{"database": "press", "table": "releases", "rows": [["https://www.peters.senate.gov/newsroom/press-releases/committee-advances-peters-bipartisan-legislation-to-help-secure-open-source-software", "Committee Advances Peters Bipartisan Legislation to Help Secure Open Source Software", "2022-09-28", "2022", "2022-09", "Democrat", "Senate", "MI", "Gary C. Peters", "P000595", "www.peters.senate.gov", "garypeters", "https://www.peters.senate.gov/newsroom/press-releases", "scraper", "WASHINGTON, DC \u2013 Bipartisan legislation authored by U.S. Senator Gary Peters (MI) to help protect federal and critical infrastructure systems by strengthening the security of open source software has advanced in the Senate. The legislation comes after a hearing convened by Peters on the Log4j incident earlier this year and would direct the Cybersecurity and Infrastructure Security Agency (CISA) to help ensure that open source software is used safely and securely by the federal government, critical infrastructure, and others. A vulnerability discovered in Log4j \u2013 which is widely used open source code \u2013 affected millions of computers worldwide, including critical infrastructure and federal systems. This led top cybersecurity experts to call it one of the most severe and widespread cybersecurity vulnerabilities ever seen. The bill was advanced by the Senate Homeland Security and Governmental Affairs Committee where Peters serves as Chair. It now moves to the full Senate for consideration.\n\n\u201cOpen source software is critical to our country\u2019s national and economic security, and we must ensure it is secure against cybercriminals seeking to exploit vulnerabilities like the one found in Log4j,\u201d said Senator Peters. \u201cNow that this bipartisan bill has advanced in the Senate, I urge my colleagues to pass it as soon as possible so we can help secure open source software and continue strengthening our defenses against persistent and evolving cybersecurity threats.\u201d\n\n\u201cThis important legislation will, for the first time ever, codify open source software as public infrastructure,\u201d said Trey Herr, Director, Cyber Statecraft Initiative, Scowcroft Center for Strategy and Security, the Atlantic Council. \u201cIf signed into law, it would serve as a historic step for wider federal support for the health and security of open source software. I am encouraged by the leadership of Senators Peters and Portman on this issue.\u201d\n\nThe overwhelming majority of computers in the world rely on open source code \u2013 freely available code that anyone can contribute to, develop, and use to create websites, applications, and more. It is maintained by a community of individuals and organizations. The federal government, one of the largest users of open source software in the world, must be able to manage its own risk and also help support the security of open source software in the private sector and the rest of the public sector.\n\nThe Securing Open Source Software Act would direct CISA to develop a risk framework to evaluate how open source code is used by the federal government. CISA would also evaluate how the same framework could be voluntarily used by critical infrastructure owners and operators. This will identify ways to mitigate risks in systems that use open source software. The legislation also requires CISA to hire professionals with experience developing open source software to ensure that government and the community work hand-in-hand and are prepared to address incidents like the Log4j vulnerability. Additionally, the legislation requires the Office of Management and Budget (OMB) to issue guidance to federal agencies on the secure usage of open source software and establishes a software security subcommittee on the CISA Cybersecurity Advisory Committee.\n\nAs Chairman of the Homeland Security and Governmental Affairs Committee, Peters has led efforts to ensure our nation is better prepared to defend against cyber-attacks. His historic, bipartisan provision to require critical infrastructure owners and operators to report to CISA if they experience a substantial cyber-attack or if they make a ransomware payment was signed into law. Peters\u2019 bipartisan bill to enhance cybersecurity assistance to K-12 educational institutions across the country was also signed into law. Peters\u2019 bipartisan bills to bolster cybersecurity for state and local governments, strengthen the federal cybersecurity workforce, and help secure federal information technology supply chains have been signed into law.\n\n###", 1, "2026-03-30T01:40:41Z", "2026-04-08T03:08:33Z"]], "columns": ["url", "title", "date", "year", "month", "party", "chamber", "state", "member_name", "bioguide_id", "domain", "scraper", "source", "date_source", "text", "has_text", "collected_at", "updated_at"], "primary_keys": ["url"], "primary_key_values": ["https://www.peters.senate.gov/newsroom/press-releases/committee-advances-peters-bipartisan-legislation-to-help-secure-open-source-software"], "units": {}, "query_ms": 1.173909055069089, "source": "dwillis/congress-press", "source_url": "https://github.com/dwillis/congress-press", "license": "MIT", "license_url": "https://github.com/dwillis/congress-press/blob/main/LICENSE"}