The Fastest-Growing Open Source Security Projects | DevOps Connect: DevSecOps 2023
Open source software (OSS) has been an integral but sometimes overlooked constituent of today’s security infrastructure. We believe that security is evolving and will follow the same trajectory as enterprise infrastructure in embracing commercial OSS models. Will open source security companies like Snyk, Project Discovery, SocPrime, Teleport, Truffle Security, Tailscale and R2C follow the same path as Hashicorp, Confluent, Databricks and many of the other successful, public commercial OSS infrastructure companies?
Leading security investors Andrew Smyth and Chenxi Wang of Rain Capital will discuss the current state of affairs in open source security. They will cover why more and more security founders are choosing open source as a business strategy, the lack of resources available to security practitioners looking for relevant open source security projects and why we created The Open Source Security Index.
Key takeaways:
1) We’ll identify the fastest-growing open source security projects and who’s behind them
2) Which areas of the security stack are adopting open source
3) The demand for developer-friendly security products
Transcript
I am an investor these days. Um, I have been the security technologist. I've been in the industry for a long time.
I transitioned from doing research to doing operator roles, and now I'm an investor. Um, be interesting in that career trajectory. Uh, you can come talk to me afterwards, uh, as an investor.
As Mark said, we have to really understand the pulse of the industry and getting in front of new emerging tech. And one way to do this is to keep an eye on where open source, um, technologies are going, and this, since we're security investors. So open source security is really important to us.
So Andrew, who, uh, you're gonna hear in just a few slides that we ask them how we, it's also not going. So Andrew is my partner. We do investments together.
Um, and we have, uh, between the two of us, we have an, an investment that is open source, um, only company called Project Discovery. And many of you probably are using their open source modules called Nuclei, uh, which is really, really cool. If you are not, you should check it out.
So by doing this company, we sort of understood a little bit more about how open source is used in different companies, um, and we say, Hey, it wouldn't be cool if we go to GitHub and pour down data from GitHub to see which ones are the most popular, most widely used, um, open source module. il. Uh, so you can search for it.
And I'm not gonna go through this whole thing, but the goal of doing this is really to see, uh, which open source security projects are, uh, widely adopted. Meaning that most number forks, most number of stars, also how many contributors they are, and how often they do cadence of releases and putting all these factors together in the model to say, Hey, here's top a hundred open source security projects that you need to be aware of. And the reason to do that, and there's a selfish reason, is for us to understand which ones are to pay attention to.
But it is a great tool, it's a free tool, a great tool for practitioners cuz you can keep a track, you can keep an eye on what open source security your peers are adopting and using, and potentially, uh, you can take advantage of that as well. So without further ado, I'm gonna introduce Andrew to give you the meat of the presentation. And let's give a hand to Andrew Smith.
Yeah, just to reiterate, um, firstly, we, we created the index, uh, as a helpful resource for security practitioners. Um, but why, apart from this, do we think understanding what's happening in open source security is so important? Um, so, so this is really it.
Um, I'm gonna skip to this slide. So, so we believe that security is evolving and we'll follow the same trajectory as enterprise infra in embracing open source models. Um, we, we've seen generational open source companies across enterprise infra data analytics and DevOps.
And we think security, um, is, is next. Um, already we're starting to see some breakout up in source security companies, um, following the footsteps of companies like Hash Corp Sneak as the obviously example. And there's other companies coming up like tail scale, um, as well.
Um, but really we think this is just the tip of the iceberg. Um, you know, as, as venture investors, our jobs can often be overcomplicated. You know, really a big part of it is figuring out where the best and brightest technologists are building.
And we are seeing this in open source security. Uh, as you can see from some of the numbers here, almost half of the open source projects and the index were created by startups. These are security practitioners and technologists who all have often left big companies or academia to start businesses, right?
So, and, and again, this number jumps where, um, when we look at, um, um, open source projects that have been started after 2020, so 85%. So really what does this tell us? Um, it tells us more and more security founders believe open source, uh, is critical to their success.
