Javier Pérez on OpenLogic’s Support for Open Source Software at OSS Seattle 2024
Javier Pérez, of OpenLogic by Perforce, discusses their role in providing enterprise-grade technical support for open source software, particularly focusing on assisting organizations with skills, experience and specific issues related to open source technologies. He highlights the findings from OpenLogic’s annual global survey on the use of open source software, revealing continued growth in adoption, with security remaining a top concern alongside challenges related to end-of-life software and keeping up with updates. The report also emphasizes the need for greater awareness and adoption of open source security tools, available for download on the OpenLogic website and GitHub.
Transcript
This is Textron tv. Hey everybody. Mitch Ashley here at the Open Source Summit in Seattle, 2024.
Lots of great folks that we're talking to. Lots of open source topics, as you might imagine. And another great topic, matter of fact, gentlemen just finished his talk, uh, here at the conference is Javier Perez with the Open Logic Yeah.
Airforce Company. Yes. One of the many, one of the many Companies.
Yes. It's great. Great to Be here.
Good to be here. Thanks for taking time. So tell us about, well, first of all, if somebody doesn't know what Open Logic is, tell us what you Do.
Yeah. Open source, uh, open Logic has been around for, for a long time now, more than 20 years. And what we do is we provide enterprise grade technical support for open source software, open source technologies.
Mm-Hmm. So organizations that are using open source software, uh, you know, sometimes they don't have the enough, uh, personnel, the skills experience, or they have specific issues. Uh, we, uh, have, uh, a number of architects experience subject matter experts on the different open source technologies.
We support many open source technologies, more than 400 actually. Mm-Hmm. And, uh, and we help organizations with that.
And that's been obviously a, a, a successful business. Uh, something that not everyone can do Mm-Hmm. By providing this level of, of support.
Uh, and we are also doing, uh, end of life, uh, so long-term support post end of life software. Mm-Hmm. Uh, cases like Santos, we can talk more about this, but it's Santos bootstrap.
They reach chain of life. The community no longer produces releases, and we are taking over after that. Mm-Hmm.
Uh, and we've been actually very successful with that, that business as well. We're Always focused on the shiny new object, but so many things get deployed. You know, there's Windows N NT running out there somewhere on some oil well, measuring SCADA data.
But, um, you know, so, so many times you just, there isn't an upgrade path for somebody, or it's not financially viable to do that. Absolutely. And one of the things that we talk about here in conference like this, there are many of the sessions that talk about, you know, how critical it's open source software infrastructure, right.
Or we call software infrastructure is software that, you know, is maybe layers down, starting with the operating system, uh, that are critical. Like if that fails, if there's something happens, uh, you are in trouble, right? Mm-Hmm.
Whereas people might just be thinking about the application level or, you know, now everyone talking about AI and all that for, you need the, you have actually some, uh, critical open source software in your infrastructure. And, uh, yeah, that's definitely a very, very important area for the enterprises. Very nice.
Well, you just finished your talk. Tell us about your talk. I know you've got a new report that's out and tell us about that.
Yes, yes. So, uh, uh, every year we work on a big survey, um, global survey about the use of open source software in organizations. And that's the key differentiator here.
Um, it's about every single question on the survey. And, uh, and by the way, it takes about 10 minutes to, to, you know, fill the survey, which is sizable Mm-Hmm. We require, Uh, you get some 10 minutes of someone time.
That's valuable Data. Yeah. Right.
So, so yeah, we were very thankful of that. Uh, we're actually very successful with the survey this year. We got, uh, more than 2000 respondents Wow.
To that survey. And every question, it's about the use of open source software in their organization. Right.
The respondents talk about their organization, uh, and that's what makes this, this survey different. And from that, uh, we put together a report, which I love that part of the, of the process, right? Mm-Hmm.
Because it's slicing and dicing all data and pulling A story together about what, what's this data saying, what's maybe new trends Yes. Things that you're finding. Absolutely.
Um, and, and, you know, we try not to have that many different, uh, demographics or firmographics, but, but we, we can slice and dice based on the company size of the response or the industry or the region, right? Mm-Hmm. Which would also give us some, some really good information.
Uh, and even like the job titles, quite obviously, an engineer might respond different to A CEO or CTO. Uh, so we, we had the opportunity to read all that data, analyze that data, and then produce a report, which, uh, which is always fun. Uh, and of course we leave so many different things out of the report.
