{"id":54091,"date":"2024-03-22T15:15:48","date_gmt":"2024-03-22T19:15:48","guid":{"rendered":"https:\/\/sdtimes.com\/?p=54091"},"modified":"2024-03-22T15:15:48","modified_gmt":"2024-03-22T19:15:48","slug":"open-source-in-2024-tackling-challenges-related-to-security-ai-and-long-term-sustainability","status":"publish","type":"post","link":"https:\/\/sdtimes.com\/os\/open-source-in-2024-tackling-challenges-related-to-security-ai-and-long-term-sustainability\/","title":{"rendered":"Open source in 2024: Tackling challenges related to security, AI, and long-term sustainability"},"content":{"rendered":"<p><span style=\"font-weight: 400;\">The first piece of open source code was published just over 70 years ago, and now open-source software finds itself in almost every application that exists today.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">A <\/span><a href=\"https:\/\/www.synopsys.com\/blogs\/software-security\/open-source-trends-ossra-report.html\"><span style=\"font-weight: 400;\">2024 report<\/span><\/a><span style=\"font-weight: 400;\"> from Synopsys found that the average application has over 500 open source components in it, and most recent industry reports show that over 95% of codebases contain open source software.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Chris Aniszczyk, CTO of the <\/span><a href=\"https:\/\/www.cncf.io\/\"><span style=\"font-weight: 400;\">Cloud Native Computing Foundation<\/span><\/a><span style=\"font-weight: 400;\"> and VP of developer relations at the Linux Foundation, says that while open source has largely been used in applications in the technology sector, it is expanding into nearly every industry in recent years, such as agriculture and pharma. The Linux Foundation also recently announced <\/span><a href=\"https:\/\/os-climate.org\/about-open-source\/\"><span style=\"font-weight: 400;\">OS-Climate<\/span><\/a><span style=\"font-weight: 400;\"> to tackle climate change problems.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Given the pervasiveness of open source software, let\u2019s look at some of the trends we\u2019ve been seeing across the last year and what we can expect from the open source community this year.\u00a0<\/span><\/p>\n<h5><b>Open source security is now being tackled by governments<\/b><\/h5>\n<p><span style=\"font-weight: 400;\">In general, open source software has been under more of a microscope lately, due to several major security issues over the past decade involving open source components, such as the Log4Shell vulnerability in Log4J.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Both the United States and European Union are now acting to improve the security of open source projects. Within the U.S., President Joe Biden signed an <\/span><a href=\"https:\/\/www.whitehouse.gov\/briefing-room\/presidential-actions\/2021\/05\/12\/executive-order-on-improving-the-nations-cybersecurity\/\"><span style=\"font-weight: 400;\">executive order<\/span><\/a><span style=\"font-weight: 400;\"> on improving cybersecurity, and a part of that is improving open source security. CISA also has <\/span><a href=\"https:\/\/sdtimes.com\/security\/cisa-releases-roadmap-for-securing-open-source-software\/\"><span style=\"font-weight: 400;\">several initiatives<\/span><\/a><span style=\"font-weight: 400;\"> tackling this issue.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">In the EU, the Cyber Resilience Act places stricter security requirements on software. While it doesn\u2019t target open source software specifically, Mike Milinkovich, executive director of the <\/span><a href=\"https:\/\/www.eclipse.org\/org\/foundation\/\"><span style=\"font-weight: 400;\">Eclipse Foundation<\/span><\/a><span style=\"font-weight: 400;\">, says \u201cthere&#8217;s really no way that you can regulate the software industry without regulating open source as some sort of a first order side effect.\u201d<\/span><\/p>\n<p><span style=\"font-weight: 400;\">The Executive Order has made people start thinking more about things like Software Bill of Materials (SBOMs) and vulnerability management (including license management), said Michele Rosen, research director at <\/span><a href=\"https:\/\/www.idc.com\/\"><span style=\"font-weight: 400;\">IDC<\/span><\/a><span style=\"font-weight: 400;\">.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">\u201cIf you&#8217;re installing a package that three dependencies deep is using some sort of GPL software, and you&#8217;re now building software on it, that can be a big legal risk for a company,\u201d she said. \u201cSo one of the things that they&#8217;re finding is that SBOM management systems can help with not only managing the vulnerabilities, but also managing the licenses of the underlying code.