie joined Dennis Publishing as a reporter. Having worked her way up to editor of ITPro, she was appointed group editor of&amp;nbsp;CloudPro&amp;nbsp;and&amp;nbsp;ITPro&amp;nbsp;in April 2012. She became the editorial director and took responsibility for&amp;nbsp;ChannelPro,&amp;nbsp;in 2016.&lt;/p&gt;
&lt;p&gt;Her areas of particular interest, aside from cloud, include management and C-level issues, the business value of technology, green and environmental issues and careers to name but a few.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/fHX2LUvngcn4RWVQKNrsTo-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[The logo of the global publisher of Open Source software solutions, Red Hat is displayed during the Viva Technology conference at Parc des Expositions Porte de Versailles on June 15, 2023 in Paris, France.]]></media:description>                                                            <media:text><![CDATA[The logo of the global publisher of Open Source software solutions, Red Hat is displayed during the Viva Technology conference at Parc des Expositions Porte de Versailles on June 15, 2023 in Paris, France.]]></media:text>
                                <media:title type="plain"><![CDATA[The logo of the global publisher of Open Source software solutions, Red Hat is displayed during the Viva Technology conference at Parc des Expositions Porte de Versailles on June 15, 2023 in Paris, France.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/fHX2LUvngcn4RWVQKNrsTo-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Red Hat is putting its money where its mouth is by continuing its mission to change up its partner program and ecosystem support for the better. </p><p>Some key tweaks have already been made and there’s more to come, according to Penny Philpot, vice president of the firm’s EMEA Partner Ecosystem. </p><p>Philpot, a multi-decade channel veteran, has made a meaningful impact on how Red Hat engages with partners since her appointment a year ago. </p><p>“One of the things we did was to put all of the channel partner-facing people in my organization. If you&apos;re just an individual reporting to somebody who&apos;s not necessarily a channel person that can get confusing in terms of what the message is. So, from the partner’s perspective [it’s about] having a very strong relationship, one that&apos;s consistent, and it&apos;s really focused on new opportunities and growth,” she said. </p><p>Philpot continued: “We&apos;re very much looking at our partners to help us to find that net new business and not just working with us,  leading from the front. We&apos;ve also changed a lot of the models, especially in companies that are not necessarily ‘enterprise.’</p><p>“We all talk about customer-first, but partner-always.  [In the past year] the DNA of working with partners has drastically improved. We&apos;ve done a lot of things to move people to understand how partners can help grow, upsell, and cross-sell. And, in many cases, they are way more advanced in knowing the landscape for customers because they&apos;re talking to them already. And we&apos;ve got a fantastic solution.”</p><p>Before joining Red Hat, Philpot spent 25 years at Oracle and held key positions at Cisco and Microsoft. This experience, she said, brought a very valid and timely external perspective to things and was a key reason for her hiring. </p><p>“We&apos;re getting very good at changing the conversation to be much more about customer value and customer solutions.  And that&apos;s across all the customer and partner-facing people. We&apos;ve also done quite a bit with regard to how we communicate with our partners as well,” she said. </p><p>Although much work has been done, Philpot is mindful that what partners want and need is generally something that must adapt and change in response to shifting market or individual requirements, </p><p>“In my experience from other vendors, it&apos;s one of those things that you never quite get right. You never will. It is like painting the forth bridge - you&apos;ll always have to go back and do it again.” <br></p><p>But that’s exactly why it was so important for Philpot to make some fundamental changes around communication and consistency early on.  These changes complement some of the previously announced shifts in how Red Hat engages with partners. </p><p>Back in January, the firm said it planned to launch a new partner program framework as well as enhancing the tools, training, and resources available to its channel ecosystem. This includes the launch of a new Partner Practice Accelerator Program and other elements designed, according to Philpot, “moving away from partner type and pigeonholing partners.”</p><p>She continued: “The idea is that the new program is going to be very much leaning towards the things you [as a partner] want to do with it. That could be one or many things, so whatever the journey is  that you want to go with us, we&apos;re here to help.”</p><p>The existing and incoming changes to Red Hat’s approach to partners are timely and sensible, according to industry experts. Indeed, research firm IDC has predicted that by next year, the majority (70 percent) of vendors will actively be pursuing a customer-led ecosystem orchestration strategy. This, it believes, will place added importance on vendor alignment with partners to offer and deliver coordinated solutions, services, and more. </p><p>Red Hat is focused on building, connecting, and driving collaboration between an open ecosystem of very diverse partners all working together to deliver customer value, according to Stuart Wilson, senior research director, EMEA Partnering Ecosystems at IDC. </p><p>“Red Hat recognizes the need to map changes in customer behavior and buying preferences and to build flexibility in the partnering model to serve each unique customer in the way that works best for that customer. Initiatives such as go-to-market models involving major cloud platform providers and their marketplace environments are examples of how Red Hat is responding to changing customer preferences for purchase and consumption,” he told <em>ITPro. </em></p><p>“Red Hat is showing commitment to a "win-win-win" blended partner and customer engagement strategy where vendor, partner, and customer are aligned around a model that focuses on mutually beneficial outcomes for all parties involved. This type of outcome is delivered through a customer-led ecosystem orchestration mindset, where the needs of customers and partners are considered in the design of the partner engagement framework and model.</p><p>“Red Hat&apos;s evolution in terms of its partnering approach also shows a growing appreciation of the value of different partner activities that are not always directly linked to transaction-based customer engagements. This flexibility starts to move Red Hat away from a partner engagement framework where partner programs were distinct and siloed by a specific partner identity or activity such as sell, serve, and build.”</p><p>It would seem the stars are somewhat aligning for Red Hat, partners, customers, and industry observers right now. Philpot agrees, saying: “It&apos;s never been a better time. I feel like we&apos;re at this pivotal inflection point where the market’s aligned, our products are aligned, and our partners are aligned as well. The partner loyalty here is amazing, much bigger than any other company I&apos;ve had.”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ The debate over ‘open source AI’ has reached boiling point — this new OSI initiative looks to set the record straight ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/software/open-source/the-debate-over-open-source-ai-has-reached-boiling-point-this-new-osi-initiative-looks-to-set-the-record-straight</link>
                                                                            <description>
                            <![CDATA[ With the debate over what constitutes 'open source AI' still raging, the OSI looks to create a clear-cut definition through a new initiative ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">iWCB4b98qdbd8AQZ73pwpL</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/VBqn2J5kcKMXXeboZJS47n-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 17 May 2024 11:05:53 +0000</pubDate>                                                                                                                                <updated>Fri, 17 May 2024 13:37:21 +0000</updated>
                                                                                                                                            <category><![CDATA[Open Source]]></category>
                                                    <category><![CDATA[Software]]></category>
                                                                                                <author><![CDATA[ george.fitzmaurice@futurenet.com (George Fitzmaurice) ]]></author>                    <dc:creator><![CDATA[ George Fitzmaurice ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/N4xHCjSAXKcijjt3oiQtfc.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/VBqn2J5kcKMXXeboZJS47n-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Open source AI concept image showing digitized brain hovering over a circuit board.]]></media:description>                                                            <media:text><![CDATA[Open source AI concept image showing digitized brain hovering over a circuit board.]]></media:text>
