Try GOLD - Free

"We have processed fixes for the top 100 open source repositories"

Open Source For You

|

June 2025

Persistent Systems aims to establish a world where every open source vulnerability has a service level agreement (SLA), so that enterprises can secure themselves against malevolent attacks without having to wait for community-driven fixes. OSFY's Yashasvini Razdan spoke to Nitish Shrivastava, SVP and Head of Products Business at Persistent Systems, about the company's mission to enhance open source security.

- Nitish Shrivastava, SVP and Head of Products Business at Persistent Systems

"We have processed fixes for the top 100 open source repositories"

Q Could you provide an overview of Persistent Systems' work in open source?

A. At Persistent, we recognise the significance of open source, both as contributors and consumers. Over the last few years, we have launched several solutions to enhance open source security. We have developed a green open source repository, which serves as an alternative for our customers. This ensures that they receive immediate fixes in compatible versions, helping them integrate updates seamlessly into their products.

Our Centre of Excellence (COE) for open source focuses on securing the entire open source supply chain. We have developed our own technology stack while also partnering with premium agencies. Our work includes identifying vulnerabilities, determining necessary paths for remediation, providing actual fixes, and making them available to the community. This ensures that enterprises receive timely solutions, keeping their systems secure.

We also offer a free service called Open Source Hub, available on our website. This allows developers to link their products and gain insights into potential vulnerabilities and remediation paths. The remediation process could involve applying an available fix, upgrading to a more secure version, or, if no solution exists, receiving a custom fix from us.

One of our key initiatives is DEVSource, a developer community designed to address security vulnerabilities in open source. We use generative artificial intelligence (AI) to automate code fixes, reducing the time required to resolve security issues with our proprietary platform SASVA.

Q How do you ensure security in open source software?

MORE STORIES FROM Open Source For You

Open Source For You

Open Source For You

Top 10 Open Source Tools for System and IT Administrators

All reputed online services have committed system and IT administrators working behind the scenes. Here are ten open source tools they should be aware of, as these can help them monitor, automate, as well as manage complex infrastructure with relative ease.

time to read

6 mins

February 2026

Open Source For You

Google opens access to its Gemini Deep Research Agent

Google has opened access to its Gemini Deep Research Agent for the first time, allowing developers to integrate advanced autonomous research capabilities directly into their applications.

time to read

1 min

February 2026

Open Source For You

Open Source For You

NVIDIA buys SchedMD, keeps Slurm open source and vendor neutral

NVIDIA has acquired AI software company SchedMD, signalling a deeper commitment to open source technologies as competition intensifies across the artificial intelligence ecosystem.

time to read

1 min

February 2026

Open Source For You

Open Source For You

How Open Source Tools Power Modern IT Operations

Open source tools have not replaced enterprise IT platforms; they have become the connective layer that makes modern operations possible.

time to read

6 mins

February 2026

Open Source For You

Mandiant's Auralnspector enhances Salesforce security

Google-owned cybersecurity firm Mandiant has released AuraInspector, a free, open source command-line tool designed to identify dangerous access control misconfigurations in Salesforce environments, marking a significant move to democratise enterprise-grade security testing.

time to read

1 min

February 2026

Open Source For You

Google launches Universal Commerce Protocol to power agentic AI commerce

Google has introduced the Universal Commerce Protocol (UCP), a new open standard that enables AI agents to autonomously perform end-to-end commerce activities, spanning product discovery, purchasing, checkout, payments, and postpurchase experiences.

time to read

1 min

February 2026

Open Source For You

Open Source For You

Zero Trust CI/CD: The Death of Static Secrets

In an era where data breach costs continue to hit record highs, shifting to a secretless CI/CD pipeline is the most effective step to safeguard digital infrastructure.

time to read

7 mins

February 2026

Open Source For You

Open Source For You

Quantum Algorithms: The Future of Computing

Explore the essence of quantum algorithms, their groundbreaking applications, recent innovations, and the challenges that remain.

time to read

8 mins

February 2026

Open Source For You

Open Source For You

Bringing Clarity to the Chaos in AI

AI feels powerful, yet most teams struggle because they cannot define what intelligence they really need. But there are ways to address this challenge.

time to read

5 mins

February 2026

Open Source For You

Open Source For You

Top researchers return to OpenAI

OpenAI has welcomed back three high-profile researchers, Barret Zoph, Luke Metz, and Sam Schoenholz, following their brief tenure at former OpenAI CTO Mira Murati's AI startup, Thinking Machines.

time to read

1 min

February 2026

Listen

Translate

Share

-
+

Change font size