\u201d<\/span><\/p>\n<p><span style=\"font-weight: 400;\">According to Aniszczyk, this regulation and push for transparency makes sense, because when we go to the grocery store, for example, we want to know exactly what is in the food we\u2019re buying. Until now, there hasn\u2019t really been an incentive to do that with software.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">\u201cWe just have so much choice in open source land and developers just use what they find on GitHub or GitLab, or all over the internet,\u201d said Aniszczyk. \u201cAnd there&#8217;s just not this maturity that you would find in industries like manufacturing or so on where there&#8217;s like a little bit more scrutiny on the supply chain.\u201d<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Milinkovich is hopeful that a side effect of this regulation is that it entices larger corporations to contribute back to open source more.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">\u201cThere is absolutely no incentive in any part of that relationship for the companies in particular that are using open source to contribute anything back,\u201d said Milinkovich. \u201cThere&#8217;s no reason to; it&#8217;s like \u2018thanks for the free stuff.\u2019 And then we&#8217;re going to put it into our applications in our internal systems. And that&#8217;s great. But regulation changes that equation somewhat. So with regulation, now, they might have a requirement to be able to produce SBOMs, they might have a requirement to demonstrate that the software components that they&#8217;re using in their products that they&#8217;re selling to the US government have to follow the NIST SSVF capabilities.\u201d<\/span><\/p>\n<h5><b>Open source may win the AI race<\/b><\/h5>\n<p><span style=\"font-weight: 400;\">A <\/span><a href=\"https:\/\/www.semianalysis.com\/p\/google-we-have-no-moat-and-neither\"><span style=\"font-weight: 400;\">leaked memo<\/span><\/a><span style=\"font-weight: 400;\"> from a Google staffer last May titled \u201cWe Have No Moat And Neither Does OpenAI\u201d explored the idea that as Google was busy trying to compete with OpenAI, they realized the possibility that neither company would win the AI race: open source could.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">\u201cThe moats memo was basically saying open source guys are getting similar results, or in some ways, even better results. And they&#8217;re advancing at a pace that&#8217;s faster, even with much smaller datasets,\u201d said Milinkovich.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">The memo states: \u201cPlainly put, they are lapping us. Things we consider \u201cmajor open problems\u201d are solved and in people\u2019s hands today \u2026 Open-source models are faster, more customizable, more private, and pound-for-pound more capable. They are doing things with $100 and 13B params that we struggle with at $10M and 540B. And they are doing so in weeks, not months.\u201d<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Some of the large companies are even starting to open source their models, and open source makers are also striking deals with the larger companies, said Rosen.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">For instance, Meta has partially open sourced Llama and Mistral, the French startup producing open source models, recently <\/span><a href=\"https:\/\/sdtimes.com\/ai\/mistral-ai-announces-its-largest-ai-model-yet-and-a-partnership-with-microsoft-for-deployment\/\"><span style=\"font-weight: 400;\">made a deal<\/span><\/a><span style=\"font-weight: 400;\"> with Microsoft.\u00a0\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">\u201cSo I think it&#8217;s pretty clear that open models are going to play a part in this whole AI space one way or the other \u2026 there was a question I would say last year where some people were implying that network effects being what they are, we were all going to sort of converge on a single model and I don&#8217;t see that happening at all, I think there&#8217;s going to be a proliferation,\u201d she said.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Another thing to keep an eye on when it comes to AI is how contributions made using AI will be handled, given the fact that the author might not actually be the author, said Milinkovich.