Major Banks Back OSERA to Deliver Industry Wide Remediation Standards and Fixes to Secure Open Source Software
PRAGUE, Oct. 7, 2026
Press Release Disclaimer: This is a press release distributed through the XPR Media network. It has not been independently verified by our newsroom.

![]()
Major Banks Back OSERA to Deliver Industry Wide Remediation Standards and Fixes to Secure Open Source Software
PR Newswire
PRAGUE, Oct. 7, 2026
Within 100 days, OSERA welcomed 6 Premier members, established an open standard for AI-scale remediation and attestation of vulnerabilities in open source software, and delivered patches for more than 50 commonly used projects in the Java ecosystem.
PRAGUE, Oct. 7, 2026 /PRNewswire/ — Open Source Summit Europe – The Fintech Open Source Foundation (FINOS), the financial services vertical of the Linux Foundation, today announced at Open Source Summit Europe that the Open Source Enterprise Resiliency Alliance (OSERA) is operational. Initial funding comes from six Premier members including Deutsche Bank, Goldman Sachs, Morgan Stanley, NatWest, and Royal Bank of Canada (RBC).
![]()
Financial institutions rely heavily on similar open source software stacks. When a security vulnerability is discovered in one of these widely used projects, banks can end up developing or commissioning the same fixes separately OSERA addresses these redundancies by giving financial institutions a shared, open and transparent way to identify, fix and verify vulnerabilities in the open source software they rely on. By working together, members can reduce duplicated effort while helping strengthen the software that underpins the financial services industry.
What’s available today
Following the intent-to-form announcement in June, in a matter of weeks, OSERA delivered:
- An open standard for fixing and verifying vulnerabilities: Within 3 weeks of operation, OSERA released the first version of its patching and attestation standard, developed through collaboration between financial institutions, patch producers and open source infrastructure leaders. The standard sets out the requirements a fix must adhere to before it can be trusted and used at scale, helping organizations adopt fixes more consistently and with greater confidence.
- First wave of high value patched projects: The alliance prioritized and delivered secure package updates with standard attestations across more than 50 widely used open source projects in the Spring and Java ecosystems. These remediations addressed publicly disclosed security vulnerabilities (CVE) and are available for immediate production usage by OSERA members. Moving forward, vendor maintainers will address newly disclosed vulnerabilities on these managed lines under a severity-based software license agreement (SLA).
“An open, verifiable standard for remediation delivers trust at scale,” said Dov Katz, Managing Director and Distinguished Engineer at Morgan Stanley, and Chair of the OSERA Remediation Standards Working Group. “That v0.1 was able to be published so efficiently shows the sector’s desire to set its own high standard for what a patch must prove before anyone consumes it. This is especially critical to enable actual risk mitigation in production, as the industry at large is consuming open source from the community and from multiple patch vendors and coalitions.”
To review the supported lines and the Remediation Standards, review the OSERA Prospectus.
A sovereign option for open source supply chain resiliency in the era of AI
Because financial institutions often rely on the same open source software, addressing vulnerabilities independently creates unnecessary cost and duplication across the industry. This is compounded by research showing that 1 in 5 financial institutions have separate teams maintaining private versions of the same projects, creating a “fork tax” that increases maintenance costs and technology risk.
As cyber threats evolve, addressing known vulnerabilities quickly and consistently is increasingly important. OSERA provides an open, member-governed approach that enables financial institutions, technology providers and maintainers to coordinate vulnerability responses that strengthen the open source software the industry relies on.
New resiliency regulations such as DORA, NIS2 and the EU Cyber Resilience Act are increasing expectations for global institutions to demonstrate robust, repeatable approaches to managing software vulnerabilities across complex technology ecosystems. OSERA can work alongside existing commercial and community support models: its source code is public, its governance is member-led under the Linux Foundation, and its standards are open. Recent efforts also demonstrate that organizations can use the service without changing their existing development processes, using existing proxies and package coordinates without requiring CI changes.
