Kusari blog

Unveiling GUAC as an OpenSSF Incubating Project for Software Dependency Management

Today, we find ourselves in a moment akin to proud parents, as we witness a significant milestone in the journey of Graph for Understanding Artifact Composition (GUAC).

Parth Patel

Michael Lieberman

March 7, 2024

In the bustling realm of open-source software, every project has a story—a narrative of innovation, collaboration, and relentless pursuit of better solutions. Today, we find ourselves in a moment akin to proud parents, as we witness a significant milestone in the journey of Graph for Understanding Artifact Composition (GUAC).

GUAC is an Incubating Project with OpenSSF

GUAC is a groundbreaking tool designed to revolutionize the task of dependency management for the software supply chain. Developed through a collaborative effort involving visionary minds from Google, Purdue University, Citi, and our own team, GUAC is a supply chain security innovation in the realm of open-source software.

GUAC stands at the forefront of a paradigm shift, offering a solution to the increasingly complex challenge of understanding and securing software dependencies. What began as a pioneering quest and a proof of concept has evolved into a robust open-source initiative, with a thriving community driving its progress.

But like any great endeavor, GUAC's journey is just beginning. Just as Kubernetes has redefined the role of containers, GUAC seeks to redefine the way we understand and manage dependencies that threaten the software supply chain.

As GUAC transitions to OpenSSF, Kusari will continue as a maintainer. We are increasing our investment in the future of GUAC - bolstering support for users, enhancing its capabilities, and fostering community growth.  Whether you're already part of the community or discovering GUAC for the first time, we invite you to join us on this journey.

This is an exciting chapter in GUAC's story—a story driven by innovation, collaboration, and the relentless pursuit of a more secure software ecosystem. Together, let's redefine the future of dependency management in open-source software.

Like what you read? Share it with others.

Other blog posts 

The latest industry news, interviews, technologies, and resources.

View all posts

Previous

No older posts

Next

No newer posts

Want to have a conversation about your software supply chain?

We’d love to hear from you.  Get in touch and we'll get back to you.

Say Hello
By clicking “Accept”, you agree to the storing of cookies on your device to enhance site navigation, analyze site usage, and assist in our marketing efforts. View our Privacy Policy for more information.