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">He believes that it will become more popular to use tools that check for plagiarism. \u201cThere&#8217;s some options in Copilot, where it will check to see if the code that it has produced is almost identical to code that went into its training data,\u201d he said. \u201cIf there\u2019s something that would be interpreted by a human as looking like plagiarism, you need to try to use those tools to avoid that.\u201d<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Rosen says \u201cthe problem is that particularly with an open source model, it&#8217;s very hard to know how to apply those licenses to let&#8217;s say the training data set or the architecture or even the system prompt or something like that.\u201d<\/span><\/p>\n<h5><b>The impact of tech layoffs on open source<\/b><\/h5>\n<p><span style=\"font-weight: 400;\">According to Rosen, about half of the open source contributors are paid in some way to contribute to open source. That\u2019s why when Google decided to <\/span><a href=\"https:\/\/www.reversinglabs.com\/blog\/google-open-source-staffer-layoffs-put-our-software-supply-chain-security-at-risk\"><span style=\"font-weight: 400;\">lay off<\/span><\/a><span style=\"font-weight: 400;\"> its open source division last year, it made some waves.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Google wasn\u2019t the only one; According to <\/span><a href=\"https:\/\/news.crunchbase.com\/startups\/tech-layoffs\/\"><span style=\"font-weight: 400;\">Crunchbase\u2019s layoff tracker<\/span><\/a><span style=\"font-weight: 400;\">, 191,000 tech workers lost their jobs in 2023 and as of March 8th, another 31,000 had already been laid off this year.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">However, despite the layoffs, data from the <\/span><a href=\"https:\/\/opensourceindex.io\/\"><span style=\"font-weight: 400;\">Open Source Contributor Index<\/span><\/a><span style=\"font-weight: 400;\"> reveals the number of active contributors from top tech companies (including Google) went up every single month in 2023.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">\u201cIt&#8217;s true that obviously some of the open source, commercial software leaders were subject to layoffs,\u201d said Rosen. \u201cAnd even though we know that there must have been some developers laid off who were contributing to open source projects, it&#8217;s important to put those layoffs in context. The losses represented a relative minority of the hiring that had taken place for the two or three previous years, so the overall impact, it&#8217;s not something that I&#8217;ve seen or that I have a sense that there has been a drain.\u201d<\/span><\/p>\n<h5><b>How to sustain open-source projects long-term<\/b><\/h5>\n<p><span style=\"font-weight: 400;\">Long-term sustainability of open source projects is another thing that has gotten more attention over the past few years. There were several examples of popular projects changing the license or business model of their projects in the last year. For instance, HashiCorp switched Terraform from MPL v2 to the Business Source License last year, and earlier this year, Buoyant <\/span><a href=\"https:\/\/linkerd.io\/2024\/02\/21\/announcing-linkerd-2.15\/\"><span style=\"font-weight: 400;\">announced<\/span><\/a><span style=\"font-weight: 400;\"> that stable Linkerd releases would only go out to Enterprise users. Also, Red Hat had <\/span><a href=\"https:\/\/www.redhat.com\/en\/blog\/furthering-evolution-centos-stream\"><span style=\"font-weight: 400;\">previously announced<\/span><\/a><span style=\"font-weight: 400;\"> that its RHEL releases would only be available through CentOS Stream, which upset many in the open source community.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">These aren\u2019t isolated incidents over the last year, however; A number of other open source projects have <\/span><a href=\"https:\/\/en.wikipedia.org\/wiki\/List_of_formerly_open-source_or_free_software\"><span style=\"font-weight: 400;\">changed their licenses<\/span><\/a><span style=\"font-weight: 400;\"> over the years, including Akka, CockroachDB, Elasticsearch, MongoDB, Redis, and more.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Aniszczyk believes that because of the backlash companies faced, this isn\u2019t going to be a common occurrence for open-source projects. \u201cI think that&#8217;s going to happen less because of how much pain it caused them, like they lost a lot of community trust,\u201d he said, speaking of HashiCorp.