True, yeah. Can still a, you know, 40 page report. Uh, but we open source the, the, the data, the data set, so anyone can go and, and check there, and they open logic, GitHub, uh, space.
There's a ripple there with the, with the data set. So my talk, which I finished just a few minutes ago, was to talk about those highlights, right? Mm-Hmm.
Talk about some of those lessons, uh, learned what what organizations are doing, uh, with the different open source infrastructure, especially infrastructure. But we cover everything from operating systems to run times to CI/CD tooling, cloud native, and security, of course. Okay.
You had me in highlights. So let's jump to the insights. Love to hear.
What, what are some of the compelling things that you thought Yeah. From this year's report? Yeah.
Well, fir first of all, uh, you know, with all sometimes bad news that we hear all these articles that we Hear, that's, you know, that's always what sells, right? The bad, the bank robbery or whatever, right. Or, or, uh, changing open source licenses.
Yes. The end of open source and things like that. Well, first I have to say that the use of open source software in organizations keeps growing.
Mm-Hmm. Every year we do, it keeps growing, uh, particularly this year. And regions like, uh, Asia, Africa, Latin America, even, uh, uh, um, even more, uh, growth, sustainable growth on the use of these open source technologies.
So that, that, that's just start Any, any slowing of growth or kind of at the same rate, what, Can we ask a question, which I think is interesting? Um, we ask, has your organization increased the use of open source software in the last 12 months? And, uh, we provide four options.
Yes. Yes. Significantly, whatever the means, the whatever your interpretation of significantly means to you.
Uh, we remain with the same amount of usage of open adoption and usage of open software, or we reduce the, the use of Mm-Hmm mm-Hmm. Well, yes. And yes, significantly was more than 66% of the respondents, if we include the one, if we include the ones that they remain the same, that's 35%.
Ah, okay. And only 5% basically reducing. And then as we go and analyze the data, it's not that they stop using open source, it's just like they stop using, uh, some of the open source software.
Oh, okay. For example, an end of life open source software like Santos. Like Santos, right.
Or angular gs. And that's why the, the reduction, So open source is alive and well, despite the, despite my death, you know, I'm alive and well. Yes, Absolutely.
Um, technologies like, uh, everything related to cloud native is growing. There's, I guess no surprise there. Mm-Hmm.
Uh, but companies are investing more on databases and data technologies. Interesting. And Why would that be here?
Why, why would that be exactly? Well, for me, it's simple. It's, they're more AI related applications, right?
So you need to manage the data, right? It is not just the, what, whatever you can do with ai, it's you, you have to handle that. And there's so much more data that we create now because we have the storage, the app, so much more telemetry that we're generating that too, metrics, whatever it might be, That that too.
And, and the good thing about open source today is that they are at least 20 to 30 good, reliable, robust, open source technology database, open source database technologies. Mm-Hmm. Or let's call it data technologies, right?
Okay. Because it's not just the traditional database, right? It's in memory, uh, streaming.
It's optimized for analytics, Data management platform, all kinds Of, all of that, right? Yeah. Uh, and then we have forks, like the ones that we just recently heard, right?
With, uh, the fork from Redis. So there's one more option now. Mm-Hmm.
Right. So, so that part is, it's also well, and, and going now on the more of, um, um, perhaps, uh, challenges or, I don't like to say the word negative, but in the, on the challenges, we ask about, you know, what are the most, uh, critical support challenges in the use of open source software in your organization? And, and, and there, number one is security.
So I was just gonna ask you, what about, because that's, that's the headline grabbing thing, log four J or whatever your picture Point, we qualify that answer more, right? Because if you ask what's the most important thing for you on any, in any survey, they're gonna say security, right? Even if you don't do anything about security, yeah.
People are gonna say, security is number one. No, I'm supposed to say security. So, right.
But we qualify that more, right? And we say, well, uh, doing, uh, security compliance, um, mm-Hmm. You're meeting a security compliance, running, uh, security scans to identify vulnerabilities.
Uh, and still is number one, number one challenge for, for organizations. Uh, number two is interesting, is dealing with end of life software. Mm-Hmm.
For end of life versions of the software. Mm-Hmm. Which relates to the number three, which is keeping up with updates and releases.