                                <media:title type="plain"><![CDATA[Open source AI concept image showing digitized brain hovering over a circuit board.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/VBqn2J5kcKMXXeboZJS47n-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The Open Source Initiative (OSI) has announced plans to further clarify the definition of <a href="https://www.itpro.com/technology/artificial-intelligence/just-how-open-are-the-leading-open-source-ai-platforms">open source AI</a> by embarking on a global workshop series aimed at garnering input from experts.</p><p>The OSI said it will engage with a range of stakeholders in the <a href="https://www.itpro.com/software/28109/what-is-open-source">open source</a> space, using their contributions to further develop the draft definition of open source <a href="https://www.itpro.com/strategy/28181/what-is-ai">AI</a> it has been working on. </p><p>These workshops will be held in five continents including North America, Europe, Africa, Asia, and Latin America, with the intention of presenting a “stable version” of the definition at the ‘All Things Open’ event in North Carolina.</p><p>“AI is different from regular software and forces all stakeholders to review how the Open Source principles apply to this space,” Stefano Maffulli, executive director of the OSI, said.</p><p>“After spending almost two years gathering voices from all over the world to identify the principles of Open Source suitable for AI systems, we’re embarking on a worldwide roadshow to refine and validate the release candidate version of the Open Source AI Definition.”</p><p>According to the OSI, the complete definition will provide a framework for AI developers to determine whether an AI platform is open source or not, acting as an accepted standard for <a href="https://www.itpro.com/software/open-source/open-source-software-attacks-everything-you-need-to-look-out-for">open source software</a> specifically in the AI space.</p><p>The extent to which this planned workshop will affect the definition will depend on the contributions that arise, Michal Szymczak, Head of AI Strategy at Zartis, told <em>ITPro</em>. </p><p>“We need to assess the workshops as very wide consultations with scholars and AI and <a href="https://www.itpro.com/strategy/28087/machine-learning-vs-ai">ML</a> practitioners who are going to attend the conferences and events,” Szymczak said.</p><p>“It is very likely the definition is going to get refined where the current components remain (as the list is rather comprehensive) but their required/optional status might change,” he added.</p><p>Szymczak also stated that the global workshop could lead to a heightened adoption rate of the new definition, as participants will be able to point to AI projects which already meet the criteria.</p><h2 id="open-source-ai-is-uncertain-territory-xa0">Open source AI is uncertain territory </h2><p>Despite the OSI’s mission to create a clear cut definition of open source AI, questions remain over the extent to which current <a href="https://www.itpro.com/technology/artificial-intelligence/just-how-open-are-the-leading-open-source-ai-platforms"><u>AI models can be defined as open source</u></a>, with many big name models criticized over their supposed alignment with the community. </p><div  class="fancy-box"><div class="fancy_box-title">RELATED WHITEPAPER</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="qfvRGvmpXjbcKPZ2q5dUqM" name="Energy efficiency and sustainability demands are transforming IT strategy.jpg" caption="" alt="Energy efficiency and sustainability demands are transforming IT strategy" src="https://cdn.mos.cms.futurecdn.net/qfvRGvmpXjbcKPZ2q5dUqM.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Dell)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/business/business-strategy/energy-efficiency-and-sustainability-demands-are-transforming-it-strategy"><em>Tips on how you can improve your energy efficiency</em></a></p></div></div><p>Companies like Meta have defined their models as open, but experts in the field such as OpenUK CEO Amanda Brock have noted that these are not “truly, 100% open source” due to certain stipulations in their terms and conditions.</p><p>The Linux Foundation recently made a move similar to that of the OSI to address this problem, unveiling the Open Platform or Enterprise AI (OPEA) as a graded approach to open source AI.</p><p>The OPEA breaks down AI platforms into their constituent parts, granting open source licenses where possible and different licenses where not, so as to better integrate open source into the complex technology of AI. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ HashiCorp's claims of code theft dubbed "embarrassing" episode for the open source community ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/software/open-source/hashicorps-claims-of-code-theft-dubbed-embarrassing-episode-for-the-open-source-community</link>
                                                                            <description>
                            <![CDATA[ HashiCorp claims OpenTofu used its code in a manner that violates licensing terms, undermining Hashicorp’s intellectual property rights in the process ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">skDaukMSg7LHoBkkEK5q8g</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/RnbwKX8ug8iuoiyjZRAyBJ-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 17 Apr 2024 13:15:10 +0000</pubDate>                                                                                                                                <updated>Wed, 17 Apr 2024 15:06:27 +0000</updated>
                                                                                                                                            <category><![CDATA[Open Source]]></category>
                                                    <category><![CDATA[Software]]></category>
                                                                                                <author><![CDATA[ george.fitzmaurice@futurenet.com (George Fitzmaurice) ]]></author>                    <dc:creator><![CDATA[ George Fitzmaurice ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/N4xHCjSAXKcijjt3oiQtfc.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/RnbwKX8ug8iuoiyjZRAyBJ-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A close up of two software engineers looking at two monitors showing computer code]]></media:description>                                                            <media:text><![CDATA[A close up of two software engineers looking at two monitors showing computer code]]></media:text>
                                <media:title type="plain"><![CDATA[A close up of two software engineers looking at two monitors showing computer code]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/RnbwKX8ug8iuoiyjZRAyBJ-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>A heated exchange between <a href="https://www.itpro.com/software/open-source/analysis-hashicorp-prioritizes-its-business-with-bsl-license-switch-but-community-upset-cannot-be-ignored">HashiCorp</a> and OpenTofu over accusations of copyright infringement has raised questions around the nature of ownership across open source projects.</p><p>HashiCorp maintains that OpenTofu has used code in a manner that violates the terms of its Business Software license (BSL), undermining Hashicorp’s intellectual property rights in the process.</p><p>OpenTofu has claimed that the code in question was originally derived from sources publicly available under the Mozilla Public License (MPL).</p><p>In a <a href="https://opentofu.github.io/legal-documents/2024-04-03%20HashiCorp%20C%26D/OpenTofu%20C&D%20-%20Redacted.pdf"><u>cease and desist letter</u></a> on April 3, HashiCorp claimed that OpenTofu had “repeatedly taken code” and used it outside the bounds of its license. It also claimed that OpenTofu had gone as far as altering or changing HashiCorp’s code to circumvent infringement claims.</p><p>“In at least some instances, OpenTofu has incorrectly re-labeled HashiCorp’s code to make it appear as if it was made available by HashiCorp originally under a different license,” HashiCorp said in the letter.</p><p>The software company then went on to threaten further and more severe legal action if OpenTofu failed to comply with its demands of a written response.</p><p>“If OpenTofu does not comply, we reserve all rights, including the right to send DMCA takedown notices to Github or any other third party hosting or source code repository provider, and the right to initiate litigation to stop further violations,” HashiCorp said.</p><p>OpenTofu made the letter public before issuing a written response almost a week later.</p><p>OpenTofu <a href="https://www.linkedin.com/posts/opentofuorg_opentofu-project-was-recently-made-aware-activity-7182147077496344576-jsDQ"><u>posted</u></a> to LinkedIn that it “vehemently denied” the claims, while members of the open source community, such as Cloud Native Computing Foundation (CNCF) CTO Chris Aniszczyk, were quick to voice their reactions.</p><p>“Embarrassing to see a company light all of its hard earned developer reputation on fire, on top of attacking open source, ” Aniszczyk said in a <a href="https://www.linkedin.com/posts/caniszczyk_opentofu-project-was-recently-made-aware-activity-7182424359930671107-Ng-Y?utm_source=share&utm_medium=member_android"><u>post</u></a> sharing OpenTofu’s statement.</p><p>OpenTofu’s defense, which it covered in more detail in a <a href="https://opentofu.github.io/legal-documents/2024-04-03%20HashiCorp%20C%26D/OpenTofu%20C&D%20Response%20-%20Redacted.pdf"><u>formal letter</u></a> addressed to HashiCorp on April 9, centered on its claim that HashiCorp had in fact conflated code under BSL and MPL.