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Rosen says that she believes companies are starting to think more about the long-term strategy of a project than they used to.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">\u201c[They\u2019re] maybe being a little bit more active in diversifying the management and really trying to think about a longer term strategy,\u201d she said. \u201cWhereas I think a lot of open source projects are launched sort of in the innovation mindset, and maybe don&#8217;t think about longer term governance. If this project becomes successful, how are we going to maintain it, what&#8217;s going to happen?\u201d<\/span><\/p>\n<p><span style=\"font-weight: 400;\">A <\/span><a href=\"https:\/\/www.hbs.edu\/ris\/Publication%20Files\/24-038_51f8444f-502c-4139-8bf2-56eb4b65c58a.pdf\"><span style=\"font-weight: 400;\">paper published<\/span><\/a><span style=\"font-weight: 400;\"> in January by the Harvard Business School revealed that 96% of the value of open source is generated by 5% of developers.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">\u201cWe have a relatively small population of people that, frankly, society is depending upon,\u201d said Milinkovich. \u201cAnd, you know, how do we make sure that those people don&#8217;t burn out? \u2026 How do we make sure those developers are sustained, but also how are they replaced as they retire and the next generation has to come back in behind them and pick up the mantle of some of these core pieces of infrastructure.\u201d\u00a0<\/span><\/p>\n<h5><b>The value of open source<\/b><\/h5>\n<p><span style=\"font-weight: 400;\">It\u2019s an important problem to solve, because that same Harvard Business School paper valued the demand side of open source software at $8.8 trillion and supply side at $4.15 billion.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">\u201cWe find that firms would need to spend 3.5 times more on software than they currently do if OSS did not exist,\u201d the researchers stated in the report.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Milinkovich believes Harvard\u2019s numbers are an underestimate of the value because they only measured websites and not operating systems.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">\u201cSome of the headlines I&#8217;ve seen make me think they didn&#8217;t actually read the paper, because it&#8217;s like, you know, \u2018open source is worth $8.8 trillion?\u2019 No, they only measured a fraction of the open source ecosystem, right? They only measured websites, and they specifically excluded operating systems. So basically, the economic value of all of the web infrastructure around the planet that we use every day, and open source\u2019s contributions to that is about $8.8 trillion, but that excludes other uses. It excludes operating systems. So it&#8217;s obviously in fact, much, much higher than that.\u201d<\/span><\/p>\n<!-- AddThis Advanced Settings generic via filter on the_content --><!-- AddThis Share Buttons generic via filter on the_content -->","protected":false},"excerpt":{"rendered":"<p>The first piece of open source code was published just over 70 years ago, and now open-source software finds itself in almost every application that exists today.\u00a0 A 2024 report from Synopsys found that the average application has over 500 open source components in it, and most recent industry reports show that over 95% of  &hellip; <a class=\"read-more\" href=\"https:\/\/sdtimes.com\/os\/open-source-in-2024-tackling-challenges-related-to-security-ai-and-long-term-sustainability\/\">continue reading<\/a><!-- AddThis Advanced Settings generic via filter on get_the_excerpt --><!-- AddThis Share Buttons generic via filter on get_the_excerpt --><\/p>\n","protected":false},"author":752,"featured_media":54092,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"om_disable_all_campaigns":false,"cybocfi_hide_featured_image":"","footnotes":"","_links_to":"","_links_to_target":""},"categories":[1],"tags":[143,6460,3568,1532,102,45],"coauthors":[11687],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v23.8 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Open source in 2024: Tackling challenges related to security, AI, and long-term sustainability - SD Times<\/title>\n<meta name=\"description\" content=\"These are the trends we\u2019ve been seeing across the last year and what we can expect from the open source community this year.