Home › Releases › Major banks launch OSERA to standardize open sourc...
Releases

Major banks launch OSERA to standardize open source security

Major banks launch OSERA to standardize open source security

Six global financial giants have activated the Open Source Enterprise Resiliency Alliance (OSERA) to combat redundant security patching. By establishing a shared, industry-wide standard for software remediation, the coalition aims to eliminate the costly, fragmented efforts currently draining resources across the financial services sector.

The alliance, spearheaded by the Fintech Open Source Foundation (FINOS), includes Deutsche Bank, Goldman Sachs, Morgan Stanley, NatWest, and the Royal Bank of Canada. Rather than each institution developing proprietary fixes for the same open source vulnerabilities, OSERA provides a unified, transparent pipeline. Within its first 100 days, the group released a formal patching and attestation standard and delivered verified updates for over 50 projects within the Java and Spring ecosystems.

This initiative addresses what industry leaders call a "fork tax," where one in five financial institutions maintains private, redundant versions of open source code. Beyond cutting maintenance costs, the move helps firms meet tightening global regulations like DORA and the EU Cyber Resilience Act. With plans to scale production to 80 patches per month by the end of 2026, OSERA intends to shift open source resiliency from an internal operational burden to a collective, high-trust capability.

Share:TelegramXFacebook

Read Also

Comments (0)

Leave a comment

No comments yet. Be the first!