DeepSyte™
Bill FeedAll repsScoreboardsPrimariesProAboutSign inGet started
DeepSyte™™

A nonpartisan civic accountability tool. We match federal legislation to your stated values — without partisan bias.

Learn

  • About
  • About the name
  • Methodology
  • Glossary

Legal

  • Privacy
  • Terms of Service
  • Refund Policy
  • Contact

Sources

Bill data from Congress.gov. Summaries from the Congressional Research Service where available.

Follow

  • Bluesky — @deepsyte.app
  • X — @deepsyteapp
All content is for informational purposes only. Always verify against primary sources.
Back to bill feed
118-hr-3286Introduced
Sign in to get alerts

Securing Open Source Software Act of 2023

Read the record. Not the rhetoric.

See how your representatives voted on this bill.

DeepSyte matches this bill to the issues you care about and shows whether your reps' votes line up — not party, not press releases. Take the 2-minute values quiz to see your alignment.

Get started freeTake the values quiz

Alignment with your views

Sign in and take the values quiz to see how this bill lines up with what you've said.

Summary

Official CRS summary
This bill sets forth the duties of the Cybersecurity and Infrastructure Security Agency (CISA) regarding open source software security. Open source software means software for which the human-readable source code is made available to the public for use, study, reuse, modification, enhancement, and redistribution. Specifically, CISA must perform outreach and engagement to bolster the security of open source software; support federal efforts to strengthen open source software security; coordinate with nonfederal entities on efforts to ensure long-term open source software security; serve as a public point of contact regarding open source software security for nonfederal entities; and support federal and nonfederal supply chain security efforts by encouraging efforts to bolster open source software security. CISA must (1) publish a framework, incorporating government, private sector, and open source software community frameworks and best practices, for assessing the risk of open source software components; (2) update the framework at least annually; and (3) ensure, to the greatest extent practicable, that the framework is usable by the open source software community. The bill requires CISA to assess open source software components deployed on high value assets at federal agencies based on the framework and provides for a pilot assessment of critical infrastructure. CISA's Cybersecurity Advisory Committee may establish a software security subcommittee.
Read full bill text

Values analysis

Sign in and take the values quiz to get a personalized read on how this bill lines up with your positions.

Bill details

Congress
118
Bill type
hr
Introduced
May 15, 2023
Sponsor
Not yet available
Last action
July 27, 2023— Placed on the Union Calendar, Calendar No. 127.

How your representatives voted

Sign in to see how your representatives voted on this bill.