Help reduce the risk to your software supply chain by using the same OSS packages that Google uses and secures in your own developer workflows.
Obtain your OSS packages from a trusted and known supplier
Know more about your ingredients from Assured SBOMs, provided in industry standard formats
Reduce risk with Google actively finding and fixing vulnerabilities in packages
Increase confidence in the integrity of the packages through signed, tamper-evident provenance
Choose from 2500+ curated Java and Python packages including ML/AI projects like TensorFlow
Benefits
Improve security
Leverage Google’s end-to-end capabilities and expertise to address the emerging threats to the software supply chain.
Increase efficiency
Reduce the need for your DevOps teams to establish and operate OSS security workflows.
Address compliance
Accelerate your business’s ability to meet new software supply chain security regulatory requirements.
Key features
Packages are built with Cloud Build, including evidence of verifiable SLSA-compliance. We provide three levels of package assurance: level 1, built and signed by Google, level 2, securely built from vetted sources, and attested to all transitive dependencies, and level 3, including transitive closure of all dependencies and continuously scanned and fuzzed.
SBOMs for each package come with enriched metadata including Cloud Build, Artifact Analysis, package health, and vulnerability impact data, provided in SPDX and VEX formats.
Packages include OSV data and are regularly scanned, analyzed, and fuzz-tested for vulnerabilities.
Packages and metadata include end-to-end provenance of how the packages were built and tested.
Signed versions of the packages and their metadata are distributed from a Google-managed, secured, and protected Artifact Registry.
New packages are added on an ongoing basis based on the open source projects that impact our customers.
What's new
Documentation
Start using Assured OSS by getting a service account, enabling the service, and then validating the connection.
View all the current packages supported in the Assured OSS portfolio.
Get options and instructions to integrate Assured OSS with popular repository managers Artifact Registry, Artifactory, and Nexus; or directly to your config scripts.
Access key metadata including SPDX, VEX, package health, and license information.
Enhance software supply chain security across the entire SDLC—from development, supply, and CI/CD to runtimes—with our fully managed, end-to-end solution.
Learn best practices that help protect your software across processes and systems in your software supply chain.
Pricing
Assured OSS is available at no cost.
Start building on Google Cloud with $300 in free credits and 20+ always free products.