Um, okay, so what does the data tell us and hopefully why is it interesting to practitioners like you all? So, so firstly, this is what we have. Uh, we actively track, uh, 387 individual security projects supported by close to 14,000 contributors security oriented contributors.
We think, um, what these folks are building, uh, and which problems they're solving, uh, is relevant both for security practitioners and leaders when looking at where the future of security is, uh, is, is headed. Um, okay, so let's dive in. So let's, uh, start by looking at, uh, what areas of security open source technologists are building in.
Uh, AppSec and identity are clear one and two, in terms of popularity. Uh, unsurprisingly, SAS tools are still popular with AppSec engineers. Uh, but for me, um, particularly within AppSec here, the data tells two big stories.
Uh, first there is a clear focus on supply chain security, which is not only the, the second biggest, uh, category after SaaS tools, but more importantly is showing the most growth in terms of net new projects being started within apsec. So new projects being started within, within application security. I've listed a couple here that you've probably heard of pro uh, projects like sasa, which were just mentioned, cosign, mega linter, uh, and sift are, are gaining, uh, are gaining traction.
Okay. So the, the second team, um, we are seeing from the data, um, within application of security is the rise of AppSec platforms and really the convergence of traditional SaaS and das tools with sca, uh, and other supply chain functionality. Um, we, we list some open source, uh, uh, projects and companies here.
Uh, mega linter from OX Security, Sam Grap, which is one you've probably heard of, um, which is number 27 on the index as well. Legit security is also there. Okay.
Um, up next is vulnerability management. So vulnerability tools have always been popular with practitioners, but there's a huge focus from technologists on this space over the past three years in particular. So since 2020, uh, nearly one in four, that's one in four, close to one in four open source projects on the index are addressing use cases in the vulnerability management space.
Um, the transition to the cloud, the expansion of the tax surface of modern architectures are, are some of the reasons behind this. Um, but it's clear security engineers want increased automation and community collaboration. Um, uh, and open source founders are leaning into this demand.
Um, gently mentioned, uh, uh, uh, a company called Project Discovery, which, uh, uh, granted we are, we are investors with. So full disclosure, we are investors in that. But this is a, a really good example here.
Um, project Discovery have five separate repos on the index focused on a tax surface management. Uh, they have a vulnerability scanner nui, uh, with over 50 million monthly scans based on a simple yammel, uh, temp, uh, templates. So this two, this tool turns proofs of vulnerabilities into executable templates that can be run and plugged into existing workflows for fast and detection, triaging, et cetera.
So the, the story really here is all of these products are being combined together to provide automated workflows between security engineers and developers. And so, so really, and I'm, I'm putting up some more, uh, some more figures around project discovery and, and their various different repos. Really.
We think Project Discovery is exactly the kind of open source project turn company that we believe is changing our, our, our industry. Um, started by security engineers, uh, and bug bounty hunters facing day-to-day issues in their own jobs. They turn to open source as a way to connect with their peers and create tools that solve problems they're facing.
Um, and as you can see from these numbers, the traction and engagement is pretty incredible. This team started in 2020, so just a couple of years ago, and they've al already built a very substantial community, which is standardizing, which is an important word, around a new approach to vulnerability management. Okay.
So, um, moving on to identity. Um, so, uh, identity was a close overall, uh, second behind AppSec in terms of, um, uh, popularity. Is that good on the sound?
Yeah. Well, okay. Um, uh, but it's actually number one amongst the faster growing projects on the index.
So, uh, identity infrastructure or I am, uh, and NextGen privileged access are, are key interests. Um, key areas of interest here. Okay, So this, this slide is interesting, right?
Look, looking at the language used by two of the more popular creators in the iam, uh, and Pam category, teleport and Tyra who support the opera project, it's clear who the target audience is here. Uh, the complexity of modern cloud environments, as we talked about, and the issues it's causing, uh, for identity and access use cases, it's quite clear. It is driving demand for more developer friendly tools in this area, and startups are starting to lean in.