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED WHITEPAPER</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="yVCRnFya8TMVQKjV5XUWDd" name="A Leader’s Guide to Battling Workforce Burnout 2.jpg" caption="" alt="Woman sitting on a sofa working on a laptop" src="https://cdn.mos.cms.futurecdn.net/yVCRnFya8TMVQKjV5XUWDd.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Udemy)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/business/the-future-of-business/a-leaders-guide-to-battling-workforce-burnout"><em>Prevent burnout among your employees</em></a></p></div></div><p>Where HashiCorp claimed that OpenTofu “improperly appropriated” code under the BSL, OpenTofu explained that the “appropriated” code was derived from publically available “pre-fork MPL-2.0 files”.</p><p>“The more accurate explanation, however, is that both the OpenTofu files to which you refer and HashiCorp’s Terraform files to which you compare them are both derived (at least to some degree) from … code that was made publicly available,” OpenTofu said.</p><p>The company argued that HashiCorp has fundamentally misrepresented the history and origination of the OpenTofu project’s source code, and therefore its accusations are baseless.</p><p><a href="https://opentofu.org/blog/our-response-to-hashicorps-cease-and-desist/"><u>In a subsequent blog post</u></a> on April 11, OpenTofu made both letters publicly available, along with a further expression of denial and a reiteration of HashiCorp’s mistake.</p><h2 id="license-changes-don-x2019-t-bode-well-for-the-community">License changes don’t bode well for the community</h2><p>The current tension at play here, between a software company and an open source platform, is one uniquely borne out of a change in business-focused change in license structure.</p><p><a href="https://www.itpro.com/software/open-source/analysis-hashicorp-prioritizes-its-business-with-bsl-license-switch-but-community-upset-cannot-be-ignored"><u>When HashiCorp itself swapped to the BSL</u></a>, there was widespread upset in the open source community, with former Percona CEO Peter Zaitsev even going so far as to brand the move “hostile”.</p><p>While the firm claimed its decision to be in the spirit of the community - as a defense mechanism against other vendors taking unfair advantage of the open source license - HashiCorp’s recent fallout with OpenTofu suggests otherwise. HashiCorp now has to defend the ownership of its source code with a level of commercial intent, pitting it against the community it used to be part of.</p><p>The waters are also considerably muddied in terms of ownership. Throughout the legal exchange between HashiCorp and OpenTofu, there is a clear sense of confusion about how and where the code had been changed.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Why Flux CD’s survival is another major victory for the open source community ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/software/open-source/why-flux-cds-survival-is-another-major-victory-for-the-open-source-community</link>
                                                                            <description>
                            <![CDATA[ Despite a rocky road after the fall of Weaveworks, Flux CD is now receiving support from several organizations ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">o7aYxrqSRxBQ9bRLuz4xuc</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/aoCKv9cD275h2U8YN5N5Nm-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 08 Apr 2024 09:15:00 +0000</pubDate>                                                                                                                                <updated>Mon, 08 Apr 2024 12:48:54 +0000</updated>
                                                                                                                                            <category><![CDATA[Open Source]]></category>
                                                    <category><![CDATA[Software]]></category>
                                                                                                <author><![CDATA[ george.fitzmaurice@futurenet.com (George Fitzmaurice) ]]></author>                    <dc:creator><![CDATA[ George Fitzmaurice ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/N4xHCjSAXKcijjt3oiQtfc.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/aoCKv9cD275h2U8YN5N5Nm-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Cloud native concept image showing multiple platforms and applications all interlinked.]]></media:description>                                                            <media:text><![CDATA[Cloud native concept image showing multiple platforms and applications all interlinked.]]></media:text>
                                <media:title type="plain"><![CDATA[Cloud native concept image showing multiple platforms and applications all interlinked.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/aoCKv9cD275h2U8YN5N5Nm-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Several companies have announced that they will be rallying around the Flux CD platform in the wake of ongoing uncertainty for the project, the Cloud Native Computing Foundation (CNCF) recently announced.</p><p>The continuous delivery tool faced a worrying future when Weaveworks, the employer of most of the project&apos;s maintainers, announced that it would terminate commercial operations.</p><p>Now, an array of companies have pledged backing for Flux CD, including Microsoft Azure and Edgecell, as well as additional “long-time Flux adopters” such as Cisco. </p><p>GitLab specifically announced its support for Flux CD and revealed in early 2023 that it would be integrating Flux with its agent for Kubernetes as the “recommended GitOps solution.”</p><p>This newfound commitment to Flux CD will help ensure the continued maintenance and development of Flux GitOps tool, as well as delivery for applications and platforms in a move that will transition the project to a “stronger and broader community.” </p><p>“This is a great example of the strength and resilience of our community and we look forward to Flux&apos;s continued evolution and growth,” Chris Aniszczyk, CTO of the CNCF, said. </p><p>Flux CD’s core maintainer, Stefan Prodan, commented on the project&apos;s future, expressing gratitude towards the CNCF while also calling on the community to help shape the platform’s future. </p><p>“We want to enable community members to take full ownership of Flux features and share the responsibility of feature stability and longer-term maintenance,” Prodan said. </p><h2 id="flux-cd-support-highlights-open-source-community-spirit">Flux CD support highlights open source community spirit</h2><p>Amanda Brock, CEO of OpenUK, told <em>ITPro </em>the continued support for Flux CD will ensure the platform is “safeguarded” for the future, and highlighted the crucial role open source industry stakeholders have played during this disruption. </p><p>Backing from ControlPlane specifically, Amanda said, will help to ensure that all the project’s core maintainers are employed going forward, paving the way for a Flux CD future that is both open and commercially viable. </p><p>“A second open source business stepping in means that they understand how to manage a revenue model, which hopefully will be more successful this time and allow it to continue,” Brock said. </p><p>Flux CD’s turbulent period began when Weaveworks announced that it was terminating operations earlier this year. </p><div  class="fancy-box"><div class="fancy_box-title">RELATED WHITEPAPER</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="KfDrE7D6uFtCf3YCRjQ7gP" name="Dell Optimizer (1).jpg" caption="" alt="Woman working on laptop" src="https://cdn.mos.cms.futurecdn.net/KfDrE7D6uFtCf3YCRjQ7gP.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Dell)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/technology/artificial-intelligence/dell-optimizer"><em>Discover how Optimizer increases app performance</em></a><em> </em></p></div></div><p>Pressure from competitors in the space, such as CircleCI and Harness Labs, made financial sustainability difficult for the firm, ultimately resulting in a termination of commercial operations.  </p><p>Prodan told <a href="https://www.forbes.com/sites/justinwarren/2024/03/20/fluxcd-plots-pathway-to-post-weaveworks-success/?sh=63dd9a5642a1"><u><em>Forbes</em></u></a> that this incident highlighted the precarious nature of open source projects which rely heavily on a single organization or limited number of maintainers. </p><p>This is a question that’s marred the open source community in one way or another for some time, with projects often problematically dependent on individual organizations.</p><p>“When you look at any project, one of the biggest issues we&apos;ve seen is single vendor products, where you have one company that&apos;s totally stacked in a product and they employ everybody who works in it,” Brock said. “That dependency is hugely problematic.”</p><p>Without a broad and healthy community surrounding a project, it becomes easy for a company to move out of open source while also threatening the stability of the project in general. </p><p>Examples of such open source departures can be seen in the likes of <a href="https://www.itpro.com/software/open-source/why-redis-license-changes-arent-the-end-of-the-world-for-open-source"><u>Redis, which recently announced its move to ‘source available’</u></a>, or <a href="https://www.itpro.com/software/open-source/analysis-hashicorp-prioritizes-its-business-with-bsl-license-switch-but-community-upset-cannot-be-ignored"><u>Hashi Corp, which moved to Business Source License (BSL) in 2023.</u></a> </p><p>Flux CD’s survival is cause for celebration, Brock added, as it points to a resilient forward momentum in the open source community often unparalleled in other arenas. </p><p>“I think what we also see is the power of the continuum that open source offers that you won&apos;t ever see in proprietary,” Brock said. </p><p>Though businesses can navigate past business closures in the proprietary code landscape, Brock said it’s difficult to mimic the “momentum and continuum” of open source that the community has seen with Flux CD. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Linux Foundation unveils Redis alternative, 'Valkey', with backing from AWS, Google Cloud, and Oracle ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/software/open-source/linux-foundation-unveils-redis-alternative-valkey-with-backing-from-aws-google-cloud-and-oracle</link>
