Google unveils new Assured Open Source Software service
New offering aims to protect enterprise customers using the same end-to-end security capabilities that Google uses for its own OSS portfolio


Google has announced its new Assured Open Source Software service as part of the tech giant’s drive to help organizations strengthen their OSS supply chain.
Expected to enter Preview in Q3, the Google Cloud product has been designed to enable enterprises and public sector users of open-source software to easily incorporate the same OSS packages that Google uses in its developer workflows.
RELATED RESOURCE
“Assured OSS lets organizations benefit from Google’s extensive security experience and can reduce their need to develop, maintain, and operate complex processes to secure their open source dependencies,” Google said in a blog post.
The offering forms part of Google’s efforts to help make the open-source software ecosystem more secure. Packages curated by the Assured OSS service will be regularly scanned, analyzed, and fuzz-tested for vulnerabilities, while corresponding enriched metadata will incorporate Container/Artifact Analysis data.
They will also be built with Cloud Build, including evidence of verifiable SLSA-compliance, verifiably signed by Google, and distributed from a secure and protected Artefact Registry.
Ultimately, Google said it is aiming to centralize control and actively secure each stage of the software supply chain for an open-source dependency.
“Assured OSS allows enterprise customers to directly benefit from the in-depth, end-to-end security capabilities and practices we apply to our own OSS portfolio by providing access to the same OSS packages that Google depends on,” the company added.
ChannelPro Newsletter
Stay up to date with the latest Channel industry news and analysis with our twice-weekly newsletter
“Users will also be able to submit packages from their own OSS portfolio to be secured and managed through the Google Cloud managed service.”
Additionally, Google Cloud has announced a new collaborative effort with cybersecurity firm Snyk to further help developers understand their open source dependencies, as well as use Assured OSS to reduce their risk.
Assured OSS will be natively integrated into Snyk solutions for joint customers to use wherever they are developing code, Google said, while Snyk vulnerabilities, triggering actions, and remediation recommendations will be available within Google Cloud security and software development life cycle tools.
“The collaboration can help developers reduce the possibility of deploying open-source software with critical vulnerabilities, more quickly identify associated impact of vulnerabilities, better eliminate new threat exposures, and increase automation of their remediation activities,” Google explained.
Dan is a freelance writer and regular contributor to ChannelPro, covering the latest news stories across the IT, technology, and channel landscapes. Topics regularly cover cloud technologies, cyber security, software and operating system guides, and the latest mergers and acquisitions.
A journalism graduate from Leeds Beckett University, he combines a passion for the written word with a keen interest in the latest technology and its influence in an increasingly connected world.
He started writing for ChannelPro back in 2016, focusing on a mixture of news and technology guides, before becoming a regular contributor to ITPro. Elsewhere, he has previously written news and features across a range of other topics, including sport, music, and general news.
-
Global cybersecurity spending is set to rise 12% in 2025 – here are the industries ramping up investment
News Global cybersecurity spending is expected to surge this year, fueled by escalating state-sponsored threats and the rise of generative AI, according to new analysis from IDC.
By Ross Kelly Published
-
Google Cloud is leaning on all its strengths to support enterprise AI
Analysis Google Cloud made a big statement at its annual conference last week, staking its claim as the go-to provider for enterprise AI adoption.
By Rory Bathgate Published
-
What the US-China chip war means for the tech industry
In-depth With China and the West at loggerheads over semiconductors, how will this conflict reshape the tech supply chain?
By James O'Malley Published
-
The Forrester Wave™: Third party risk management platforms
Whitepaper The 12 providers that matter the most and how they stack up
By ITPro Published
-
Apple to shift MacBook production to Vietnam in further step away from China
News The plan has been reportedly been worked on for two years, with the tech giant already having a test production site in the country
By Zach Marzouk Published
-
Food and beverage traceability
Whitepaper Understanding food and beverage manufacturing compliance and traceability
By ITPro Published
-
Ensuring compliance with the National Bioengineered Food Disclosure Standard (NBFDS)
Whitepaper How food manufacturers can enhance traceability with technology to be compliant
By ITPro Published
-
The future of manufacturing
Whitepaper Digitally transform your business and get ready for Industry 4.0
By ITPro Published
-
Microsoft targets optimised supply chain investments with new platform launch
News Microsoft's new Supply Chain Platform fully harnesses Microsoft cloud to help businesses improve supply chain agility and resilience
By Daniel Todd Published
-
Micron to invest historic $100 billion in NY semiconductor site
News Construction on the site will commence in 2024, with output expected in the late 2020s
By Rory Bathgate Published