Read as article
Banks Band Together in OSERA to Patch Shared Open Source
By @sharedot · · 8 pages
- Programming
- Open Source Security
- Fintech
Major banks backed OSERA, which in 100 days set an AI-scale vulnerability remediation standard and shipped patches for over 50 Java projects.
Banks launch a shared pipeline for open source fixes
At Open Source Summit Europe in Prague, the Fintech Open Source Foundation (FINOS) announced that the Open Source Enterprise Resiliency Alliance (OSERA) is operational, with initial funding from six Premier members including Deutsche Bank, Goldman Sachs, Morgan Stanley, NatWest and Royal Bank of Canada (RBC). According to PR Newswire, the alliance gives financial institutions a shared, open and transparent way to identify, fix and verify vulnerabilities in the open source software they all rely on, rather than each bank separately commissioning fixes for the same widely used projects.
A 100-day sprint produced a standard and 50+ patches
The speed is the surprise. Following only an intent-to-form announcement in June, PR Newswire reports that within 100 days OSERA welcomed six Premier members, released the first version of its patching and attestation standard within three weeks of operation, and delivered secure package updates with standard attestations across more than 50 widely used open source projects in the Spring and Java ecosystems. Those remediations address publicly disclosed CVEs and are available for immediate production use by members, with vendor maintainers handling newly disclosed vulnerabilities under a severity-based SLA going forward.
Ending the 'fork tax' on duplicated patching
The problem OSERA attacks is structural. PR Newswire cites research that 1 in 5 financial institutions maintain separate teams patching private versions of the same open source projects, a 'fork tax' that inflates maintenance cost and technology risk. Dov Katz of Morgan Stanley, chair of the Remediation Standards Working Group, said an open, verifiable standard 'delivers trust at scale,' especially as the industry consumes open source from communities and multiple patch vendors. Deutsche Bank's Peter Thomas said pilots showed banks can pull hardened, standard-compliant releases through standard corporate proxies with zero friction to existing pipelines.
A crowded field: Lightwell's 400 bug milestones
OSERA is not the only new force in open source remediation. Technology Decisions reports that IBM and Red Hat's $5 billion Lightwell initiative, announced in late May, has uncovered, remediated and backported fixes for more than 400 previously unknown vulnerabilities in widely deployed Java libraries, and has made Lightwell Clearinghouse generally available so enterprises can submit dependencies for priority review. The two efforts share a thesis: fixes must reach production code without forcing a choice between security and uptime, and both route remediations through secured repositories that leave existing development pipelines untouched.
Regulation is the forcing function
The stakes come from compliance as much as security. PR Newswire notes that resiliency regulations such as DORA, NIS2 and the EU Cyber Resilience Act are raising expectations for global institutions to demonstrate robust, repeatable vulnerability management across complex technology ecosystems. OSERA's answer is an open-first model: public source code, member-led governance under the Linux Foundation, and open standards, positioned as a 'regulated downstream' complement to upstream efforts like the Akrites initiative. RBC's Abe Batthish said the bank wants to hold vendor maintainers to clear standards and SLAs so every fix meets the same bar regardless of who produces it.
Targets through 2026 and the wider Linux Foundation push
Looking ahead, PR Newswire reports OSERA aims to produce at least 80 patches per month, with vendor maintainer Moderne delivering patches to a secured platform with quarantine gates built by ControlPlane, and a first end-to-end platform release planned for the Open Source in Finance Forum in New York this November, alongside a per-project sponsorship model. The announcement lands amid broader consolidation of open source stewardship at the Linux Foundation: The Linux Foundation itself says AWS became a Platinum Member on October 7, gaining a board seat after joining 25 projects and foundations including the CNCF and OpenSSF.
Sources
- prnewswire.com › Major Banks Back OSERA to Deliver Industry Wide Remediation Standards and Fixes to Secure Open Source Software
- technologydecisions.com.au › IBM and Red Hat patch 400 bugs in open source software
- linuxfoundation.org › AWS Becomes a Platinum Member of the Linux Foundation, Deepening Commitment to Open Source