                                                                            <description>
                            <![CDATA[ Valkey will provide developers with an open source Redis alternative following the firm’s move to a more restrictive licensing scheme in March ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">NNhzMhAtd7JgNZogdakDp4</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/kVzjcVBBrB9tCFRMt3W37P-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 05 Apr 2024 20:00:00 +0000</pubDate>                                                                                                                                <updated>Mon, 08 Apr 2024 12:40:47 +0000</updated>
                                                                                                                                            <category><![CDATA[Open Source]]></category>
                                                    <category><![CDATA[Software]]></category>
                                                                                                <author><![CDATA[ ross.kelly@futurenet.com (Ross Kelly) ]]></author>                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Ross Kelly is ITPro&#039;s News &amp;amp; Analysis Editor, with a keen interest in cyber security, business leadership and emerging technologies.&lt;/p&gt;
&lt;p&gt;He graduated from Edinburgh Napier University in 2016 with a BA (Hons) in Journalism, and joined ITPro in 2022 after four years working in technology conference research.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;In his spare time, Ross enjoys cycling, walking and is an avid reader of history and non-fiction.&lt;/p&gt;
&lt;p&gt;You can contact Ross at ross.kelly@futurenet.com or on &lt;a href=&quot;https://twitter.com/rosswritesetc&quot;&gt;Twitter&lt;/a&gt; and &lt;a href=&quot;https://www.linkedin.com/in/ross-kelly-18a54411a/&quot;&gt;LinkedIn&lt;/a&gt;.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/kVzjcVBBrB9tCFRMt3W37P-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Concept image of a female software developer sitting at computer station using open source Redis alternative, Valkey]]></media:description>                                                            <media:text><![CDATA[Concept image of a female software developer sitting at computer station using open source Redis alternative, Valkey]]></media:text>
                                <media:title type="plain"><![CDATA[Concept image of a female software developer sitting at computer station using open source Redis alternative, Valkey]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/kVzjcVBBrB9tCFRMt3W37P-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>A host of cloud industry players have pledged their support for an <a href="https://www.itpro.com/software/28109/what-is-open-source">open source</a> Redis alternative since the company’s shift to a ‘source-available’ license setup last month. </p><p>Redis shocked the open source community in late March after its decision to <a href="https://www.itpro.com/software/open-source/why-redis-license-changes-arent-the-end-of-the-world-for-open-source">switch to a dual-license approach</a> that will see the firm adopt a more restrictive software distribution model.</p><p>Under the proposals, Redis releases will be made available under RSALv2 (Redis Source Available License) and SSPLv1 (Server Side Public License) licenses moving forward.</p><p>This shift to a ‘source available’ approach marked a departure from the company’s traditional setup, which allowed developers to freely use source code for commercial purposes.</p><p>The move by Redis sparked criticism from open source developers and prompted calls for a new open source ‘fork’ - or alternative - to be made available as soon as possible.</p><p>Last week, the <a href="https://www.itpro.com/development/open-source/367689/linux-foundation-unveils-world-of-open-source-research-initiative">Linux Foundation</a> stepped up to the plate on this front, announcing its intent to launch ‘Valkey’, an open source alternative to Redis’ in-memory data store.</p><p>The Linux Foundation said the decision to create an open source alternative was due to the widespread popularity and use of Redis since its creation in 2009.</p><p><a href="https://www.itpro.com/business-strategy/careers-training/358051/software-developers-versus-software-engineers">Developers</a> have used Redis’ in-memory data store capabilities for caching, data analysis, and as a higher throughput data store alternative to backend databases for more than a decade, the foundation said.</p><p>“Developers ranked Redis the sixth most used database in the 2023 Stack Overflow developer survey, and it was among the top three most admired,” according to a <a href="https://www.linuxfoundation.org/press/linux-foundation-launches-open-source-valkey-community" target="_blank">statement</a> from the foundation..</p><p>“To continue improving on this important technology and allow for unfettered distribution of the project, the community created Valkey, an open source high performance key-value store.”</p><p>Valkey will support the <a href="https://www.itpro.com/operating-systems/24841/windows-vs-linux-whats-the-best-operating-system">Linux</a>, macOS, OpenBSD, NetBSD, and FreeBSF platforms, the organization said in a blog post.</p><p>“In addition, the community will continue working on its existing roadmap including new features such as a more reliable slot migration, dramatic scalability and stability improvements to the clustering system, multi-threaded performance improvements, triggers, new commands, vector search support, and more.”</p><h2 id="cloud-giants-welcome-the-open-source-redis-alternative">Cloud giants welcome the open source Redis alternative</h2><p>Several major industry stakeholders have welcomed the move by the Linux Foundation, including AWS, <a href="https://www.itpro.com/cloud/cloud-computing/google-cloud-platform-review-a-solid-but-expensive-service-for-cloud-infrastructure">Google Cloud</a>, Oracle, Ericsson, and Snap Inc. </p><p>All have confirmed their support for Valkey and aim to make contributions that “support the long-term health and viability” of the project, according to the foundation.</p><p>Madelyn Olson, former Redis maintainer, co-creator of Valkey and a principal engineer at AWS, said the creation of Valkey will enable contributors to “pick up where they left off and continue to contribute to a vibrant open source community”.</p><p>Moving forward, Valkey will follow an open governance model, creators said, and a technical leadership committee has been established to oversee the development of the Redis alternative.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED WHITEPAPER</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="r3YLyqAwvXmrVd6r3YAG98" name="r3YLyqAwvXmrVd6r3YAG98.jpg" caption="" alt="Digital chains linked together" src="https://cdn.mos.cms.futurecdn.net/r3YLyqAwvXmrVd6r3YAG98.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Shutterstock)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/technology/idc-marketscape-worldwide-supply-chain-oracle-ecosystem-services-vendor-assessment"><em>Discover how you can innovate your supply chain</em></a></p></div></div><p>Chris Aniszczyk, CTO at the Linux Foundation and <a href="https://www.itpro.com/cloud/cloud-computing/building-human-connections-key-to-cloud-native-success">Cloud Native Computing Foundation</a> (CNCF), said keeping Valkey in the hands of the community will prevent any snap changes to licensing and potential future disruption.</p><p>“Valkey is a fully open source successor built by long standing Redis contributors and maintainers. Fostering open collaboration that benefits all and not just a single organization is critical in building long term, sustainable open source communities,” he said.</p><p>“Also, having this project in the hands of a foundation, rather than a single company, means Valkey will be community-driven without surprise license changes that break trust and disrupt a level open source playing field.”</p><p>Aniszczyk initially cautioned restraint from the community in the wake of the Redis announcement last month. Speaking to <em>ITPro</em> on the situation from <a href="https://www.itpro.com/news/live/kubecon-2024-all-the-latest-news-and-announcements">KubeCon 2024</a> in Paris, he said while the move was disappointing, an alternative would inevitably become available.</p><p>The Redis move marked the latest pivot to more restrictive licensing schemes in the open source space. In mid-2023, <a href="https://www.itpro.com/software/open-source/analysis-hashicorp-prioritizes-its-business-with-bsl-license-switch-but-community-upset-cannot-be-ignored">HashiCorp revealed plans to change its source code license</a> to BSL (Business Source License), which prohibits commercial use.</p><p><a href="https://www.itpro.com/security/data-breaches/mongodb-insists-customers-are-safe-in-wake-of-corporate-systems-data-breach">MongoDB</a> previously made its own changes, which prompted a similar backlash to that witnessed during the HashiCorp switch.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ "We got lucky": What the XZ Utils backdoor says about the strength and insecurities of open source ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/software/open-source/we-got-lucky-what-the-xz-utils-backdoor-says-about-the-strength-and-insecurities-of-open-source</link>
