Multiple major banks support OSERA in promoting open-source software repair standards and patch delivery
PR Newswire
58m ago
Ai Focus
FINOS announced at the European Open Source Summit that the Open Source Enterprise Resilience Alliance OSERA has begun operations, with initial funding coming from six Premier members including Deutsche Bank, Goldman Sachs, Morgan Stanley, NatWest, and the Royal Bank of Canada. The alliance claims to have established open source repair and certification standards within 100 days and has provided patches for more than 50 commonly used projects in the Java ecosystem.
Helpful
No.Help

Within 100 days, OSERA welcomed 6 members from Premier, established open-source software vulnerability repair standards tailored for the AI scale, and delivered patches to over 50 commonly used projects within the Java ecosystem.

Prague, October 7th / PRNewswire / -- At the European Open Source Summit ( Open Source Summit Europe ), the Financial Technology Open Source Foundation FINOS (a vertical organization under Linux Foundation targeting the financial services industry) announced today that the Open Source Enterprise Resilience Alliance ( Open Source Enterprise Resiliency Alliance, abbreviated as OSERA ) has officially commenced operations. The initial funding comes from 6 members, including Deutsche Bank, Goldman Sachs, Morgan Stanley, NatWest , and Royal Bank of Canada ( RBC ).

Financial institutions rely heavily on similar open-source software stacks. When a security vulnerability is discovered in one of these widely used projects, banks often have to develop or commission separate solutions to fix it. OSERA addresses this redundant effort by providing financial institutions with a shared, open, and transparent way to identify, fix, and verify vulnerabilities in the open-source software they depend on. Through collaboration, members can reduce duplicate efforts and at the same time help to strengthen the software foundation that supports the financial services industry.

Today's available content

Just a few weeks after announcing its intention to be formed in June, OSERA has delivered:

  • Open standards for vulnerability repair and verification: Within 3 weeks of operation, OSERA released the first version of its patching and verification standards. These standards were developed through collaboration among financial institutions, patch providers, and leaders in open-source infrastructure, specifying the requirements that a repair solution must meet before it can be trusted and widely adopted, helping organizations to adopt such solutions more consistently and with greater confidence.
  • First batch of high-value patch projects: The alliance prioritized delivering security package updates with standard certifications to more than 50 widely used open-source projects within the ecosystems of Spring and Java. These fixes address publicly disclosed security vulnerabilities ( CVE ), and members of OSERA can immediately apply them in production environments. In the future, vendor maintainers will handle newly discovered vulnerabilities according to a software service agreement ( SLA ) that classifies them by severity.

Morgan Stanley's Managing Director, distinguished engineer, and Chairman of the OSERA Fixing Standards Working Group, Dov Katz, stated: "An open and verifiable fixing standard can establish trust in large-scale scenarios. The fact that it has been released so efficiently indicates that the entire industry wants to set its own high standards for what must be proven before patches are used by anyone. This is particularly crucial for achieving true risk mitigation in production environments, as the industry consumes open source from both the community and from multiple patch providers and alliances."

For a list of supported lines and repair standards, please refer to OSERA Prospectus.

AI The Sovereign Option for Open-Source Supply Chain Resilience in the Era

Since financial institutions often rely on the same open-source software, handling vulnerabilities independently can lead to unnecessary costs and duplicate work across the industry. Research shows that one-fifth of financial institutions have independent teams maintaining private versions of the same project, which results in what is known as " fork tax ", increasing maintenance costs and technical risks.

As cyber threats continue to evolve, it has become increasingly important to handle known vulnerabilities quickly and consistently. OSERA provides an open, member-governed approach that enables financial institutions, technology providers, and maintainers to coordinate their vulnerability responses, thereby strengthening the open-source software on which the industry relies.

New resilience regulatory requirements such as DORA, NIS2, and the European Union's Cyber Resilience Act (EU Cyber Resilience Act) are raising the global community's expectations for robust and repeatable methods of managing software vulnerabilities in complex technological ecosystems. OSERA can operate in parallel with existing commercial and community support models: its source code is open, governance is led by members of Linux Foundation, and the standards are open. Recent efforts have also shown that institutions can use this service without altering their current development processes, simply by using existing proxies and package coordinates, without the need to modify CI.

FINOS Executive Director Gabriele Columbro stated: " OSERA transforms open-source resilience from a decentralized internal burden into a collective operational capability, and this year we are proving this with rapid delivery, rather than just staying on the roadmap. Initiatives like Akrites at the upstream level are about safeguarding public resources. OSERA on the other hand, is a regulated downstream process: signed and standard-compliant fixes are delivered to the production environment, with terms set by the industry itself."

Looking to the Future

The alliance has established a target delivery plan up to the end of 2026:

  • At least 80 patches are produced each month. According to the alliance's SLA, the supplier maintenance party Moderne will deliver the patches to a secure platform with isolation gatekeeping, which is built by open-source security experts ControlPlane. The continuous participation of HeroDevs, RapidFort, Sonatype, and Scott Logic will continue to drive the standardization process and accelerate the production and use of supported software versions.
  • In November, the first end-to-end version of the OSERA platform was delivered on Open Source, in, and Finance Forum NY. It is expected that this will continue to reduce the cost per patch, expand the coverage of the software, and enhance the ability to respond to an increased number of AI vulnerabilities.
  • Development is carried out under a project sponsorship model, which allows companies to not only have priority in the common fund pool but also to directly fund and promote the projects they rely on.
  • Cooperates with sister initiatives such as Akrites. OSERA and Linux Foundation's Akrites and other initiatives are highly complementary, which will promote collaboration on repair standards and financial service priorities to maximize value and avoid duplicate efforts.

