Javier Perez, Perforce Software | OSS North America 2023
Join Mike Vizard in an interview with Javier Perez, Chief Open Source Evangelist at Perforce Software, as they discuss the evolving landscape of open source software adoption and the increasing need for C-suite oversight in open source program offices. Javier highlights the growing realization among organizations that open source software is critical to their operations, prompting a shift from being mere consumers to active participants in the open source community. He emphasizes the importance of improving open source security best practices, including vulnerability disclosure, and the need for executive oversight to drive education, awareness, and usage of open source initiatives.
Transcript
This is Techstrong tv. Hello, and welcome back to the Open Source Summit in beautiful Vancouver. We're here today with Javier Perez, who's from Perforce, and we're talking about open source software curation and how people are actually using software these days.
Javier, welcome to the show. Thank you, Mike. Great to be here.
I think there was an era of open source that you could equate to maybe free love in the sixties. Everybody was kind of downloading whatever they needed or wanted, and, you know, there are some risks that go with that particular lifestyle, and we're now encountering all that stuff. Are you seeing people kind of being more careful about what open source packages they're using, where they're getting it from and, and, and what drives them to kind of have that level of maturity?
Well, there's, there's a lot more awareness on open source security, and that's for sure, and that's keeps growing. And now at here at Opensource Summit, we are hearing more and more about, uh, that awareness, that making sure that, that you're protected, that you do your security scans. Um, the reality is that, you know, we have so much open source out there that, you know, when you download, when you start using a library, you don't know what it's behind all those dependencies and all those other libraries.
So you just download a package and you, you are assuming that everything else, it's, it's working, doesn't have box, doesn't have security vulnerabilities. So the, the, the awareness and having more, uh, knowledge about open source security has improved. Uh, I also see this, this strength of more disclosure of vulnerabilities, which is a good thing.
People might say, well, now we have a lot more vulnerabilities than ever before. Well, that's because we're disclosing more, right? Because software always had box, always had issues.
Uh, so I, that's a positive trend. Uh, but now the challenge for, for everyone, especially organizations, is to keep up with, you know, the updates, the patches, the fixes. Uh, the other thing that I always tell people is, remember that most of the vulnerabilities and talking about open source most, and I will say 95, 98, 90 9% already have a fix, right?
Because they were disclosed when they were, the smart way to do it is you disclose it with, with the fix, right? So you just have to keep up with the updates with the patches, right? Happened with Lock four J was mentioned several times yesterday or here at, uh, couple of other sessions.
And, uh, it affix was done in a couple of days, right? But the challenge was to make sure that you identify all the applications that have that li that specific library, and then go and patch or fix all that. So why don't we keep up with the releases?
I mean, it seems to me, I talked to folks in there, four or five releases behind, or they never update it ever because they're afraid something's gonna break. What's the issue? Well, first of all, when was the last time you updated your apps on your phone, right?
Last time I turned it on and off, it seemed to automatically do it. So The, the thing with, with open source software, it's, um, Well, first of all, applications, right? There are many applications out there in the industry that were done once, and then they're there, there are legacy, and they just work, right?
And then people come and go, and then the person that knew that code is gone and no one wants to touch the app. So adding the risk of updating, upgrading when you are not familiar with the app, that's a challenge, right? And I work with our, we work with our customers all the time.
When they say, look, we recommend you to go. I mean, you're already several major release versions behind it's time to do it. Oh, no.
I mean, that's gonna be a project. And I mean, GUI js went in of life at the end of 2021, so it's been a year and a half. Uh, the last survey that we did, the state of open source report, about 15% of the respondent said, we still have angulars.
And it's end of life. You know, no updates, not, not nothing. Um, operating systems more challenging, right?
Linear distributions. Santos, uh, Santos, version six, version eight are end of life now, Santos seven, it's coming in of life next year. Um, it is not that easy to go and deploy it and upgrade all your, all your, uh, Linux deployment distributions out there, right?
So it's challenging. And, and, and that's a reality, right? It's, it's, it's, uh, it's not that easy.
You need to resources, you need to test, you need to make sure that everything is properly tested. The lower the layers, the more you have to test on the layers of right. All the way to your application.
So it, it's challenging, right? My Dependencies have dependencies, right? Yeah.
Um, do we need to be more careful about what open source we're using and kind of think it through in terms of not just what the functionality is, but just how supportable is this thing for the long term? Absolutely. And, and there are some great initiatives.
I, I hear a lot about that. And at this event, you know, they talk about, uh, SBOs software, bill of materials, just, just keep up with what you have, making sure that you are up to date, keep up with the upgrades. Um, another um, point from our state of opensource report was that, right?
We ask, what are the major challenges supporting opensource software in your organization? And number one was like keeping up with updates and, uh, and releases. Number two was kind of getting the experience, right, the skills and, and the proficiency, right?
Um, uh, I was just looking at here on the, was mentioning one of the keynotes about the, the latest, uh, Linux Foundation, uh, uh, jobs report. I think there's rename now it's the tech report and still, you know, there's a lack of, uh, expertise, right? It's a great time.
