With cyberattacks on the rise, increasing software supply chain visibility is crucial for organizations to proactively identify and mitigate vulnerabilities within their applications and infrastructure. However, handling diverse security data sources such as software bill of materials (SBOMs), critical vulnerabilities and exploits (CVEs), and vendor advisories remains a major challenge due to inconsistent formats, varying levels of detail, and the lack of standardized integration points. Addressing this challenge requires not only better tools, but also open collaboration across the entire ecosystem, demanding transparency and trust.
In an effort to create a more unified and scalable solution for managing security metadata, Red Hat is proud to contribute Trustify to the Graph for Understanding Artifact Composition (GUAC), an Open Source Security Foundation (OpenSSF) incubating project. This contribution reflects Red Hat’s belief that transparent, upstream-first innovation is essential to building security solutions that are more scalable, interoperable, and community-driven. Under the OpenSSF umbrella, end-users will be able to contribute and collaborate to Trustify, helping to grow the project adoption and mature the technology.
Trustify is an open source project, developed by Red Hat, that provides a high-performance, searchable backend for software supply chain metadata. It supports SBOM and advisory formats such as SPDX, CycloneDX, and OSV, and is designed for integration into modern continuous integration and continuous delivery (CI/CD) workflows.
The GUAC open source project aggregates and connects software security metadata into a unified graph. It enables developers and security teams to answer complex questions about software provenance, vulnerability impact, and supply chain integrity at scale.
Managing software security data in the open
Both Trustify and GUAC are designed to tackle the overwhelming challenge of managing vast amounts of software security data that can lead to unmanageable vulnerability handling for security engineers (also known as “alert fatigue”). While Trustify focuses on providing a single, searchable database for SBOMs, CVEs and advisories, GUAC's strength lies in its ability to normalize data from multiple sources into a rich graph database, providing deeper insights and actionable intelligence.
By bringing the two together the GUAC community can enhance its own capabilities, creating a unified effort to address the challenges of consuming, processing, and utilizing supply chain security metadata at scale. This synergy is expected to create a more robust and comprehensive tool for developers and IT security teams. The combined effort is intended to help the open-source community better understand and enhance the security posture of their software, making the entire ecosystem more resilient.
Red Hat believes that the best technologies are built in the open, with transparent processes and a diverse community, where contributions are made not just as code, but as a way to build better systems together. We believe that Trustify as part of GUAC will continue to accelerate its technical evolution and its ability to strengthen the integrity and security of the software supply chain.
We invite anyone interested to try it out, provide feedback and help push the technology forward.
저자 소개
Red Hat is the world’s leading provider of enterprise open source software solutions, using a community-powered approach to deliver reliable and high-performing Linux, hybrid cloud, container, and Kubernetes technologies.
Red Hat helps customers integrate new and existing IT applications, develop cloud-native applications, standardize on our industry-leading operating system, and automate, secure, and manage complex environments. Award-winning support, training, and consulting services make Red Hat a trusted adviser to the Fortune 500. As a strategic partner to cloud providers, system integrators, application vendors, customers, and open source communities, Red Hat can help organizations prepare for the digital future.
채널별 검색
오토메이션
기술, 팀, 인프라를 위한 IT 자동화 최신 동향
인공지능
고객이 어디서나 AI 워크로드를 실행할 수 있도록 지원하는 플랫폼 업데이트
오픈 하이브리드 클라우드
하이브리드 클라우드로 더욱 유연한 미래를 구축하는 방법을 알아보세요
보안
환경과 기술 전반에 걸쳐 리스크를 감소하는 방법에 대한 최신 정보
엣지 컴퓨팅
엣지에서의 운영을 단순화하는 플랫폼 업데이트
인프라
세계적으로 인정받은 기업용 Linux 플랫폼에 대한 최신 정보
애플리케이션
복잡한 애플리케이션에 대한 솔루션 더 보기
가상화
온프레미스와 클라우드 환경에서 워크로드를 유연하게 운영하기 위한 엔터프라이즈 가상화의 미래