Designed for participants from various industries

OSERA adopts an open and transparent operating model that is suitable for everyone. Although OSERA addresses a key need of financial institutions, its design is also intended to benefit all participants in the software supply chain, including commercial patch producers, software component analysts, and registry suppliers.

The participation method is as follows:

  • Financial institutions should join OSERA to become members and access a reinforced version of financial services.
  • Open-source infrastructure providers should become members of FINOS, actively contribute to and ultimately adopt the repair standards to ensure that their products meet the needs of the financial industry.
  • Commercial maintenance parties and patch producers should also consider becoming members of FINOS to participate in the development of repair standards, and are eligible to become supplier maintenance parties under the alliance SLA.
  • Anyone can rebuild and repair on GitHub to form a reinforced project route.

Supporting quotes

The Managing Director and distinguished engineer of Deutsche Bank, Peter Thomas, stated: "The advantage of OSERA lies in its ability to be effectively implemented within existing corporate environments. In our preliminary trials, we have demonstrated that banks can pull the enhanced, standard-compliant versions into their existing development pipelines with zero friction through standard corporate proxies. Replacing repetitive internal patching work with shared, highly trusted pipelines is a tremendous benefit for the entire industry."

RBC Vice President, DevOps Person in Charge. Abe Batthish stated: "Many of the things we build run on open-source, and we hope to help maintain their security and ensure sustainability for everyone in the industry." RBC I'm glad to assist in leading this effort. OSERA We are reinforcing the governance of the patch pipeline, requiring suppliers and maintainers to adhere to clear standards and SLA to ensure that every fix meets the same high standards, regardless of who produces them.

About FINOS

FINOS (Fintech Open Source Foundation) collaborates with the financial services industry to jointly build open technologies and standards in order to enhance profitability, increase resilience, and accelerate innovation. FINOS is a trusted community designed by regulated industry participants to address industry-level challenges and drive operational excellence and financial technology innovation. As part of Linux Foundation, FINOS provides a neutral and well-governed platform for open-source collaboration across the industry. FINOS boasts a global community with over 100 member organizations, including large financial institutions, fintech companies, and tech firms, promoting open standards and production-grade open source for the financial sector. This work integrates these technologies and standards into the core workflows, platforms, and policies of financial institutions, making them an indispensable part of the way the industry is built, operated, and evolves. FINOS advocates that the adoption of open source should clearly focus on measurable return on investment.

For more information, please visit www.finos.org.

Media contact: Tosha Ellison, Vice President of Research and Communications: FINOS

[ email protected ]

Tip
$0
Like
0
Save
0
Views 15
CoinMeta reminds readers to view blockchain rationally, stay aware of risks, and beware of virtual token issuance and speculation. All content on this site represents market information or related viewpoints only and does not constitute any form of investment advice. If you find sensitive content, please click“Report”,and we will handle it promptly。
Submit
Comment 0
Hot
Latest
No comments yet. Be the first!
Related
Russia's first batch of registered crypto custody institutions announced; Sberbank joins the list
Russia registers first batch of crypto exchange operators and digital custodian institutions under new crypto regulations, including its largest bank, the Federal Savings Bank of Russia. The bank stated that it has applied for digital custody qualifications and plans to launch its first batch of crypto products on December 1st, initially supporting Bitcoin, Ethereum, and USDT.
Cointelegraph
·2026-10-07 16:33:42
0
Chevron CEO warns diesel export ban is "unwise," claiming it may make the situation worse
Chevron CEO Mike Wirth warns that if the Trump administration pursues a diesel export ban, it would be "unwise" and could make the supply situation worse. He stated that the United States has always been a reliable supplier and should not leave allies and partners wondering about future supplies.
CNBC
·2026-10-07 16:33:38
0
FNB Allows South African users to buy cryptocurrencies such as Bitcoin starting from 10 Rand
South Africa's leading national bank ( FNB ) has launched cryptocurrency trading services through its existing investment platform, allowing customers to buy Bitcoin, Ethereum, XRP, Solana, and USDT starting from 10 Rand. The service is supported by the local exchange VALR, but users are not able to transfer crypto assets in or out of the FNB platform.
crypto.news
·2026-10-07 16:06:11
15
Although Bitcoin has fallen, it has not lost its support; the bullish trend in a stepped manner remains.
Bitcoin fell to around $84,200 on Wednesday, but still remained within the range of $83,000 to $87,000, maintaining the stepwise bullish pattern since July. Analysts said that support around $83,000 is crucial, and if it continues to fall below the $82,000 to $83,000 range, it would indicate a failure of the breakout in September.
CoinDesk
·2026-10-07 16:06:09
15
Stacks Suddenly Becomes the Focus
After the price of STX broke above $0.40, social interest suddenly increased, and the progress of Bitcoin staking on the Stacks network also accelerated. The article states that Genesis Bond was launched in September, and the second round of Bonding Period is expected to begin around October 10th. The market is paying attention to the key resistance level between $0.45 and $0.47.
Coinpedia
·2026-10-07 15:45:07
16
View More