Sonatype Eliminates Pain of Reporting OSS Vulnerabilities

Sonatype and HackerOne Eliminate the Pain of Reporting Open Source Vulnerabilities

March 21, 2019
By Bruce Mayhew

4 minute read time

The power of open source never ceases to amaze me. It's transformed, and continues to transform, the way we build software, for the better. And, it's all done collaboratively through an incredible community.

While conversations around developer security and open source vulnerabilities have heated up in recent years, many people still don't understand, or think about, the actual vulnerability reporting workflow and best practices for reporting in an actionable way. Because the open source ecosystem is built by millions of people and across hundreds of thousands of projects, there has never been an efficient or easy process for what to do when a vulnerability is discovered.

Today, we're changing that. We've teamed up with HackerOne to build The Central Security Project (CSP), a pioneering program that brings together ethical hacker and open source communities to streamline the process of reporting and resolving vulnerabilities discovered in libraries housed in the Central Repository. The partnership uses HackerOne's unique vulnerability reporting platform and Sonatype's security research capabilities to fast track potential code exploits and ease the painful process of CVE vulnerability disclosure and reporting.

We've long served as the stewards of the Central Repository, providing it as a free service to support the development community. We take our responsibility as stewards seriously and recognized that we could be doing even more to make the component contributions it houses safer.

Any researcher who has ever experienced reporting a vulnerability to an open source project is painfully aware of the headaches involved in that process. From finding the appropriate security contact at the project to identifying the proper grace period for disclosure, vulnerability reporting is circuitous and frustrating.

With the launch of the CSP, Sonatype hopes to eliminate four main pain points of vulnerability reporting:

How it works:

  1. "Report a vulnerability" links will be added to every project page within The Central Repository and OSS Index. The Central Repository is the largest collection of Java and other open source components. It provides the easiest way to access and distribute software components to millions of developers. It is the default repository for Apache Maven, SBT and other build systems and can be easily used from Apache Ant/Ivy, Gradle and many other tools.

  2. From there, developers and researchers with a potential exploit to report will use HackerOne's platform to submit the request.

  3. When vulnerabilities are reported, Sonatype's security research team will rapidly assess the report and, where appropriate, develop a fix.

  4. HackerOne will contact the target project and open a dialogue.

  5. As a Certified CNA, HackerOne will facilitate CVE assignment.

  6. After the fix has been released, the report will be made public, and the reporter will receive credit for the submission.

  7. The reporter can see the submitted vulnerability and all disclosed vulnerabilities for the ecosystem on the platform.

Join this important mission and a community of like-minded researchers at the Central Security Project today. We look forward to seeing you there.

Written by Bruce Mayhew

Bruce Mayhew serves as Sonatype's Director of Data and Security R&D, where he's focused on product development and research around collecting, analyzing and understanding millions of open source libraries.