                                                                            <description>
                            <![CDATA[ The XZ Utils backdoor could’ve caused serious problems for Linux, but luckily a developer spotted the malicious code and prevented disaster ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">VvavWafX3bTHGatjv8JMqU</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/qH4rSgzMX6EfrTyVvDH7aB-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 03 Apr 2024 19:00:01 +0000</pubDate>                                                                                                                                <updated>Thu, 04 Apr 2024 10:07:17 +0000</updated>
                                                                                                                                            <category><![CDATA[Open Source]]></category>
                                                    <category><![CDATA[Software]]></category>
                                                                                                                    <dc:creator><![CDATA[ Steve Ranger ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/gFeXmAxutpTpGN7c98ZAwJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/qH4rSgzMX6EfrTyVvDH7aB-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Cyber security concept image showing digitized padlock on a network interface with source code.]]></media:description>                                                            <media:text><![CDATA[Cyber security concept image showing digitized padlock on a network interface with source code.]]></media:text>
                                <media:title type="plain"><![CDATA[Cyber security concept image showing digitized padlock on a network interface with source code.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/qH4rSgzMX6EfrTyVvDH7aB-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p><a href="https://www.itpro.com/software/linux">Linux</a> has just dodged a serious security threat in the form of a mysterious backdoor added to a key library found in many distributions.  </p><p>The backdoor was found in the XZ Utils library and could have allowed an attacker to compromise SSHD authentication, granting unauthorized access to the entire system remotely. Fortunately, however, it was spotted before it had been widely incorporated.</p><p>XZ is a data compression format present in nearly every Linux distribution which helps compress and then decompress large file formats for sharing via file transfers.</p><p>“With a library this widely used, the severity of this vulnerability poses a threat to the entire <a href="https://www.itpro.com/operating-systems/24841/windows-vs-linux-whats-the-best-operating-system">Linux</a> ecosystem,” the Kali Linux team explained in an advisory. “Luckily, this issue was caught quickly so the impact was significantly less than it could have been”.</p><p>The backdoor is quite complex, according to analysis from Akamai. Instead of pushing parts of the backdoor to the public git repository, these were only included in source code tarball releases.</p><p>“This caused parts of the backdoor to remain relatively hidden, while still being used during the build process of dependent projects,” it said.</p><p>It’s not clear who added the backdoor into the library or why, but it seems to have been a very sophisticated attempt to introduce malicious code. It appears that a developer joined the project and contributed to it for two years and took on more responsibility before their account was used to introduce the rogue code.</p><p>In this case, the backdoor was found relatively quickly after another developer spotted some odd behavior around liblzma (part of the xz package) and decided to do a bit of digging.</p><p>After posting his findings online, the Linux distributions affected by the backdoor also issued warnings.</p><p>OpenSUSE said the rolling release distribution openSUSE Tumbleweed and openSUSE MicroOS included the affected version of the XZ / liblzma library between March 7 and March 28.</p><p><a href="https://www.itpro.com/software/open-source/what-red-hats-source-code-restrictions-mean-for-businesses">RedHat</a> also revealed its <a href="https://www.itpro.com/software/linux/357095/switch-to-linux-with-these-top-distros/5">Fedora Linux</a> 40 beta had contained two affected versions of xz libraries, and the vulnerability affected Kali Linux between March 26 to March 29.</p><p>Meanwhile, Debian said compromised packages were part of the <a href="https://www.itpro.com/135084/debian-and-the-grass-roots-of-linux">Debian</a> testing, unstable and experimental distributions, with versions ranging from 5.5.1alpha-0.1 (uploaded on 2024-02-01), up to and including 5.6.1-1.</p><p>The package has since been reverted to use the upstream 5.4.5 code.</p><p>CISA recommended that developers and users downgrade XZ Utils to an uncompromised version - such as XZ Utils 5.4.6 Stable - and hunt for any malicious activity.</p><p>“This backdoor almost became one of the most significant intrusion enablers ever,” said Akamai, because if widely implemented the flaw would have given attackers access to any <a href="https://www.itpro.com/operating-systems/25139/linux-mint-vs-ubuntu-which-one-is-better">Linux</a> machine running an infected distro.</p><p>“This obviously raises a lot of concerns. We got lucky,” Akamai added. “If this backdoor was not detected by a curious engineer, how long would it have remained active? And perhaps even more concerning: What if this has happened before?”</p><h2 id="xz-utils-incident-highlights-the-pros-and-cons-of-open-source">XZ Utils incident highlights the pros and cons of open source</h2><p>It&apos;s an incident which reflects the complicated nature of open source development - and how the actions of a small group of developers can have an outsized impact across the software supply chain. </p><p>The <a href="https://www.itpro.com/software/open-source/openssf-malicious-packages-repository-launches-in-bid-to-counter-security-threats">Open Source Security Foundation</a> said situations like this “remind us all that we need to remain vigilant within the open source software ecosystem”</p><p>“<a href="https://www.itpro.com/software/28109/what-is-open-source">Open source</a> is about well-intentioned humans donating their time and talents to help solve problems, and sadly this can be compromised,” the foundation added.</p><p>However, the open nature of open source stopped the bad code from getting very far, the foundation noted.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED WHITEPAPER</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="koNvE9zmQFam7EYpnGTT9m" name="ThreatLabz Report_The state of encrypted attacks_listing.jfif.jpg" caption="" alt="Whitepaper cover with title over image of high rise buildings with red circular digital icons dotted around" src="https://cdn.mos.cms.futurecdn.net/koNvE9zmQFam7EYpnGTT9m.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Zscaler)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/phishing/threatlabz-report-the-state-of-encrypted-attacks"><em>Discover where most enterprise defense strategies fall short</em></a></p></div></div><p>“The nature of open source software allowed this vulnerability to be discovered, reported, and addressed in a short period of time due to the diligence and oversight of the community.</p><p>Beyond that, the way that open source packages cycle from “experimental” to “stable” releases meant that the compromised packages were contained to a narrow distribution.”</p><p>As many will recall from XKCD, all modern <a href="https://www.itpro.com/cloud/infrastructure-as-a-service-iaas/361845/practices-for-maximising-the-business-value-of">digital infrastructure</a> is underpinned by the maintainers of obscure <a href="https://www.itpro.com/desktop-software/28858/best-project-management-software">software projects</a> that few people know about, but on which everyone relies.</p><p>This latest incident, which many are warning could have turned out far, far worse, is just the latest reminder of that.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ The future of generative AI lies in open source ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/software/open-source/the-future-of-generative-ai-lies-in-open-source</link>
                                                                            <description>
                            <![CDATA[ The tenets of open source could support AI in areas such as security and ethical development, but major roadblocks might impede progress ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">otbE6RrxwohuuB2uMMH3dW</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/6TnYk7UCnK5uJ4Y74iBeSE-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 25 Mar 2024 11:15:33 +0000</pubDate>                                                                                                                                <updated>Mon, 25 Mar 2024 12:08:40 +0000</updated>
