Securing Open Source Software with Lineaje’s Javed Hasan
After picking up an additional $20 million in funding, Lineaje CEO Javed Hasan explains why a different approach to securing open source software is required.
Transcript
This is Textron tv. Hey guys, thanks for the throw. We're here with Java Hassan, who is CEO for Lineage, and we're talking about, well, they picked up $20 million in additional funding, and they're focused on this whole area of helping us secure our software supply chains.
And we're gonna jump into what's driving that these days. 'cause I feel like we talk a lot about it, but I'm not quite sure what the progress is. Jam welcome to show.
Hey, thank you Mike. Uh, great being here. Well, let's get started with the funding itself.
Um, it's not an easy to raise money this, in this current climate. So what, uh, is driving people to invest in this space and, and ultimately, how do you see this category evolving? So, you know, so first we are very excited about the funding.
Round 20 million is, uh, is more than what we wanted to raise, but the market was there. So we decided to, to raise as much as the, the market would, would give us. Uh, and, and you're right, I mean, at, at one level, what, what we are seeing is software supply chain has become more and more important with every passing quarter is the way we see it.
You know, started with the executive order 1, 4 0 2 8 by the, by the White House. And, and we just seem to see significant momentum around that as, as we are going along now. And so, and the, you know, we started the company as, you know, in 2022, raised the seas seed round at the end of 2022.
2023 was a great year for us. We did, uh, we did very well from a startup perspective. First year of revenue, we got a, got heavy traction specifically in, uh, in US defense, US gov, you know, uh, software development firms and, and, and of course the higher regulation verticals.
So that worked well for us. So heading into 2024, we wanted to start focusing on having built, built good products is started focusing on go to market. So needed more money for that.
So, so here we are having completed that round, and we were incredibly fortunate that, that we could raise money in the market that, that we know is tough. I think everybody understands that it's important to secure their software supply chains, and I think they're even more aware that they are being compromised. But it seems like people have a tough time getting their arms around this and getting started.
So when you talk to customers, what are kind of the challenges that they incur? I mean, I, I think what we are seeing is a connection between the current biggest challenges that companies are facing and the, and their software supply chain. For example, if you talk to most resource right now, they will say they're overwhelmed with vulnerability management, right?
And, and then, and, and in, in, in, in the applications that, that they, that they deploy or they, or they set. And, uh, one of the big issues fundamentally there is, is, so where do these vulnerabilities come from? And what we are finding out, 70% of to 80% of applications are now built with open source, which is your supply chain.
Effectively, if you sort of start thinking about it that way, 95% of the vulnerabilities, in fact, 95% of the risks come from the supply chain. So effectively, developers can't fix what they didn't build. So increasingly what we are seeing is how is, you know, companies like Lineage help people get to the root cause of the problem, which is, hey, if you have a faulty or a insecure supply chain, your applications will be insecure.
So we solve these problems, even today's problem at a more fundamental level than throwing vulnerabilities at your developers and saying, Hey, why don't you fix them? Like I said, developers can't fix what they didn't build. And that creates a very fundamental drive for imp for a improved supply chain that we are seeing.
We, we, we are seeing the forward looking companies sort of look at it and say, we, unless we address the supply chain, we will not really address soft equality. Well, to your point about open source, how do I fix something that I didn't build? 'cause a lot of times people are dependent on maintainers that they don't know, and then it turns out there might be only two or three people working on that project.
And building a isn't necessarily a priority for them. Yeah, I mean, I mean, that's one of the, of the bigger issues. I mean, if you just sort of double click on, on, on that statement you made, you're absolutely right.
So the first problem there is do I actually know the full dependency chain of the open source that I depend on, right? So the, and what we have found is, what linear research has revealed is that, you know, uh, software supply chain in the open source may be 21 levels deep. And, and at each level, 70% of the software comes from other open source components that were not built by the people who built the package that you, that your developers use.
So in a sense, you get 21 levels with many, many, many organizations or, or many, many open source developers, uh, working together to deliver that. And within that chain, you're absolutely right. There are large, large number of components that are not necess necessarily well maintained.
