HR 3286 United States House · 118th Congress

Securing Open Source Software Act of 2023

This bill requires the Director of the Cybersecurity and Infrastructure Security Agency (CISA) to develop a framework for assessing risks in open source software components used by federal agencies. It mandates annual assessments of critical open source software, considering factors like security practices, deployment scope, and community health, and requires public sharing of results and tools. The law directly affects federal agencies (which must use these assessments) and the open source software community (which must be consulted in framework development). Key provisions include publishing risk frameworks, automating assessments, and conducting a study on extending assessments to critical infrastructure sectors.
Sub-Topics: Cybersecurity
Bill status in committee 1 of 4 stages cleared
Introduction
May 2023
Committee Review
Floor Vote
President
Introduced May 15, 2023 Last action Jul 27, 2023
Floor votes

How they voted

No floor votes recorded yet.
Full legislative history

Actions timeline

Total actions
7
Key actions
3
Committee
4
Amendments
1
Jul 27, 2023
Lower · Passed
Committee on Oversight and Accountability discharged.
lower
Jul 27, 2023
Lower · Passed
Reported (Amended) by the Committee on Homeland Security. H. Rept. 118-160, Part I.
lower
May 17, 2023
Introduced
Ordered to be Reported (Amended) by Voice Vote.
lower
May 17, 2023
Lower · Passed
Committee Consideration and Mark-up Session Held.
lower
May 15, 2023
Committee
Referred to the Committee on Homeland Security, and in addition to the Committee on Oversight and Accountability, for a period to be subsequently determined by the Speaker, in each case for consideration of such provisions as fall within the jurisdiction of the committee concerned.
lower
May 15, 2023
Introduced
Introduced in House
lower
1 primary · 3 co-sponsors

Sponsors