                                                                                                                                            <category><![CDATA[Open Source]]></category>
                                                    <category><![CDATA[Software]]></category>
                                                                                                <author><![CDATA[ george.fitzmaurice@futurenet.com (George Fitzmaurice) ]]></author>                    <dc:creator><![CDATA[ George Fitzmaurice ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/N4xHCjSAXKcijjt3oiQtfc.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/6TnYk7UCnK5uJ4Y74iBeSE-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Open source generative AI concept image showing a digitized human brain elevated over a GPU and circuit board.]]></media:description>                                                            <media:text><![CDATA[Open source generative AI concept image showing a digitized human brain elevated over a GPU and circuit board.]]></media:text>
                                <media:title type="plain"><![CDATA[Open source generative AI concept image showing a digitized human brain elevated over a GPU and circuit board.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/6TnYk7UCnK5uJ4Y74iBeSE-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The <a href="https://www.itpro.com/software/28109/what-is-open-source">open source</a> ecosystem has long been the backbone of the global technology industry, and in the age of generative AI, the situation is no different. Some of the most impressive models out there are open source, such as Mistral AI and Meta’s Llama.</p><p>With the <a href="https://www.itpro.com/strategy/28181/what-is-ai">AI</a> industry growing at an astounding pace, the open source community is well placed to contribute to - and guide - whatever this next generation of technology brings.</p><p>Speaking at a press briefing at <a href="https://www.itpro.com/news/live/kubecon-2024-all-the-latest-news-and-announcements">KubeCon 2024</a>, Jim Zemlin, executive director of the Linux Foundation, touted the wide range of areas in which open source may be able to assist in the development of AI.</p><p>“It might be easier to think about the goal of open source more broadly in generative AI by looking at it from a full stack,” Zemlin said.</p><p>Zemlin worked his way from the <a href="https://www.itpro.com/hardware/368553/how-to-pick-the-best-business-laptop-cpu">CPU</a> level up to the data level of open source and generative AI’s relationship, pointing out the notable headway open source is making along the way.</p><p>On the baseline computing level, the Linux Foundation has created the ‘Unified Acceleration Foundation’ to look a little more closely at the role of open source and <a href="https://www.itpro.com/hardware/30399/what-is-a-gpu">GPUs</a>, while he also mentioned the forward momentum of open source at the foundation model level.</p><p>Perhaps most notably, Zemlin said he believes that open source might be the answer to some of AI’s most pertinent problems, such as <a href="https://www.itpro.com/technology/artificial-intelligence/openais-sam-altman-hallucinations-are-part-of-the-magic-of-generative-ai">hallucinations</a>, security risks, and distinguishing between real and AI-generated content.</p><div  class="fancy-box"><div class="fancy_box-title">MORE FROM KUBECON 2024</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="dGaGsjWEHmDxVrFxFGcERE" name="20240320_091121.jpg" caption="" alt="KubeCon" src="https://cdn.mos.cms.futurecdn.net/dGaGsjWEHmDxVrFxFGcERE.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Future)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/cloud/cloud-security/why-workload-identity-complexity-is-causing-cloud-native-security-headaches">Why workload identity complexity is causing cloud native security headaches</a><a data-analytics-id="inline-link" href="https://www.itpro.com/software/open-source/why-redis-license-changes-arent-the-end-of-the-world-for-open-source">Why Redis license changes aren&apos;t the end of the world for open source</a><a data-analytics-id="inline-link" href="https://www.itpro.com/business/digital-transformation/cicd-comes-into-focus-as-enterprises-ramp-up-application-modernization-efforts">CI/CD comes into focus as enterprises ramp up application modernization efforts</a></p></div></div><p>“Sometimes the answer to problems in tech is more tech, and a lot of people are skeptical of that,” Zemlin said. “But in this case, I think it&apos;s true.”</p><p>“If you look at some of the things around large language models, around AI safety and security, I think this is an area where we&apos;re seeing some good starts,” Zemlin said.</p><p>Speaking to the specific areas in which the open source community could help develop tools to track problems, Zemlin said projects are already underway to assist developers with ‘unlearning’ in a bid to fine tune AI models.</p><p>“We&apos;re already seeing some of these tools in our <a href="https://www.itpro.com/development/open-source/367689/linux-foundation-unveils-world-of-open-source-research-initiative">Linux Foundation</a> AI big data project,” he added.</p><p>Zemlin also drew attention to open source’s commitment to the Coalition for Content Provenance Authority (C2PA), a project which builds on the efforts of the Content Authenticity Initiative (CAI) in establishing a framework for identifying AI-generated content.</p><h2 id="the-open-source-ecosystem-can-do-more-to-support-ai-development">The open source ecosystem can do more to support AI development</h2><p>Zemlin warned, however, that the open source community can be more proactive with regard to AI development. The ecosystem should be more vocal about the role it can play in underpinning safe and responsible development, he suggested. </p><p>“[There’s] a real opportunity for open source to do more,” he said.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED WEBINAR</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="n5Tiup4AxKCZyxH3pobFZX" name="Regain IT and security control_ How Cloudflare’s connectivity cloud tames complexity_listing.jpg" caption="" alt="A webinar screen with contributor images, with  discussions around how to tame IT and security complexities with Cloudflare" src="https://cdn.mos.cms.futurecdn.net/n5Tiup4AxKCZyxH3pobFZX.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Cloudflare)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/cloud/cloud-management/regain-it-and-security-control-how-cloudflares-connectivity-cloud-tames-complexity"><em>Address IT and security challenges</em></a></p></div></div><p>Speaking to <em>ITPro</em> at the conference, Oleksandr Matvitskyy, senior director analyst at Gartner, echoed Zemlin’s comments regarding the role of open source in the future of <a href="https://www.itpro.com/technology/artificial-intelligence-ai/369959/what-is-generative-ai">generative AI</a> development.</p><p>Closer collaboration with the ecosystem and ensuring open source development is prioritized should be a key focus for enterprises, regulators, and governments alike moving forward, Matvitskyy said.</p><p>“I think anything can be done with open source,” he told ITPro.</p><p>“I think [it] has to be every government&apos;s, every regulator&apos;s priority to make sure that AI remains open source,” Matvitskyy added.</p><h2 id="prevalence-of-proprietary-data-could-hamper-progress">Prevalence of proprietary data could hamper progress</h2><p>Roadblocks are standing in the way of open source AI development approaches, however, specifically with regard to AI training. The last 18 months have been fraught with instances of hallucinations and security issues. </p><p>Matvitskyy pointed out that these issues are particularly visible in the operation of AI models.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="Ngxxhe5mfj6G8BsZdNqGA4" name="ChatGPT_GettyImages-1462188008.jpg" caption="" alt="ChatGPT welcome screen and user interface displayed on a laptop screen." src="https://cdn.mos.cms.futurecdn.net/Ngxxhe5mfj6G8BsZdNqGA4.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Getty Images)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/jailbreaking-chatgpt-researchers-swerved-gpt-4s-safety-guardrails-and-made-the-chatbot-detail-how-to-make-explosives-in-scots-gaelic">Researchers swerved GPT-4&apos;s safety guardrails and made the chatbot detail how to make explosives in Scots Gaelic</a></p></div></div><p>“They still hallucinate in their outputs,” Matvitskyy said, “they have no data to learn on - everything is private, everything is protected.”</p><p>Companies often hoard their data, thus limiting the amount of open data available for the training of AI which, fundamentally, is the only way that AI models will develop past whatever their current level of complexity is.</p><p>Mattvitskyy said that around 60% of the data that companies are holding on to is probably “not really important” and could be released into the public domain for the training of AI models.</p><p>“They should be open and the companies should get money … for innovation, for what they actually do, not for what they created thirty years ago,” Matvitskyy said.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Why Redis license changes aren't the end of the world for open source ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/software/open-source/why-redis-license-changes-arent-the-end-of-the-world-for-open-source</link>
                                                                            <description>