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/sdtimes.com\/os\/open-source-in-2024-tackling-challenges-related-to-security-ai-and-long-term-sustainability\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Open source in 2024: Tackling challenges related to security, AI, and long-term sustainability - SD Times\" \/>\n<meta property=\"og:description\" content=\"These are the trends we\u2019ve been seeing across the last year and what we can expect from the open source community this year.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/sdtimes.com\/os\/open-source-in-2024-tackling-challenges-related-to-security-ai-and-long-term-sustainability\/\" \/>\n<meta property=\"og:site_name\" content=\"SD Times\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/SDTimesD2\" \/>\n<meta property=\"article:published_time\" content=\"2024-03-22T19:15:48+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/sdtimes.com\/wp-content\/uploads\/2024\/03\/girl-2583442_1280.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"853\" \/>\n\t<meta property=\"og:image:height\" content=\"1280\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Jenna Barron\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@sdtimes\" \/>\n<meta name=\"twitter:site\" content=\"@sdtimes\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Jenna Barron\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"9 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/sdtimes.com\/os\/open-source-in-2024-tackling-challenges-related-to-security-ai-and-long-term-sustainability\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/sdtimes.com\/os\/open-source-in-2024-tackling-challenges-related-to-security-ai-and-long-term-sustainability\/\"},\"author\":{\"name\":\"Jenna Barron\",\"@id\":\"https:\/\/sdtimes.com\/#\/schema\/person\/f2524e55ae19da07ea3613577da9f786\"},\"headline\":\"Open source in 2024: Tackling challenges related to security, AI, and long-term sustainability\",\"datePublished\":\"2024-03-22T19:15:48+00:00\",\"dateModified\":\"2024-03-22T19:15:48+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/sdtimes.com\/os\/open-source-in-2024-tackling-challenges-related-to-security-ai-and-long-term-sustainability\/\"},\"wordCount\":1803,\"publisher\":{\"@id\":\"https:\/\/sdtimes.com\/#organization\"},\"image\":{\"@id\":\"https:\/\/sdtimes.com\/os\/open-source-in-2024-tackling-challenges-related-to-security-ai-and-long-term-sustainability\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/sdtimes.com\/wp-content\/uploads\/2024\/03\/girl-2583442_1280.jpg\",\"keywords\":[\"AI\",\"CNCF\",\"Eclipse Foundation\",\"IDC\",\"open source\",\"security\"],\"articleSection\":[\"Latest News\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/sdtimes.com\/os\/open-source-in-2024-tackling-challenges-related-to-security-ai-and-long-term-sustainability\/\",\"url\":\"https:\/\/sdtimes.com\/os\/open-source-in-2024-tackling-challenges-related-to-security-ai-and-long-term-sustainability\/\",\"name\":\"Open source in 2024: Tackling challenges related to security, AI, and long-term sustainability - SD Times\",\"isPartOf\":{\"@id\":\"https:\/\/sdtimes.com\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/sdtimes.com\/os\/open-source-in-2024-tackling-challenges-related-to-security-ai-and-long-term-sustainability\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/sdtimes.com\/os\/open-source-in-2024-tackling-challenges-related-to-security-ai-and-long-term-sustainability\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/sdtimes.com\/wp-content\/uploads\/2024\/03\/girl-2583442_1280.jpg\",\"datePublished\":\"2024-03-22T19:15:48+00:00\",\"dateModified\":\"2024-03-22T19:15:48+00:00\",\"description\":\"These are the trends we\u2019ve been seeing across the last year and what we can expect from the open source community this year.\",\"breadcrumb\":{\"@id\":\"https:\/\/sdtimes.com\/os\/open-source-in-2024-tackling-challenges-related-to-security-ai-and-long-term-sustainability\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/sdtimes.com\/os\/open-source-in-2024-tackling-challenges-related-to-security-ai-and-long-term-sustainability\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/sdtimes.com\/os\/open-source-in-2024-tackling-challenges-related-to-security-ai-and-long-term-sustainability\/#primaryimage\",\"url\":\"https:\/\/sdtimes.com\/wp-content\/uploads\/2024\/03\/girl-2583442_1280.jpg\",\"contentUrl\":\"https:\/\/sdtimes.com\/wp-content\/uploads\/2024\/03\/girl-2583442_1280.jpg\",\"width\":853,\"height\":1280},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/sdtimes.com\/os\/open-source-in-2024-tackling-challenges-related-to-security-ai-and-long-term-sustainability\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/sdtimes.com\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Open