Skip to main content
Cloud / Google Cloud / Products / Assured Open Source Software - Curated OSS Packages from Google

Assured Open Source Software - Curated OSS Packages from Google

Assured OSS provides open source packages that Google itself secures and uses, with SBOMs, VEX data, and signed provenance.

Security
Pricing Model Free tier and Premium tier; the Premium tier is available when you purchase Security Command Center Premium or Security Command Center Enterprise (per the documentation)
Availability Available as a Google Cloud service; curated repositories are created in a Google-managed project (free tier) or in a project you specify (Premium tier)
Data Sovereignty As published by the provider / see official documentation
Reliability As published by the provider / see official documentation SLA

Assured Open Source Software (Assured OSS) provides open source packages that Google itself secures and uses, complete with SBOMs, VEX data, and signed provenance.

What is Assured Open Source Software?

Assured OSS lets you take advantage of the security and experience that Google applies to open source software by incorporating the same OSS packages that Google secures and uses into your own developer workflows.

Per the documentation, this lets you obtain your OSS packages from a trusted and known supplier, learn more about package contents through Assured SBOMs provided in the SPDX industry standard, review threat and security information as VEX in the CycloneDX industry standard, and reduce security risk because Google actively scans for, finds, and fixes new vulnerabilities in the curated packages.

The open source packages built securely by Google meet Supply-chain Levels for Software Artifacts (SLSA) level 3 requirements per the documentation and have verifiable provenance and an SBOM.

Core Features

  • Curated repositories: Obtain packages through remote repository access, and for Java and Python also through direct repository access
  • Assured SBOMs: A software bill of materials per package in the SPDX industry standard
  • VEX information: Vulnerability context in the CycloneDX industry standard
  • Signed provenance: Tamper-evident attestations covering the origin and build of each package
  • Security metadata: Retrieval through the Container Analysis API or through Cloud Storage
  • Notifications: Subscription to security notifications for the packages you use

Typical Use Cases

Securing the software supply chain

Sourcing Java, Go, Python, and NPM dependencies from a supplier that Google continuously scans and maintains, rather than from unvetted public registries.

Compliance evidence

Providing SBOMs in SPDX format as evidence for auditors and customers, complemented by VEX data that puts reported vulnerabilities into context.

Build-time integrity checks

Verifying signed provenance in CI/CD pipelines to confirm that the artifacts in use come from the expected source.

Machine learning stacks

Using curated packages for common ML and AI projects such as TensorFlow, Pandas, and Scikit-learn.

Benefits

  • Known supplier: Packages come from a curated source managed by Google
  • Traceable contents: SBOM and VEX in industry standard formats instead of self-generated lists
  • Less in-house effort: Google handles scanning and fixing vulnerabilities in the curated packages
  • Entry without an extra licence: The free tier covers Python, Go, and Java packages

Integration with innFactory

As a certified Google Cloud partner, innFactory supports you in adopting Assured OSS: assessing your dependencies, connecting the curated repositories to your build pipelines, and evaluating SBOM and VEX data for your compliance processes.

Contact us for a consultation on Assured Open Source Software.

Available Tiers & Options

Premium tier

Strengths
  • Adds JavaScript/NPM packages in curated and canonical repositories
  • Automated setup as part of organization-level activation
  • Curated repositories in a project you specify
  • Universal package metadata collected and signed by Google
Considerations
  • Requires Security Command Center Premium or Security Command Center Enterprise

Typical Use Cases

Securing the software supply chain in Java, Go, Python, and NPM projects
Providing SBOMs in SPDX format as compliance evidence
Evaluating VEX information in CycloneDX format
Verifying package provenance through signed, tamper-evident attestations

Technical Specifications

Formats SBOM in SPDX, vulnerability context as VEX in CycloneDX
Languages Java, Go, Python, and JavaScript (NPM) - more than one thousand of the most popular packages per the documentation
Metadata Security metadata access through the Container Analysis API or through Cloud Storage
Slsa Packages built securely by Google meet SLSA level 3 requirements per the documentation and have verifiable provenance and an SBOM

Frequently Asked Questions

What is Assured Open Source Software?

Assured Open Source Software (Assured OSS) lets you incorporate the same open source packages that Google secures and uses into your own developer workflows. Google actively scans, finds, and fixes vulnerabilities in the curated packages and provides metadata for each package.

Which programming languages are supported?

Per the documentation, more than one thousand of the most popular Java, Go, Python, and JavaScript (NPM) packages are available, including common machine learning and artificial intelligence projects such as TensorFlow, Pandas, and Scikit-learn. JavaScript/NPM packages are part of the Premium tier.

Which tiers exist and what do they cost?

Assured OSS has a free tier and a Premium tier. The Premium tier is available when you purchase Security Command Center Premium or Security Command Center Enterprise. Google does not publish a dedicated pricing page for Assured OSS; the official documentation is authoritative.

What compliance evidence does Assured OSS provide?

Each package comes with an SBOM in the SPDX industry standard and VEX information in CycloneDX format. Packages built by Google meet SLSA level 3 requirements per the documentation and have verifiable provenance.

How do I access the packages?

Access happens through curated remote repositories, and through direct repository access for Java and Python packages. Security metadata can be retrieved through the Container Analysis API or through Cloud Storage, and you can subscribe to security notifications.

Note: All product information on this page has been compiled with care, but is provided without guarantee and may be outdated or incomplete. Cloud services evolve rapidly — features, pricing, SLAs, and availability change frequently. Authoritative and up-to-date information can only be found on the official product page of Google Cloud (official documentation). This page does not represent an offer by Google Cloud.

Google Cloud Partner

innFactory is a certified Google Cloud Partner. We provide expert consulting, implementation, and managed services.

Google Cloud Partner

Similar Products from Other Clouds

Other cloud providers offer comparable services in this category. As a multi-cloud partner, we help you choose the right solution.

AWS

AWS Continuum: AI-Driven Security Platform

AWS Continuum discovers, prioritises, validates, and remediates security risks across the software lifecycle, with …

Pricing No official pricing page published yet
SLA Per provider / see official documentation
Compare →
AWS

AWS European Sovereign Cloud: Sovereign AWS Partition in the EU

AWS European Sovereign Cloud: an independent AWS partition with its first Region in Brandenburg, generally available …

Pricing Billed per service used, see official …
SLA Per provider / see official documentation
Compare →
AWS

AWS Payment Cryptography - Managed Payment HSM

AWS Payment Cryptography provides payment cryptographic operations and key management as a managed service, without …

Pricing Per active key per month plus per API …
SLA As stated by the provider; see official documentation
Compare →
AWS

AWS Private Certificate Authority: Managed Private PKI

AWS Private CA creates private certificate authority hierarchies and issues X.509 certificates for internal resources, …

Pricing Monthly price per private CA …
SLA Per provider / see official documentation
Compare →
AWS

AWS Security Incident Response: Managed Incident Response

AWS Security Incident Response automatically triages security findings and gives you 24/7 access to AWS security …

Pricing Billed by the number of security …
SLA Per provider / see official documentation
Compare →
AWS

AWS Signer - Managed Code Signing

AWS Signer signs Lambda packages, container images and IoT firmware from a central signing environment and manages the …

Pricing No additional charge when used with …
SLA As stated by the provider; see official documentation
Compare →

56 comparable products found across other clouds.

Ready to start with Assured Open Source Software - Curated OSS Packages from Google?

Our certified Google Cloud experts help you with architecture, integration, and optimization.

Schedule Consultation