Home Content News Eclipse Foundation And OWASP Launch Open Source Security Alliance

Eclipse Foundation And OWASP Launch Open Source Security Alliance

0
1
Eclipse Foundation Logo
Eclipse Foundation Logo

The Eclipse Foundation and OWASP have joined forces to help open source projects strengthen security practices and prepare for the EU Cyber Resilience Act through shared guidance, resources, and industry collaboration.

The Eclipse Foundation and the Open Worldwide Application Security Project (OWASP) have signed a Memorandum of Understanding (MoU) to strengthen open source security and help organisations prepare for the European Union’s Cyber Resilience Act (CRA). The partnership combines the Eclipse Foundation’s expertise in open source governance, industry collaboration, and regulatory readiness with OWASP’s application security projects, standards, education, and community.

The collaboration will develop practical resources for open source maintainers, software stewards, manufacturers, and development teams to strengthen security practices and meet evolving regulatory requirements. It also aims to reduce fragmentation across the open source ecosystem by providing coordinated security guidance and regulatory readiness support.

The announcement comes as AI accelerates both software development and vulnerability discovery, increasing the urgency for stronger security across open source software. The CRA introduces mandatory cybersecurity requirements for products with digital elements, including those that use or depend on open source software. Its vulnerability and incident reporting obligations for manufacturers take effect on 11 September 2026.

The regulation also formally recognises open source software stewards as participants in the software supply chain, assigning responsibilities for secure development, vulnerability management, transparency, and ecosystem cooperation.

“Open source is critical digital infrastructure, but responsibility for securing it is distributed across a complex global ecosystem,” said Mike Milinkovich, Executive Director of the Eclipse Foundation.

Andrew van der Stock, Executive Director of the OWASP Foundation, added: “Security guidance only makes a difference when developers, maintainers, and organisations can put it into practice.”

LEAVE A REPLY

Please enter your comment!
Please enter your name here