So one, one of the things that we can do is not only just give you full visibility into, into your open source dependencies, but we can now categorize them with, with a new product. We launched earlier this year called open source manager into, well-maintained unmaintained and maintained. And so it's, no one has fixed a vulnerability for in, or, or issued a patch or an update for the last two years for that open source package, and you have a big dependency on it.
Well, you're not getting one. So if you take that thing thing further, 52% of vulnerabilities in open source are never fixed. That's a large number.
So half the vulnerabilities are never fixed. So now I'm basically saying, look, first you need to know what's in your open source, what's the full dependency chain is, categorize this into well maintained, unmaintained and maintained. And the third thing you really need to be able to then do is find out what, if you have a dependency on them, what will be fixed?
What can you rely on them to fix? And then what you can't rely on them to fix. And so we did a, as you know, we had, we have done a partnership with Persistent Systems last year, and they built for us what people are open source crew.
So what we can do is we find the, the ones that you are dependent on, and basically go assign them to this open source crew to fix it. Now, as we go forward, this funding round allows us to expand that kind of capabilities. So now we have Hitachi Ventures, WEBPRO Ventures, all of us, all of the them participating in this round.
And what that allows us to do is to scale these very large, uh, services organizations to a large extent and, and, and, and, and services companies to a large extent, and use them as a way of enhancing this kind of offering and essentially build the ecosystem of what we call fixed open source. So in a sense, you have to take, you can't live, continue to live with unmaintained open source as a fundamental building, uh, you know, building block, block of software and somehow get to secure software. So essentially you have to go all the way back in the supply chain, fix that, fix the software, you build, fix third party code that comes in, put it all together in, in, in modern applications that are built secure by design.
So we sort of take it all the way back and then bring it all the way to the front and say, this is how you build secure software. Mm-Hmm. And so essentially you manage your supply chain, you get secure software, Does the fix that you guys created, then it's up to me as a customer, I might wanna contribute that back to the open source project itself, or you know, is there a virtuous cycle here or how does that all come together?
There there is absolutely a virtuous cycle, you know, cycle there, right? So now you contributed back. Now we contributed back as well, right?
So now, and you create what we would call secure branches in, in open source. Now the hope is that more companies will use the secure branches, right? And so every, you know, so we, we get to a more secure supply chain just by building more secure components that are widely used.
So today, I think the average developer might spend maybe 5% of their time, maybe 10 and most fixing vulnerabilities. Um, do we need to reallocate that or is that the right amount of time and we just used to needed, we need to find a way to use that more efficiently. Yeah, I mean, you, I I think what we are seeing in some organizations that the 30% that a third of developers spend half the time fixing vulnerabilities two, two problems with that, right?
So, so one is a significant overhead now at this moment. And the problem fundamentally is if you sort of look at all your dependencies, they come in a hundred plus languages, most developers will know a couple, right? So how do you go fix stuff that you don't necessarily essentially understand?
So you can't really fix your, all your dependency. The only thing you can do is upgrade from version one to version two, which may fix some of the issues, right? So that's what developers are doing, and they're already overwhelmed with it.
And the problem is that if it's three levels deep and you patch a version, you know, a, a a a component or upgrade a component that is three levels deep in, in open source, you actually don't know its effects. So, you know, there's a lot of unknowns without a software like Lineage. So what we can do is we can detect which, which updates are and upgrades are compatible and which ones are not one developers about it.
Make them, you know, put all the compatible ones together so you can uptake them faster and put all the incompatible ones together so you can now test the whole thing, but you break compatibility once, not many times, as is the current state. So we think we can bring about 40 to 50% efficiency in software maintenance by, by following that approach, right? So that's, that's another product that we have.
But you're absolutely right, developers spending too much time and that will continue to happen unless we source better, right? If you buy better products, better components, your developers will have to fix less. And I think one of the frustrating things that people encounter is a lot of times I fix a vulnerability only to discover that same vulnerability is found its way back into the application because somebody updated some module and downloaded that same vulnerability over again.
And I wind up with this crazy, um, loop. So, um, can I kinda get at this in a way that's, you know, do once and for all time? That's exactly the point, right?
