SOS.dev initiative will combat software supply chain attacks by encouraging researchers to suggest security improvements to key projects. . A new program is aiming to reward developers and security researchers who make improvements to critical infrastructure based on open source technology. The Secure Open Source Rewards ( SOS.dev ) scheme will be broader than current bug bounty programs, according to its backers. The program will “harden critical open source projects” and help protect against application and software supply chain attacks by encouraging researchers and developers to suggest security improvements. Rewards range from $505 for small improvements up to $10,000 or more for “complicated, high-impact and lasting improvements that almost certainly prevent major vulnerabilities”. . A fresh initiative seeks to incentivize programmers and cybersecurity experts who enhance vital open-source endeavors.. Secure Open Source, Developer Rewards, Software Security, Supply Chain Protection. . LinuxSecurity.com Team
Google said Wednesday it plans to reward developers for developing proactive security improvements for some of the most widely used open-source software programs.. The program aims to "improve the security of key third-party software critical to the health of the entire Internet," wrote Michal Zalewski of Google's Security Team. Rewards will range between US$500 to $3,133.70, he wrote. The link for this article located at Network World is no longer available. . In an effort to bolster the safety of vital open-source applications on the web, Google intends to provide incentives to developers who contribute to improving their security.. Security Enhancement, Open Source Funding, Developer Programs. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.