OpenAI announced a new plan for open-source communities, which seeks to use AI tools and security team collaboration to help project maintainers to identify and repair gaps more quickly. The plan is called "Patch the Planet", in collaboration with the security company Trail of Bits.
Trail of Bits is directly involved in the search
According to OpenAI, the security staff of Trail of Bits will work directly with the Open Source Project maintainer to examine potential code issues. OpenAI security tools, including Codex Security, will also be involved in supporting analysis.
OpenAI stated that the aim of the plan was not to impose a new handling burden on the maintainer, but to screen the issue first by the safety engineer and then hand over the more definitive results to the project party. The team will also assist in the development of patches and tests and the organization of reusable workflows.
The focus is on reducing maintenance pressure.
Open-source projects have long relied on decentralized community collaboration, but maintenance resources are often limited. According to OpenAI, many defenders already need to process an increasing number of security reports within a limited time frame, and therefore need more external support.
This model is equivalent to having the security engineer take on the diagnostics first, before completing the initial screening and restoration recommendations with the AI tool. At the core of this is to reduce the pressure on defenders to face a large number of original loopholes directly.
Open source security implications Hiro.
Open source software is an important basis for commercial software, but security management is often not centralized. Once there are gaps in bottom projects, the impact may quickly spread to a large number of enterprise systems. The previously widely used open-source tool, log4j, has given rise to a wide range of security risks when serious loopholes have been exposed.
Recently, the AI security tools have also generated new discussions. On the one hand, such tools can identify code deficiencies more quickly; on the other hand, they can make the use of loopholes easier. OpenAI's approach this time is to use AI on the defensive side to help open-source communities to improve repair efficiency.
At present, OpenAI has no details of how the plan will operate in the future and whether it will further expand its coverage.