Oh, yeah. And you know, we here in this conference, uh, some so successful open source projects that are issuing releases often, right? It's not longer every six months, every year.
No. They are sending, they are updating all the time, right? Everything's more automated, you know, smaller releases, um, best practices.
So how do you keep up with that? Because, you know, the patch for that vulnerability is gonna come on that, right? On that release, on that patch, Or to apply the patch, you've gotta catch up to be able to fly it, right?
So, so that those three are the, you know, definitely the most, uh, the top three challenges in the supporting open source software. Let me ask you, so on the topic of security software, supply chain security is a big topic for everyone. And, you know, it's easy to think about the sources of where we get our software from repositories and online sources.
Um, but it's a lot more than that. It's actually, you know, within the software itself, finding vulnerabilities, but also the build process for how it gets created. Is there any, uh, different, more increasing awareness because about this?
Because I ask, 'cause now the government's getting involved, right? Yes. The EU US want to get deeper under the covers about how software is being made, and not just are you scanning it for vulnerabilities as you're creating it, but is the pipeline process itself secure?
I've written a couple of articles, a couple of blog posts about this. Uh, I've been very, uh, have a background on, uh, open source security actually, uh, prior to, uh, prayer force. Uh, so I've been following this very closely, uh, including all these government initiatives, US government, uh, European Union, uh, in the uk.
They also have multiple initiatives in Japan and other and other places. Yeah. Uh, great news that there's more awareness today.
There's no question about that, right? When the government starts, someone said that, you know, if you don't regulate yourself, that's when, that's when the government comes. Yeah.
When they start issuing edicts, that's when last week comes. Not so fun. Not So fun.
But so now you, you all in, for example, in the US all now, uh, government agencies, they have to, uh, run security scans and generate software bill of material sales moms. So that's positive. That's Chris more awareness, by the way.
Uh, that's another result from the report where we ask, like, if you're generating software bill of materials, and it's only about 20% of the organizations, okay. You're not surprised by That. Yeah.
Now we're talking about organizations That might actually be higher than I would, we're Talking about organizations of all sizes, right? Yeah. When we split that, larger organizations do more of that.
I mean, It's early in that adoption And, and government actually up to 30% globally in the US even more. So that's a, that's, those are good, good signs. Uh, now that, that's just one step.
Right? Now you have a software build, not, uh, you scan for vulnerability. You have a, an inventory build of materials.
That's just one, one step. Now what do you do with all that? Uh, we also, uh, see more and more developers, uh, getting familiar with, uh, with what a vulnerability is and with the always top 10 types of vulnerabilities.
So the more, uh, enablement training, the better, right? And, and the concept of, uh, security champions where, you know, one developer is more of the expert and can explain the others or can review what the, the work of others. Those are also, uh, helpful.
Uh, and then, you know, organizations like the Linux Foundation and the Open, open SSF, they have many initiatives from the initiatives drive to where, where the significant progress, right. The one that comes to mind is the, you know, starting, starting to replace some of the c and c plus plus code with, uh, rust or some other programming languages to avoid some of the memory leakage or memory related bilities. Sure.
It's a great initiative. Also, keeping an eye on the, you know, top 10,000 most used open source projects that's part of the initiatives that they're working on. And trying to, um, you know, increase the level of, uh, process, the security, the, so that benefits everyone, right?
Mm-Hmm. So, uh, and that's why we're able to respond really quickly when there's a big, uh, you know, uh, zero, uh, zero day vulnerability or critical vulnerability communities typically respond Really, really quick to that, the issue, and we see that on the report, is now for the organizations to apply the patches. I was wondering about that.
Do you have any, some, some people look at kind of days to remediate, or how long does it take to apply a patch to your open source? Any aspects of that that you looked at? So when we, in the case of open logic, we work on post 10 of live Okay.
Software, right, Uhhuh. So that doesn't mean that vulnerabilities are not discovered, right? Right, right.
So it means that the community, there are no more update, there are more, no more releases, but vulnerability keep getting disclosed, even with the delays that we hear now in terms of the CVEs, but, but they're, they're there, right? And there are other advisories that actually, there's The backlog of cd, There's a backlog, but, but there's also other advisories that are reporting the vulnerabilities, right? Right.