                            <![CDATA[ Redis license changes could spark consternation among members of the open source community, but what does this move actually mean? ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">Ft4nkK4pBnewkwWqmdf5hA</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/kkSxF7avnLVjrNeHRABpSa-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 22 Mar 2024 15:59:46 +0000</pubDate>                                                                                                                                <updated>Mon, 25 Mar 2024 11:51:23 +0000</updated>
                                                                                                                                            <category><![CDATA[Open Source]]></category>
                                                    <category><![CDATA[Software]]></category>
                                                                                                <author><![CDATA[ ross.kelly@futurenet.com (Ross Kelly) ]]></author>                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Ross Kelly is ITPro&#039;s News &amp;amp; Analysis Editor, with a keen interest in cyber security, business leadership and emerging technologies.&lt;/p&gt;
&lt;p&gt;He graduated from Edinburgh Napier University in 2016 with a BA (Hons) in Journalism, and joined ITPro in 2022 after four years working in technology conference research.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;In his spare time, Ross enjoys cycling, walking and is an avid reader of history and non-fiction.&lt;/p&gt;
&lt;p&gt;You can contact Ross at ross.kelly@futurenet.com or on &lt;a href=&quot;https://twitter.com/rosswritesetc&quot;&gt;Twitter&lt;/a&gt; and &lt;a href=&quot;https://www.linkedin.com/in/ross-kelly-18a54411a/&quot;&gt;LinkedIn&lt;/a&gt;.&lt;/p&gt; ]]></dc:description>
                                                                                                        <dc:contributor><![CDATA[ George Fitzmaurice ]]></dc:contributor>
                                                                    <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/kkSxF7avnLVjrNeHRABpSa-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Cloud computing concept image showing a cloud symbol attached to separate containers.]]></media:description>                                                            <media:text><![CDATA[Cloud computing concept image showing a cloud symbol attached to separate containers.]]></media:text>
                                <media:title type="plain"><![CDATA[Cloud computing concept image showing a cloud symbol attached to separate containers.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/kkSxF7avnLVjrNeHRABpSa-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Redis has announced changes to its licensing setup that will see the firm adopt a more restrictive <a href="https://www.itpro.com/software">software</a> distribution approach.</p><p>The changes, announced this week by CEO Rowan Trollope, will see Redis releases made available under RSALv2 (Redis Source Available License) and SSPLv1 (Server Side Public License) licenses.</p><p>The dual licensing setup means the company is now adopting a ‘source available’ approach. This marks a departure from the company’s Berkeley Software Distribution (BSD) model, which allows <a href="https://www.itpro.com/software/development/developers-dont-interrupt-us-if-you-want-better-collaboration">developers</a> to freely use <a href="https://www.itpro.com/software/open-source/what-red-hats-source-code-restrictions-mean-for-businesses">source code</a> for commercial purposes.</p><p>‘Source available’ refers to software released under a distribution license that means it can be publicly accessed - and in some cases modified - but with restrictions. This typically allows devs to use code for educational purposes, for example, while preventing them from using source code in a commercial context.</p><p>The changes will take effect from Redis version 7.4, and mean cloud service providers that host Redis solutions will be forced to enter into commercial agreements with the company to use source code.</p><p>Redis said the motivation behind the shift to source available licenses will allow the company to “sustainably provide permissive use” of source code. Trollope noted that, in recent years, the company’s success has created a “unique set of challenges” in terms of commercialization.</p><p>The provider has been sponsoring “the bulk” of development in collaboration with the developer community. However, the majority of commercial sales are “channeled through the largest cloud service providers”, he said.</p><p>Trollope said these providers, which include Microsoft, have essentially “commoditized Redis’ investments”, suggesting that the previous licensing setup was no longer delivering commercial value for the company.</p><p>The move by Redis could spark backlash from the open source community akin to that witnessed last year in the wake of <a href="https://www.itpro.com/software/open-source/analysis-hashicorp-prioritizes-its-business-with-bsl-license-switch-but-community-upset-cannot-be-ignored">HashiCorp licensing changes</a>.</p><p>In August, the company announced plans to change its source code license to the Business Source License (BSL) which prohibits commercial use. The decision was heavily criticized by many across the open source ecosystem.</p><p>HashiCorp said at the time that the reason for the switch was because too many vendors were profiting from the work of open source software projects.</p><h2 id="what-next-for-open-source-after-the-redis-license-changes">What next for open source after the Redis license changes?</h2><p>Speaking exclusively to <em>ITPro </em>from <a href="https://www.itpro.com/news/live/kubecon-2024-all-the-latest-news-and-announcements">KubeCon 2024</a> in Paris, Chris Aniszczyk, CTO at the Cloud Native Computing Foundation (CNCF), appeared to lament the news of the licensing changes - although he’s been somewhat short of time amidst the furor of the conference. </p><p>While the move by Redis is disappointing, Aniszczyk said it’s nothing the community hasn’t seen before. Redis itself has previously made licensing changes, as has <a href="https://www.itpro.com/business-strategy/chief-information-security-officer-ciso/370365/mongodb-ciso-dont-be-afraid-simplify-issues-executives">MongoDB</a> and the aforementioned HashiCorp.</p><p>These situations aren’t the norm though, and shouldn’t be a major cause for concern - especially given the sheer volume of <a href="https://www.itpro.com/development/open-source/369920/350000-open-source-projects-vulnerable-15-year-old-python-bug">open source projects</a> across the global community, Aniszczyk said.</p><p>“There&apos;s a bajillion <a href="https://www.itpro.com/software/28109/what-is-open-source">open source</a> projects out there, right? When the HashiCorp thing happened, we were like, <em>is this a common thing? How often is this happening?</em></p><div  class="fancy-box"><div class="fancy_box-title">RELATED WEBINAR</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="aPCvsA7qmcSLHbfCMUfbrZ" name="Network DDoS Attack Protection_listing.jpg" caption="" alt="A webinar screen with contributor images, on Network DDoS attack protection" src="https://cdn.mos.cms.futurecdn.net/aPCvsA7qmcSLHbfCMUfbrZ.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Cloudflare)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/cloud/cloud-management/network-ddos-attack-protection"><em>Protect your network against DDoS attacks</em></a></p></div></div><p>“We did our investigation and [found] there’s been a few handful of projects that have relicensed from open source to basically what I refer to as ‘source available’.”</p><p>Aniszczyk told ITPro he views the current situation with Redis through the same lens as HashiCorp’s decision - that being that individual circumstances will dictate how an organization approaches licensing.</p><p>In this instance, Redis’ CEO said the move will enable it to streamline the distribution of its technology and redefine its relationship with <a href="https://www.itpro.com/business/policy-and-legislation/us-proposes-new-know-your-customer-restrictions-on-cloud-providers">cloud providers</a>. This aligns with the HashiCorp situation in which it also viewed open source licensing as something that was preventing it from delivering commercial value.</p><p>“I think what happened with these companies is … other people were using the software, maybe they were building products, maybe they were competing with them,” he explained.</p><p>“There&apos;s ways of looking at this, like, oh my gosh, we have this cool open source software, someone took it and is competing with me now and not maybe giving anything back.”</p><p>Open source enables competition that’s good for end users, Aniszczyk said, even if it isn’t always good for companies. Ultimately though, companies should stick to their stance on the matter.</p><p>“If you think that you as an organization developing software should own it all, just don’t be open source,” he said.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ CISA wants closer ties with open source developers to prevent the next Log4Shell ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/software/open-source/cisa-wants-closer-ties-with-open-source-developers-to-stop-the-next-log4shell</link>
                                                                            <description>