Okay, so taking a step back, as I said, it's important to recognize, uh, with some of the cool stuff that I've just mentioned, um, that well known tools, uh, that I'm sure you've all heard of, Melo Open ssl, um, um, still dominate the top positions in the index, right? Um, but, But we think there, there is momentum building around new projects, um, meeting new security challenges. And that is evident in the numbers as well.
There is a shift happening, um, uh, when you look, when you look into the numbers and, you know, close to half of the projects on the index have only started in the last five years. Uh, and that number has grown by the month, uh, as we track it, we're, we're, we're seeing it. So, um, and, and this is another example.
So four outta five of the fastest growing projects started after 2020. Uh, inci here on the far left, um, for example, which is an encrypted secret manager, uh, for API keys only started in August, I think of last year. Um, um, so some of the growth there has been, um, pretty impressive.
Um, so to conclude, um, why does this matter to you? I think so as PR practitioners, um, expect to be seeing more and more of these open source companies and projects being used by your teams, uh, and maybe knocking on your door. Okay.
Okay. So we're nearly there. Um, to, to wrap up, um, again, we created the index.
Uh, I think it's important to, to mention this as a resource for security engineers to find open source security projects. Um, but we think the data is important for you because it provides some interesting takeaways and I'll just quickly go through them again. Okay.
So it suggests one, it suggests more and more security founders think open source is the future. Uh, two security engineers are bringing automation and community led, uh, collaboration to categories like vulnerability management. Uh, three, we are seeing the convergence of traditional SaaS and das and SCA tools with supply chain.
And finally, down the bottom here, um, there is evidence for increased demand for, for developer friendly products in identity and access management. Um, so that's it. Um, thank you.
It's not common for Andrew and I both be here, so question? Yes, yes, please. Hello there.
My name is Fas Mosley. Um, really great presentation. Lots of data and it looks like an amazing index.
Um, how does that play into your decisions to make the investments and, you know, how do you prioritize that? Do you wanna go? Um, look, I mean I think, uh, we, we have to be very careful that that, um, number of stars and, and, and some metrics don't necessarily translate to, to, uh, to business value.
Uh, but I think what we focus on is developer engagement, uh, and what security practitioners are interested in. And then it's, you know, the normal focus on, um, CEOs and, and, and company building and whether the, whether the company has a a, has a shop. But, um, it, it definitely is a helpful, uh, pointer, uh, for us.
Um, but it's not the, it's, it's, it's not the key, uh, the key metric for us on, on an investment. Well, it's one, I I would say it's one of the metrics, right? And so for instance, project discovery, um, thei project, the, the company that behind that project that I've seen people using nuclei all over the place and my friends are telling me great things about it.
And then we looked it up on the open source, uh, not the index, cuz we, that was before we created the index and we looked up on GitHub and they got tons of stars and I talked to the, the founder and they had, when I put in money, first time they had 1 million per, uh, 1 million scans a month. And two years later, now they have 55 0 million scans a month. Uh, these all open source usage, but the, the metrics are amazing.
And on top of that, so the reason that we, I'm very proud of this work is that, for instance, project discovery, the founders are, um, they're two, three guys in India, right? They're not even US based, typical investors would never find them cuz they're flying under the radar. But we, because we, we keep our ears close to the, um, practitioners like you, and then we found them and we love the work they're doing.
So I, uh, we put in money early and a year later they got four term sheets from huge large funds. So it's, it's a success story. So we hope to find more success stories from the open source index as, as one of the factors of decision making.
That sounds great. Um, it would really be great to see later on, perhaps not right now, but maybe a few years from now, the correlation between the success in the market of a particular technology or idea and how the investments panned out versus the index and, and other factors probably, right? Because there are probably other factors coming in from the outside, like how are, even if somebody's launched something and 50,000 users are using it, if they're not liking it, um, then maybe, you know, it's not fitting the need and market fit is not good.