Some programming languages are more effective than others. Now, for example, CNC fours is more effective by the delays, uh, whereas others, they have other advisories and people know about the, the vulnerabilities. Uh, so, um, yes.
So obviously enterprises want, uh, uh, respond time, right? They want patch immediately. They're paying for at, so, so we cover that.
Uh, we try, we monitored this on a, in real time on a daily basis, right? So as soon as, as soon as, as vulnerabilities is disclosed, especially the high severity vulnerabilities, we react immediately rolled out and look for the, look for the resolution for that vulnerability that even, okay, So, uh, a report like this, and obviously you do a lot more things, but that's the news, is the report, um, could be a lot of good uses for who could, you know, justifying, here's why we're investing more use of it, et cetera. Um, if you were an engineering manager, development manager, running software development team, what part of the report do you think would be more valuable if you were gonna say, turn to page X, y, Z on this topic?
Start there. That's where you're gonna really find the interesting things to you, but what would that be? Yeah, so, so we have a section for each one of the categories of open source software, right?
So section for cloud native, a section for open source infrastructure, a section for DevOps, ci i, cd tooling run times. Okay. And, uh, actually for the first time on this report, we added a question about open source security tools.
Mm. Right. Okay.
And the bad news there is that, uh, there's, there's still a lot of, uh, there's lack of awareness, I was gonna say, right? Yeah. That's not a big topic.
But Yeah, we did the research. I had a great time like doing the research and saying, alright, this 20 is what we think are the most popular open source security tools. We listed it on the survey for people to select which ones they're using, and the percentages are really low, one single digits.
Right? Interesting. So there's room for improvement there on the, on the, you know, start using.
And I, I, I had a conversation with one of the industry analysts showing them that, that, um, showing them that, that that result. And, and, and she's a security analyst, right? She's like, look, organizations are using commercial software, and they probably don't realize that there's all these open source options, Right?
Well, also security people aren't, you know, it's not like developers that are very accustomed to using open source for lots of things. I think it's more, maybe security people aren't as quite as, Yeah. But, but developers can use these tools as well.
Okay. Right. So, I mean, of course if it's more about, you know, networking or low balancing and stuff that could not be for necessarily be for the developers, but, so there's, uh, yeah, there's lack of awareness there.
I think, you know, a report like this, to answer your question, a report like this, one of the objectives, uh, for me has always been like, you know, provide information. Even when you're filling the survey, you find out that there's other tools that, other open source options that you Never heard there. All these things, I don't know.
Well, let's go find out what's, let's Open out. So first help with, with awareness. I think that's, that's critical.
That's very important. Um, different regions provide different results. Just after my talk, someone came over that says, can you tell me more about, uh, Africa?
What are things are going happening in Africa with the, with what, with the numbers that you just show? And I said, well, look, it's the data set is open source. Yes, you can go check yourself on the report.
We have some of the, uh, results per region. So we show different charts perhaps per, per region. Um, for last year's report, I have a company, a startup that they reach out to me because they have questions about the report.
I said, sure, happy to talk about. Right? I'm always happy to talk about open source.
I turns out that they were, um, startup, um, on the gas, oil and gas industry, which is obviously one of the categories, one of the major industries. Mm-Hmm. And they had more questions on the results of the report on that, on those industries.
And I was like, sure, happy to. I mean, we, I found out when, when we started talking, and I said, well, I have a lot more data. I can, you know, run a few charts, give you some, some information.
And the question is, well, why did, why did you need this? And he's like, well, this's a start over. We're actually making decisions based on That makes total sense to me.
You want some market data, here you go. Right. That obviously made my day.
And I said like, yeah, that this is, this is, uh, you know, a small contribution that we can do to the, the, the industry or the open source space. Um, and, and keeping it vendor neutral, keeping it completely, uh, you know, on bias, uh, report. Great.
Where do folks download the report from or can they get it? com, uh, website. Uh, there's an option there to download their report.
Uh, they can also look for my slides on the open source Summit, uh, schedule. The, uh, all the slides are there. And also on GitHub Open Logic.
Uh, for GitHub, they can download the free open source data Set Open logic website. Download the report for free. Thanks for joining us.
Javi. Great talking with you, Javier Perez. With, uh, thank you.
Open Logic and, uh, Perforce more great interviews available on Textron tv. We'll hope to check the next one out. Just, just hang tight.
Another one will be up for you to watch in a minute.