source in 2024: Tackling challenges related to security, AI, and long-term sustainability\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/sdtimes.com\/#website\",\"url\":\"https:\/\/sdtimes.com\/\",\"name\":\"SD Times\",\"description\":\"Software Development News\",\"publisher\":{\"@id\":\"https:\/\/sdtimes.com\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/sdtimes.com\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/sdtimes.com\/#organization\",\"name\":\"SD Times\",\"url\":\"https:\/\/sdtimes.com\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/sdtimes.com\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/sdtimes.com\/wp-content\/uploads\/2014\/05\/deafaultlogo.png\",\"contentUrl\":\"https:\/\/sdtimes.com\/wp-content\/uploads\/2014\/05\/deafaultlogo.png\",\"width\":225,\"height\":90,\"caption\":\"SD Times\"},\"image\":{\"@id\":\"https:\/\/sdtimes.com\/#\/schema\/logo\/image\/\"},\"sameAs\":[\"https:\/\/www.facebook.com\/SDTimesD2\",\"https:\/\/x.com\/sdtimes\",\"https:\/\/www.linkedin.com\/company\/sdtimes\/\"]},{\"@type\":\"Person\",\"@id\":\"https:\/\/sdtimes.com\/#\/schema\/person\/f2524e55ae19da07ea3613577da9f786\",\"name\":\"Jenna Barron\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/sdtimes.com\/#\/schema\/person\/image\/b4be3423b187642936e62f121111345e\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/b128943929626cdcafccbac86bd306f9?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/b128943929626cdcafccbac86bd306f9?s=96&d=mm&r=g\",\"caption\":\"Jenna Barron\"},\"description\":\"Jenna Barron is News Editor of SD Times.\",\"url\":\"https:\/\/sdtimes.com\/author\/jennifer-sargent\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Open source in 2024: Tackling challenges related to security, AI, and long-term sustainability - SD Times","description":"These are the trends we\u2019ve been seeing across the last year and what we can expect from the open source community this year.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/sdtimes.com\/os\/open-source-in-2024-tackling-challenges-related-to-security-ai-and-long-term-sustainability\/","og_locale":"en_US","og_type":"article","og_title":"Open source in 2024: Tackling challenges related to security, AI, and long-term sustainability - SD Times","og_description":"These are the trends we\u2019ve been seeing across the last year and what we can expect from the open source community this year.","og_url":"https:\/\/sdtimes.com\/os\/open-source-in-2024-tackling-challenges-related-to-security-ai-and-long-term-sustainability\/","og_site_name":"SD Times","article_publisher":"https:\/\/www.facebook.com\/SDTimesD2","article_published_time":"2024-03-22T19:15:48+00:00","og_image":[{"width":853,"height":1280,"url":"https:\/\/sdtimes.com\/wp-content\/uploads\/2024\/03\/girl-2583442_1280.jpg","type":"image\/jpeg"}],"author":"Jenna Barron","twitter_card":"summary_large_image","twitter_creator":"@sdtimes","twitter_site":"@sdtimes","twitter_misc":{"Written by":"Jenna Barron","Est. reading time":"9 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/sdtimes.com\/os\/open-source-in-2024-tackling-challenges-related-to-security-ai-and-long-term-sustainability\/#article","isPartOf":{"@id":"https:\/\/sdtimes.com\/os\/open-source-in-2024-tackling-challenges-related-to-security-ai-and-long-term-sustainability\/"},"author":{"name":"Jenna Barron","@id":"https:\/\/sdtimes.com\/#\/schema\/person\/f2524e55ae19da07ea3613577da9f786"},"headline":"Open source in 2024: Tackling challenges related to security, AI, and long-term sustainability","datePublished":"2024-03-22T19:15:48+00:00","dateModified":"2024-03-22T19:15:48+00:00","mainEntityOfPage":{"@id":"https:\/\/sdtimes.com\/os\/open-source-in-2024-tackling-challenges-related-to-security-ai-and-long-term-sustainability\/"},"wordCount":1803,"publisher":{"@id":"https:\/\/sdtimes.com\/#organization"},"image":{"@id":"https:\/\/sdtimes.com\/os\/open-source-in-2024-tackling-challenges-related-to-security-ai-and-long-term-sustainability\/#primaryimage"},"thumbnailUrl":"https:\/\/sdtimes.com\/wp-content\/uploads\/2024\/03\/girl-2583442_1280.jpg","keywords":["AI","CNCF","Eclipse Foundation","IDC","open source","security"],"articleSection":["Latest News"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/sdtimes.com\/os\/open-source-in-2024-tackling-challenges-related-to-security-ai-and-long-term-sustainability\/","url":"https:\/\/sdtimes.com\/os\/open-source-in-2024-tackling-challenges-related-to-security-ai-and-long-term-sustainability\/","name":"Open source in 2024: Tackling challenges related to security, AI, and long-term sustainability - SD Times","isPartOf":{"@id":"https:\/\/sdtimes.