“OSERA turns open source resiliency from a fragmented internal burden into a collective operational capability and we are proving it with fast delivery this year, not a roadmap,” said Gabriele Columbro, Executive Director of FINOS. “Upstream initiatives like Akrites secure the commons. OSERA is the regulated downstream: signed, standards-gated remediation delivered into production environments, on terms the industry itself sets.”
Looking ahead
The alliance has defined a target delivery schedule through the end of 2026:
- Produce a minimum of 80 patches per month. Under the alliance’s SLA, vendor maintainer Moderne will deliver patches to a secured platform with quarantine gates, being built by open source security experts ControlPlane. Growing participation from HeroDevs, RapidFort, Sonatype and Scott Logic will continue to develop the standardization process and accelerate production use of supported software versions.
- Deliver the first end-to-end release of the OSERA platform at the Open Source in Finance Forum NY in November. This is expected to continue driving down the cost per patch, enabling increased software coverage and capacity to respond to increases in AI vulnerabilities.
- Develop a per-project sponsorship model that lets firms directly fund and boost projects they depend on, in addition to the common pool prioritization.
- Collaborate with sister initiatives like Akrites. OSERA is highly complementary to Linux Foundation initiatives like Akrites, and will promote collaboration on remediation standards, and financial services priorities to compound value and avoid duplication.
Designed for every industry constituent
OSERA offers an open-first, transparent operational model suitable for everyone. While OSERA addresses a critical need for financial institutions, it is designed to provide benefits for all constituents in the software supply chain, from commercial patch producers to software composition analysis and registry vendors.
To get involved:
- Financial institutions should join as OSERA members to consume financial services-grade hardened releases.
- Open source infrastructure vendors should become FINOS members to actively contribute to and ultimately adopt the remediation standards, ensuring their offerings meet the financial industry’s needs.
- Commercial maintainers and patch producers should also consider becoming FINOS members to participate in remediation standards and be eligible to become vendor maintainers under alliance SLAs.
- Everyone can rebuild fixeson GitHub as hardened project lines.
Supporting Quotes
Peter Thomas, Managing Director, Distinguished Engineer, Deutsche Bank:
“The strength of OSERA lies in its practical execution inside existing enterprise environments. In our initial pilots, we proved that banks can pull hardened, standard-compliant releases through standard corporate proxies with zero friction to existing development pipelines. Replacing duplicate internal patching efforts with a shared, high-trust pipeline is a huge win for the industry.”
Abe Batthish, Vice President, DevOps, RBC:
“So much of what we build runs on open source, and we want to help keep it safe and viable for everyone in the industry. RBC is excited to help lead the governance of OSERA’s backpatching pipelines, holding vendor maintainers to clear standards and SLAs so every fix meets the same bar no matter who produces it.”
About FINOS
FINOS (The Fintech Open Source Foundation) unites the financial services industry to build open technologies and standards that enhance profitability, improve resilience, and accelerate innovation. FINOS is the trusted community designed by regulated industry participants to solve industry-wide challenges and drive operational excellence and financial technology innovation. As part of the Linux Foundation, FINOS provides a neutral, well-governed home for open source collaboration across the industry. With a global community of more than 100 member organizations including major financial institutions, fintechs, and technology firms, FINOS advances open standards and production-grade open source for finance. This work embeds these technologies and standards into the core workflows, platforms, and policies of financial institutions, making them essential to how the industry builds, operates, and evolves. FINOS advocates for a clear focus on measurable ROI from open source adoption.
Learn more at www.finos.org.
Media Contact:
Tosha Ellison, VP Research and Communications, FINOS
tosha.ellison@finos.org
View original content to download multimedia:https://www.prnewswire.com/news-releases/major-banks-back-osera-to-deliver-industry-wide-remediation-standards-and-fixes-to-secure-open-source-software-302900065.html
SOURCE FINOS

