Assured Open Source Software (Assured OSS) provides open source packages that Google itself secures and uses, complete with SBOMs, VEX data, and signed provenance.
What is Assured Open Source Software?
Assured OSS lets you take advantage of the security and experience that Google applies to open source software by incorporating the same OSS packages that Google secures and uses into your own developer workflows.
Per the documentation, this lets you obtain your OSS packages from a trusted and known supplier, learn more about package contents through Assured SBOMs provided in the SPDX industry standard, review threat and security information as VEX in the CycloneDX industry standard, and reduce security risk because Google actively scans for, finds, and fixes new vulnerabilities in the curated packages.
The open source packages built securely by Google meet Supply-chain Levels for Software Artifacts (SLSA) level 3 requirements per the documentation and have verifiable provenance and an SBOM.
Core Features
- Curated repositories: Obtain packages through remote repository access, and for Java and Python also through direct repository access
- Assured SBOMs: A software bill of materials per package in the SPDX industry standard
- VEX information: Vulnerability context in the CycloneDX industry standard
- Signed provenance: Tamper-evident attestations covering the origin and build of each package
- Security metadata: Retrieval through the Container Analysis API or through Cloud Storage
- Notifications: Subscription to security notifications for the packages you use
Typical Use Cases
Securing the software supply chain
Sourcing Java, Go, Python, and NPM dependencies from a supplier that Google continuously scans and maintains, rather than from unvetted public registries.
Compliance evidence
Providing SBOMs in SPDX format as evidence for auditors and customers, complemented by VEX data that puts reported vulnerabilities into context.
Build-time integrity checks
Verifying signed provenance in CI/CD pipelines to confirm that the artifacts in use come from the expected source.
Machine learning stacks
Using curated packages for common ML and AI projects such as TensorFlow, Pandas, and Scikit-learn.
Benefits
- Known supplier: Packages come from a curated source managed by Google
- Traceable contents: SBOM and VEX in industry standard formats instead of self-generated lists
- Less in-house effort: Google handles scanning and fixing vulnerabilities in the curated packages
- Entry without an extra licence: The free tier covers Python, Go, and Java packages
Integration with innFactory
As a certified Google Cloud partner, innFactory supports you in adopting Assured OSS: assessing your dependencies, connecting the curated repositories to your build pipelines, and evaluating SBOM and VEX data for your compliance processes.
Contact us for a consultation on Assured Open Source Software.
Available Tiers & Options
Free tier
- Python, Go, and Java packages in curated repositories
- Universal proxy endpoints for open source packages and their metadata
- Support for Amazon Web Services (AWS) account access
- Manual setup steps
- Curated repositories live in a Google-managed project
- No JavaScript/NPM packages
Premium tier
- Adds JavaScript/NPM packages in curated and canonical repositories
- Automated setup as part of organization-level activation
- Curated repositories in a project you specify
- Universal package metadata collected and signed by Google
- Requires Security Command Center Premium or Security Command Center Enterprise
Typical Use Cases
Technical Specifications
Frequently Asked Questions
What is Assured Open Source Software?
Assured Open Source Software (Assured OSS) lets you incorporate the same open source packages that Google secures and uses into your own developer workflows. Google actively scans, finds, and fixes vulnerabilities in the curated packages and provides metadata for each package.
Which programming languages are supported?
Per the documentation, more than one thousand of the most popular Java, Go, Python, and JavaScript (NPM) packages are available, including common machine learning and artificial intelligence projects such as TensorFlow, Pandas, and Scikit-learn. JavaScript/NPM packages are part of the Premium tier.
Which tiers exist and what do they cost?
Assured OSS has a free tier and a Premium tier. The Premium tier is available when you purchase Security Command Center Premium or Security Command Center Enterprise. Google does not publish a dedicated pricing page for Assured OSS; the official documentation is authoritative.
What compliance evidence does Assured OSS provide?
Each package comes with an SBOM in the SPDX industry standard and VEX information in CycloneDX format. Packages built by Google meet SLSA level 3 requirements per the documentation and have verifiable provenance.
How do I access the packages?
Access happens through curated remote repositories, and through direct repository access for Java and Python packages. Security metadata can be retrieved through the Container Analysis API or through Cloud Storage, and you can subscribe to security notifications.
Note: All product information on this page has been compiled with care, but is provided without guarantee and may be outdated or incomplete. Cloud services evolve rapidly — features, pricing, SLAs, and availability change frequently. Authoritative and up-to-date information can only be found on the official product page of Google Cloud (official documentation). This page does not represent an offer by Google Cloud.