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/sdtimes.com\/os\/open-source-in-2024-tackling-challenges-related-to-security-ai-and-long-term-sustainability\/#primaryimage"},"image":{"@id":"https:\/\/sdtimes.com\/os\/open-source-in-2024-tackling-challenges-related-to-security-ai-and-long-term-sustainability\/#primaryimage"},"thumbnailUrl":"https:\/\/sdtimes.com\/wp-content\/uploads\/2024\/03\/girl-2583442_1280.jpg","datePublished":"2024-03-22T19:15:48+00:00","dateModified":"2024-03-22T19:15:48+00:00","description":"These are the trends we\u2019ve been seeing across the last year and what we can expect from the open source community this year.","breadcrumb":{"@id":"https:\/\/sdtimes.com\/os\/open-source-in-2024-tackling-challenges-related-to-security-ai-and-long-term-sustainability\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/sdtimes.com\/os\/open-source-in-2024-tackling-challenges-related-to-security-ai-and-long-term-sustainability\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/sdtimes.com\/os\/open-source-in-2024-tackling-challenges-related-to-security-ai-and-long-term-sustainability\/#primaryimage","url":"https:\/\/sdtimes.com\/wp-content\/uploads\/2024\/03\/girl-2583442_1280.jpg","contentUrl":"https:\/\/sdtimes.com\/wp-content\/uploads\/2024\/03\/girl-2583442_1280.jpg","width":853,"height":1280},{"@type":"BreadcrumbList","@id":"https:\/\/sdtimes.com\/os\/open-source-in-2024-tackling-challenges-related-to-security-ai-and-long-term-sustainability\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/sdtimes.com\/"},{"@type":"ListItem","position":2,"name":"Open source in 2024: Tackling challenges related to security, AI, and long-term sustainability"}]},{"@type":"WebSite","@id":"https:\/\/sdtimes.com\/#website","url":"https:\/\/sdtimes.com\/","name":"SD Times","description":"Software Development News","publisher":{"@id":"https:\/\/sdtimes.com\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/sdtimes.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/sdtimes.com\/#organization","name":"SD Times","url":"https:\/\/sdtimes.com\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/sdtimes.com\/#\/schema\/logo\/image\/","url":"https:\/\/sdtimes.com\/wp-content\/uploads\/2014\/05\/deafaultlogo.png","contentUrl":"https:\/\/sdtimes.com\/wp-content\/uploads\/2014\/05\/deafaultlogo.png","width":225,"height":90,"caption":"SD Times"},"image":{"@id":"https:\/\/sdtimes.com\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/SDTimesD2","https:\/\/x.com\/sdtimes","https:\/\/www.linkedin.com\/company\/sdtimes\/"]},{"@type":"Person","@id":"https:\/\/sdtimes.com\/#\/schema\/person\/f2524e55ae19da07ea3613577da9f786","name":"Jenna Barron","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/sdtimes.com\/#\/schema\/person\/image\/b4be3423b187642936e62f121111345e","url":"https:\/\/secure.gravatar.com\/avatar\/b128943929626cdcafccbac86bd306f9?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/b128943929626cdcafccbac86bd306f9?s=96&d=mm&r=g","caption":"Jenna Barron"},"description":"Jenna Barron is News Editor of SD Times.","url":"https:\/\/sdtimes.com\/author\/jennifer-sargent\/"}]}},"_links":{"self":[{"href":"https:\/\/sdtimes.com\/wp-json\/wp\/v2\/posts\/54091"}],"collection":[{"href":"https:\/\/sdtimes.com\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/sdtimes.com\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/sdtimes.com\/wp-json\/wp\/v2\/users\/752"}],"replies":[{"embeddable":true,"href":"https:\/\/sdtimes.com\/wp-json\/wp\/v2\/comments?post=54091"}],"version-history":[{"count":1,"href":"https:\/\/sdtimes.com\/wp-json\/wp\/v2\/posts\/54091\/revisions"}],"predecessor-version":[{"id":54093,"href":"https:\/\/sdtimes.com\/wp-json\/wp\/v2\/posts\/54091\/revisions\/54093"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/sdtimes.com\/wp-json\/wp\/v2\/media\/54092"}],"wp:attachment":[{"href":"https:\/\/sdtimes.com\/wp-json\/wp\/v2\/media?parent=54091"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/sdtimes.com\/wp-json\/wp\/v2\/categories?post=54091"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/sdtimes.com\/wp-json\/wp\/v2\/tags?post=54091"},{"taxonomy":"author","embeddable":true,"href":"https:\/\/sdtimes.com\/wp-json\/wp\/v2\/coauthors?post=54091"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}