                            <![CDATA[ CISA has signaled it wants to foster greater collaboration between industry, regulators, and the open source community ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">W9nRzrt7HQFoBrB3JBgk4G</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/mmz6sSMfACZifkwgKSJ6xZ-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 08 Mar 2024 13:03:42 +0000</pubDate>                                                                                                                                <updated>Mon, 11 Mar 2024 11:34:33 +0000</updated>
                                                                                                                                            <category><![CDATA[Open Source]]></category>
                                                    <category><![CDATA[Software]]></category>
                                                                                                <author><![CDATA[ solomon.klappholz@futurenet.com (Solomon Klappholz) ]]></author>                    <dc:creator><![CDATA[ Solomon Klappholz ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/z2aSrrbwGAyWwinHzGraAP.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Solomon Klappholz is a Staff Writer at ITPro. He has experience writing about the technologies that facilitate industrial manufacturing which led to him developing a particular interest in IT regulation, industrial infrastructure applications, and machine learning.&lt;/p&gt;
&lt;p&gt;Before he joined ITPro, Solomon graduated from the University of Warwick in 2018 with a BA (Hons) in Philosophy, Politics, and Economics which included an intercalated year studying Philosophy at the Erasmus University, Rotterdam.&lt;/p&gt;
&lt;p&gt;Outside of the office, Solomon enjoys reading, visiting new art exhibitions, and playing football.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/mmz6sSMfACZifkwgKSJ6xZ-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[CISA director Jen Easterly delivers a speech during &#039;Kyiv international cyber resilience forum 2024]]></media:description>                                                            <media:text><![CDATA[CISA director Jen Easterly delivers a speech during &#039;Kyiv international cyber resilience forum 2024]]></media:text>
                                <media:title type="plain"><![CDATA[CISA director Jen Easterly delivers a speech during &#039;Kyiv international cyber resilience forum 2024]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/mmz6sSMfACZifkwgKSJ6xZ-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The US <a href="https://www.itpro.com/security/vulnerability/361441/cisa-federal-agencies-cyber-security-patch-deadlines">Cybersecurity & Infrastructure Security Agency</a> (CISA) has <a href="https://www.cisa.gov/news-events/news/cisa-announces-new-efforts-help-secure-open-source-ecosystem" target="_blank">announced</a> new efforts to secure the <a href="https://www.itpro.com/software/28109/what-is-open-source">open source</a> ecosystem, including closer collaboration between regulators and the community.</p><p>The pledge by the cyber agency came during a two-day summit on open source software (OSS) security, with director Jen Easterly highlighting the integral role OSS plays in underpinning <a href="https://www.itpro.com/security/hackers-are-lying-low-in-networks-to-wage-critical-infrastructure-attacks-heres-how-they-do-it">critical services</a> across the US. </p><p>During her opening keynote at the Open Source Software Security Summit, Easterly said the organization has placed an increased focus on OSS security in recent years in the wake of <a href="https://www.itpro.com/security/a-prudent-approach-to-major-security-incidents">major security incidents</a> like <a href="https://www.itpro.com/security/zero-day-exploit/361819/what-is-log4shell-log4j-vulnerability">Log4Shell</a>.</p><p>“We at CISA are particularly focused on OSS security because, as everyone here knows, the vast majority of our critical infrastructure relies on open source software," she said. </p><p>“And while the Log4Shell vulnerability might have been a big wakeup call for many in government, it demonstrated what this community has known and warned about for years: due to its widespread deployment, the exploitation of OSS vulnerabilities becomes more impactful.”</p><p>On 7 March, CISA announced a number of key actions it is taking aimed at securing the <a href="https://www.itpro.com/software/software-supply-chain-attacks-are-rife-this-is-what-developers-need-to-watch-out-for">software supply chain</a>, many of which involve providing more hands-on support for <a href="https://www.itpro.com/621532/open-source-developers-ditch-iphone-for-android">open source developers</a> looking to secure their projects.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="psSDYxBsjQnfNC8Dkqmmog" name="Cyber_security_GettyImages-1599973349.jpg" caption="" alt="Cyber security concept image showing a digitized padlock on a digital interface and circuit board." src="https://cdn.mos.cms.futurecdn.net/psSDYxBsjQnfNC8Dkqmmog.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Getty Images)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/hackers-are-lying-low-in-networks-to-wage-critical-infrastructure-attacks-heres-how-they-do-it">Hackers are lying low in networks to wage critical infrastructure attacks - here’s how they do it</a></p></div></div><p>In particular, the agency will launch a project to improve collaboration and information sharing between open source developers and <a href="https://www.itpro.com/infrastructure">infrastructure</a> operators. </p><p>The agency will also work closely with package <a href="https://www.itpro.com/software/development/359246/how-to-download-from-github">repositories</a> to promote the adoption of the Principles of Package Repository Security.</p><p>Developed by CISA and the <a href="https://www.itpro.com/software/open-source/openssf-malicious-packages-repository-launches-in-bid-to-counter-security-threats">Open Source Security Foundation</a> (OpenSSF) Securing Software Repositories Working Group, the framework outlines voluntary <a href="https://www.itpro.com/security/advancing-your-risk-management-maturity">security maturity</a> levels for package repositories.</p><p>Five of the most popular package repository operators are taking steps to align themselves with the framework, including the Rust Foundation, <a href="https://www.itpro.com/business-strategy/careers-training/356640/how-to-become-a-python-software-developer">Python Software Foundation</a>, Packagist and Composer, Maven Central, and npm. </p><h2 id="cisa-move-is-a-positive-step-for-open-source-security">CISA move is a positive step for open source security</h2><p>The announcement from CISA has been welcomed by <a href="https://www.itpro.com/software/open-source/uk-open-source-ecosystem-can-bridge-growing-tech-industry-skills-gap">industry stakeholders</a> as a positive shift toward a more collaborative joint approach between open source developers and <a href="https://www.itpro.com/security/367741/us-security-emergency-alert-vulnerable-vmware-products">security agencies</a>.</p><p>Mike McGuire, senior software solutions manager at <a href="https://www.itpro.com/security/software-vulnerabilities-are-declining-but-third-party-risks-still-linger">Synopsys</a> Software Integrity Group, said open source maintainers have historically been fairly diligent in keeping their code secure and up to date, but the initiative launched by CISA should help improve things further.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED WHITEPAPER</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="EPV84k3zp9wAMjg9EVwqEC" name="Understanding AI Models to Future-Proof your AppSec Program_listing.jpg" caption="" alt="Dark background with light text that says Understanding AI models to future-proof your AppSec program" src="https://cdn.mos.cms.futurecdn.net/EPV84k3zp9wAMjg9EVwqEC.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Snyk)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/technology/artificial-intelligence/understanding-ai-models-to-future-proof-your-appsec-program"><strong>See the different ways businesses can use AI to futureproof their AppSec program</strong></a></p></div></div><p>“The efforts of the open source community, in concert with CISA as part of this initiative, is indicative of a broader truth, which is that open source project maintainers and stewards generally do an effective job at keeping their code secure, up to date, and of acceptable quality”, he explained.</p><p>“There is no doubt that threat actors have been taking advantage of the inherent trust that we have in open source, so these efforts should go a long way in preventing supply chain attacks from starting at the level of open source project development.”</p><p>McGuire did warn that more needs to be done, however, with regard to businesses ensuring they are responsibly managing open source assets. </p><p>“No matter what is done because of these exercises, no commercial application will be made any more secure if development organizations don’t invest more in managing the open source that they leverage.”</p><p>McGuire explained that the greatest threat to open source security is bad <a href="https://www.itpro.com/security/cyber-attacks/novel-china-linked-linux-backdoor-exploits-organizations-that-fail-to-patch-old-vulnerabilities">patching practices</a> from organizations using third party code.</p><p>“When over 70% of commercial applications have a high-risk open source vulnerability, and the average age of all vulnerabilities is 2.8 years old, it’s clear that the biggest concern is not with the open source community but with the organizations failing to keep up to date with the varying security patching work that the community is doing."</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
            </channel>
</rss>