I mean, if you sort think of the famous, you know, our, in our last few, the most famous vulnerability lock four J it is shocking that many organizations still have lock four J vulnerability components, vulnerable components right now. And, and the fundamental reason is because we expect, I mean, it's, it's sort of like a, if I could get a fixed log four J from a central place, then everyone would use it. The question is, right now what we ask each developer to do is patch correctly to get to the solution for log four J.
And what that does is that breaks main break applications that depend on them that cannot use a later version. So now you're asking developers to do special things to keep their software running, right? And, and that's hard for them because they didn't write the log four J module, right?
So what we, we fundamentally believe that a central source for a fixed log four J would have much wider implications. And that's why we keep going back to, hey, let's fix the open source and make it available to everyone. So if everyone uses the, the, the, the good secure version, then the world is a better place.
And, and, and, and developers have less issues with, with the components they pull in. Do you think, uh, AI may play some role in this as we go forward? You can't walk down the street without somebody leaping out to tell you about their new AI thing.
So, um, how I, how could we apply this stuff to, um, code remediation? So, so, so two, two big things, right? So, so one is make better decisions.
Like, like we use AI to, to determine compatibility of, of dependencies versus incompatibility of dependencies and so on. So linear AI allows us to do some parts of that. The second big part, like you rightly said, is now to fix the vulnerability, do you actually need humans?
So we're seeing a, seeing a, you know, a number of AI companies build, uh, applications that will help you fix vulnerabilities in some costs, or, you know, they're not a hundred percent automated, but let's say they, they can make, uh, uh, developers 50% more efficient in terms of 60% more efficient in terms of actually fixing vulnerabilities in code, right? Which is a hard problem for most companies. And that's why we believe that a partner like Webpro Ventures and persistent would use a bunch of these tools and become very, very efficient in their little, in, in the software factories they build with us to fix these vulnerabilities.
Mm-Hmm. Right? So, so the basic idea is that you have a set of developers who are very, very good in using these modern AI tools and, and essentially, you know, lift all boats by delivering fixed code for everyone along with us.
What's your sense of what's the regulatory environment? I don't think anybody gets out of bed in the morning and says, I want to go build insecure code, but life happens. But at what point do you think that, um, the regulations that are coming down the pike will, will have enough bite in them that will drive people to kind of go do this because they have to?
I, I think that we are starting to see that happen in, in, in many, I I would look at it as a, you know, by vertical, by vertical issue. So I think if you're a software developer who sells to the federal government, you are there where your software, you're, you are required to submit a SPO and it'll be assessed and you will get this feedback that we are talking about saying, look, we have components that are vulnerable and so on and so forth relatively quickly. We are seeing that in, in defense in public sector, we are starting to see it in large financials and healthcare.
The FDA mandated that all software on all devices now needs to have an s onem that can be assessed, right? So now all those mandates are now in place. And so we are seeing it.
It's, so this is why I think lineage is exciting. We are in a market where the US federal government and many other countries, Japan is going down that path. Singapore is going down that path.
Some of the Middle East countries are going down that path. Europe is going down that path, are really sort of saying that your software supply chain has to be well managed and they're different flavors of the same law, if you think of it that way. But we are seeing a global focus on this, and that's why some of our investors, right, like Hitachi Ventures comes from Japan, and of course there, they're, again, they're global, but they also take us into Japan.
Webpro Ventures comes from India, they also have US and European market, you know, uh, prosperity seven very strong in the Middle East. So one of the things that we are seeing with this funding round is this whole need to go global. And so we think that that, you know, we have been amazed at the speed at which this, this market has moved.
I would give you that it's really more around the high regulation government kind of markets and software development firms. But if you go back, you know, I would just give you a little analogy if that's okay. If you go back to any other supply chain industry, you know, like take the automotive supply chain, right?
Or take the food supply chain. What you will find is if you look at the automotive supply chain, the big brand moved to fix their supply chains and then everything else moved. So I think what we are seeing is the big brand move in software care a lot about, uh, about their brand and the implications of their software supply chain and the rest will follow.
All right folks, you heard it here. Software supply chains are gonna get more secure. It's just a question that whether you're gonna do it now or later, but I'll tell you what, thank the sooner you do the easier it gets.
Java, thanks for being on the show. Thank you, Mike. Pleasure being with you.
All right, and back to you guys in the studio.