I always say it's a great time to be an engineer. It's a great time to, to know about all these open source technologies because there are plenty of opportunities out, out there. And, and, and that's a challenge, right?
So going back to my previous comment, there's, I see a lot more awareness. But yes, there is a challenge. You have to have, you have to be op, keep an eye on your open source.
Uh, and then some of the more mature organizations mature in the use of open source software. Uh, they're moving in the direction of open source program offices, suppose basically create governance around everything relates to open source, and that that goes long way to help them with, with security concerns and, and functionality performance and other things. Unfortunately, it seems like most organizations, you know, we're still early on sbo, so nobody seems to know what's running and where and when and what version.
Mm-hmm. So does that just make the whole security equation a nightmare? Because when there is a zero day vulnerability, nobody knows where anything is.
Yeah. Well, I, I, I have actually an optimistic point of view here, and I think we, we are improving a lot. Uh, I think all those initiatives around, uh, generating SBOs have grown, right?
You don't have to have a open source program office to just generate an, an SBO or demand from your vendors, even outside open source demand from your vendors to issue an, an sbo. And when there's an issue, at least you have an inventory where to go back and say, well, I happen to have an issue on this and this and this other applications, I think things are, are, are improving. Um, I think the, the, you know, some of the things that we saw in organizations like creating a security office and having the role of, uh, chief information security officers, I think that, and the open source, we're moving in that direction as well.
Getting more organized, more strategic about the use of open source. And they're very tied together with security, right? So not only on just developing code in the open, but also on the security side.
You guys will curate open source packages on behalf of organizations Who makes that decision? Cuz it seems like the developers tend to just go find the raw bit somewhere and download it in a way they go, so who kind of wakes up one morning and says, you know, we need to have a more, um, curated approach to what open source software we're using. Yeah, I mean, qra, it's, it's an interesting approach, right?
It gives you peace of mind bringing software from a trusted source, right? Mm-hmm. That's, that's, that's what it is, right?
A bit of a insurance policy. It's saying, well, this is a trusted source. You see a hundred percent guarantee that it's gonna be com, uh, you know, uh, without box, without abilities, well, no, but you wanna have a trusted source.
Now, there are others that will challenge that and say, Hey, open source is moving so fast how you are not gonna keep up with curated list, right? If you ask your developers just to, just to use libraries from that specific repository, you're gonna slow them down, right? And, and, and, and that's the, those are the balances that, you know, organizations have to have to go.
Uh, we, we not necessarily do a specific curation, but we have a couple of offerings where we extend the long-term support, meaning after the open source communities end of life, the project, we, uh, we go and address high severity vulnerabilities with patches, uh, that will do an, an angular JS incentive. Are we just flat out going too fast? And maybe we should slow down in the name of safety and security?
Uh, someone told me like, no, we don't roll, we don't roll back, we roll forward. Um, I, I mean, I love this. I mean, for anyone like it's, uh, advocate and passionate about open source.
I love the fact that we move fast and, and I would love to move even faster, right? I mean, we see so many things going on, on, on the AI space and all are built with the, with open source. Like the building blocks are open source, the models might be preparatory, but the, the, the tooling all open source.
Um, I think it's great. And I think that organizations that are very strategic about the, the use of open source, they become the experts on those projects and they can go even faster, right? And then they can contribute back and everyone benefits from that.
Now, the maintainers of these open source packages, you know, I mean, not everything is Linux, right? Sometimes it's just two guys hanging out. What is the, how do we incentivize those folks to actually go and create a patch when there's an issue?
Yeah. Or go address some problem because they're not getting paid and they have lives and things they need to do that don't involve, you know, your new vulnerability discovered in some software that they never asked you to use in the first place. Yeah, no, I mean, that, that's one of the main, uh, challenges in, in the open source space.
And, and, you know, in conference like this, we talked about those, those things. Uh, the, the recent, um, uh, initiatives by the open source software Security foundation, open ssf with some of the top, uh, major tech, uh, organizations. One of the, they have 10 streams of initiatives.
One of them, or actually a couple of them are about looking at those like the top 10,000 open source projects and look at their security best practices, have having funding and say, well, how can we fund, how can we pay some of the, the maintainers? Um, I think we are in a different era in open source where it's sponsored by, uh, organizations, right? And it doesn't have to be the major tech organizations that we all know.
Now it's banks and it's, uh, you know, financial industries and, and, um, you know, what you consider hardware vendors, you know, they are, um, sponsoring and, and adding, you know, resources to some of these communities because they know that, you know, these maintainers, especially the ones that, you know, maintain some of the critical open source that are dependencies for not hundreds, but sometimes thousands of other projects, you know, something happens there. There's a big issue, right? So I think there's a, as a industrywide there's a recognition of that issue.