Yeah, We are doing, we're tracking the, uh, rising of new projects into top 50. And by the, by the same token, we're tracking things moving out of top 50, right? And you want, Yeah, so we, we, um, as I mentioned, we we're, we're tracking almost, um, nearly 400 repos, right?
And, and we present a hundred based on a, um, a score which, um, incorporates not only star count and star cadence, but also release cadence, um, commits, um, and, and contributors, right? Um, as well as some other bits and pieces. So yeah, I, I, I think it, the, the, the key for us is to see, um, how some of these companies are progressing within a technical community, going after a specific space and then figure out whether, whether they're, uh, investible or not in terms of a, a companies, Right?
I think we also now started tracking which, uh, venture firms are investing in some of these, uh, open source technology. So after, after some time, we are gonna see, uh, we're probably gonna publish a report on who is the most active open source investor in security that would be interesting to us, would be an interesting report. That's really great.
Thank You. Great. Thank you.
Hi. Uh, I'm curious how early you guys get engaged, uh, in terms of both, uh, outreach and investment stage. And, uh, at the same time, I'm also curious about your guys' philosophy on company buildings.
So, uh, perhaps founders that are really passionate about building technology, but maybe not so fluent in creating, uh, you know, scalable business models and how you guys work with founders and founding teams like that, or if you generally avoid investing in, in companies like that. Thank you. Great question.
Um, I'll start then, then you, so we invest really early with seed investors, right? We would put money in, uh, two person with a deck, if we like the idea. We like the passion of the founders.
We'll, uh, we'll give, we'll write a check check. We prefer to be the first check in. So that's, uh, uh, the stage that we invest in.
Um, as opposed to technologists versus knowledge of building businesses. Um, I've had some of my greatest success betting on first time founders. Um, not to say repeat founders not good, but first time founders tend to have the, they tend to be really, really hungry, right?
And they wanna learn, they're passionate about what they're building. Um, so, but what we bring to the table is the ability to help you scale the business, build repeatable practices in other parts of the business, such as marketing, such as sales, and such as go to market. And which serves as a great compliment to the technical insight and technical ability that founders bring.
One final point of that, I mean, I think we, um, primarily back, uh, uh, technical, um, um, founders, but I think credibility is, is one of the big things we, we lean into rather than trying to pro, uh, predict whether they can be big company builders, uh, have they established credibility within a, uh, a domain, uh, and do their peers in that domain respect them. Um, that's, that's the first stepping stone to success of the Thank you. So I have a question about open source business models, right?
We've come a long way since Red Hat is the only open source company that's been successful, but yet I, I just came back from Con in Amsterdam, no shortage of open source based companies there. It seems the dominant form though is oh yes, we take our open source project and offer it as a hosted version, a SaaS model as an investor. Is that, is that the model you you're looking for?
Or is there more meat on the bone for open source models? There's definitely more meat on the bone, right? So I think hosted version is one thing.
Uh, we would like to see enterprise level support and sometimes, uh, a lot or a lot of times the open source technology. How do you, how do you trigger it? It's, uh, cam, right?
There's no, uh, interface. So we are looking, we, we will be looking at, if you are doing an open source based company, we would be looking for enterprise features such as single sign-on, such as usable ui, ux. And also, um, I would like to see how you collect data on the backend and whether you can offer a, a usable council report for uh, uh, whoever the user is, right?
Uh, I've had a, a conversation I had two years ago with a founding team. It's great engine, but there's no, um, backend, uh, report, right? And, and I took it to a security team and the security guys are like, well, yeah, I can use this, but I can't use this product in any way to tell my boss or my peers, we've done our job, there's no data, you know, how do I pay you?
He's like, I can't pay you cuz I need that report. So those things technical founders may or may not think about in the beginning, but those are really important. Great.
Thank you both. Thank you Both. All right, thank you.