And, you know, perhaps slowly, but we're, we're looking into doing more sponsorships. I mean, I've been in, in my role, I've been, you know, trying to go on, let's say, well, let's, how can we sponsor some of the communities, some of the foundations? Uh, we work with osi, we work with, uh, Alma Linux Foundation, we are Rock Linux Foundation, we work with small departments.
So should organizations take an inventory of the open source software they're using and then determine that maybe that's where they should get involved in kind of either contribute something financially or some code or even documentation. I mean, is there a responsibility here? Yeah.
And first of all, it's, it's not a one time thing. They have to run that inventory all the time, right? Mm-hmm.
And that's the generation of software built materials. And that's, those are the companies that, that are, that we're calling that they become more mature in the use of open source when they do that, when what you just said, basically. Alright, well let's, let's see what's critical here.
And if our business depends on this software, and this software depends on this two or five or 10, uh, open source projects, why don't we sponsor help that? And by the way, why don't we have our engineers becoming experts and contributors on those technologies, right? The challenging of the challenge of having, uh, the skills and the proficiency on, on the technologies will you address that if you are part of those communities.
So we see many of the companies, uh, moving in that direction. And, you know, hopefully in next year's, uh, survey, we can see a lot more, uh, open source program offices and a lot more initiatives like that. What is the role of the government in all of this?
I mean, a former president once said, the nine most dangerous words in English language are, hello, I'm from the government and I'm here to help. Yeah. No, I mean, there's a whole set of initiatives, uh, at least in the us well actually in the European Union as well, and in the uk, uh, where government is stepping in, right?
And especially around security. And, and you know, I'm not go, I forgot who, but I I'm gonna quote someone I forgot now they who to quote. But, uh, they say, look, when when you can't regulate yourself, government is gonna go and regulate for you, right?
And, uh, we see those initiatives. Uh, the, the most recent, um, uh, cybersecurity strategy, this is the most recent, uh, open support, uh, open source security act, which hasn't passed, uh, as a law yet. But they have initiatives, a lot of that.
It's about, uh, forcing government agencies to generate serviceable materials to have, uh, security documented, the security processes, their security posture, uh, even, even actually on the cybersecurity, uh, strategy, even for the first time saying, well, as a vendor you are liable if something happens around securities, you better make sure that you have all your processes and you make sure that what you deliver, it's secure. There's another initiative, I just wrote a blog post about that. That's how I have it a little bit fresh about, um, uh, medical devices.
There's also guidance from the FDA now to say, you have, you have to have, uh, security controls. You have to run your materials for anything that you produce that goes into a medical device. Mm-hmm.
Right? How critical is a medical device Is in effect the entire open source community now embracing some form of DevSecOps as a result. I mean, it seems like we're doing this at a profound level of scale, but it peel it back.
Each project is the same, same thing every enterprise is doing. Absolutely. And, and by the way, because we all the open source pro, many open source projects are, uh, automating their processes, right?
They're applying DevOps and continuous integrations, continuous delivery, they are delivering more often Goes, Go, goes back to the challenges we were talking about, right? Keeping up with all those releases and all those updates. But yeah, and, and another challenge there is CILs can't, they cannot support all their versions, right?
Because they're moving so fast that they say, well, I cannot go back that far back, you know, two, three years because, you know, I need, I need the resource, I need to focus on, on the latest things. So those are some of the interesting challenges that we see in the communities, just like in the, in organizations, Do we need something that feels like an open source security SWAT team that will drop in anytime there's an issue and, you know, there's, there's somebody I can call when a crisis comes in. Well, that's part of the, uh, open source program offices working together with the security offices within organizations.
And then as an industry, some of these initiatives, uh, that are driven by the open ssf, open source security foundation are, are about also helping with some of the framework, some of the documentation, some of the training. So there are a number of initiatives actually, uh, in, in that direction. And, you know, hopefully they, they take off and there's more adoption.
The key here is more adoption. So what's your advice to the average organization? Should I set up like an open source program office, or should I, uh, get the cybersecurity people involved?
What's the thought process here? Yeah, My recommendation is like, you don't have to set a formal open source program office, right? But you have to have some governance and, and you can start small with one or two people working on, on it.
Uh, start small, but have some, some governance on the use of open source, right? Started finding some PO internal policies about what are you gonna use, how you're gonna use it. Uh, open source is distributed by nature, right?
We have contributors all from all over the world. Uh, but in organizations, it's good to have a central, uh, management or governance of, of all of us. So that, that's my my advice kind of.
You're gonna start small. Identify the open source technologies that you are, that are critical to you, and go and find the support. Find the help, find the, the, or learn the skills, train your, your, your, uh, your employees to be familiar with those critical technologies.
I mean, for example, uh, web infrastructure, right? If something happens with any of the software, web structure, then your websites or your applications, nothing works, right? So we have to pay attention, things like that.
Yeah. All right. Hey folks, you heard it here.
If you're consuming massive amounts of open source software and you're not giving anything back, just remember luny is one of the seven deadly sins. Javier, thanks for being on the show. Thank You.
And we'll be back in a minute.





