August 2026 - OSERA is operational: Citi, Deutsche Bank, Morgan Stanley, NatWest and RBC fund and govern the alliance as founding Premier members. Meet the members · Governing Board · Press.

Secure open source. In production. At scale.

OSERA is the Open Source Enterprise Resiliency Alliance: a FINOS initiative helping regulated institutions close patch coverage gaps and operationalize remediation at scale. We help participants prioritize vulnerabilities, sponsor open back-patches, define shared consumption standards, and apply patches from upstream, vendors, and elsewhere - with greater consistency and evidence. A neutral, member-governed answer to a global problem — built so institutions of every size, in every jurisdiction, can consume it. Operational resilience, without the lock-in.

The Downstream Dilemma — the launch video from OSFF London 2026
Read the FINOS launch announcement
The thesis

A network is only as safe as its weakest link

The sector runs strikingly similar software — the same core libraries, in the same versions — so a flaw in one is a flaw in all. J.P. Morgan's Patchmageddon report puts numbers on it: disclosures have outrun the sector's capacity to patch, and exploitation now starts the day a CVE goes public. And the weakest links are rarely the largest firms: systemic resilience only works if institutions of every size, in every country, can afford the same fix. Incubated in financial services, where the regulatory bar is highest, the model is built to serve any regulated enterprise. Open collaboration is the neutral, sovereign way to provide the shared answer — no single vendor, and no single jurisdiction, controls it.

~80%

of open source dependencies sit unmanaged and outdated — resilience is a consumption problem, not just a patching one.

1 in 3

institutions are confident the components they consume are maintained and current. The rest are the weak links.

~78%

of exploitations now begin on or before the day the CVE is disclosed — up from 19% in 2018. The window to apply a known fix has collapsed.

1 in 5

financial services firms report different teams independently maintaining forks of the same open source project — the "fork tax", paid many times over.

See how OSERA addresses this

The solution

Public sources, FSI-grade member-only releases

We apply fixes for known CVEs to the exact projects and versions the sector still runs — prioritised across firms in Risk Navigator, and accepted into the repository only through the Remediation Standards gate. The source stays open and offered upstream; member-ready release sits behind membership.

Known CVE in a [package, version]
in software the sector still runs — surfaced and prioritised across firms in Risk Navigator
Fix produced & tested
under an alliance SLA · green CI on the upstream test suite · must clear the Remediation Standards acceptance gate
The Remediation Standards are the acceptance gate: no release enters the OSERA repository until it conforms, and per the standard each release will carry attestations — cryptographic signing, full SBOMs, VEX and test evidence — that are member-only. Source stays public by default; only the built, attested release artifacts sit behind membership. Releases are time-bound — a managed bridge to a current, supported version, not a licence to stay behind. Dive deeper on The Solution page, or see the workstreams where it all happens.

Upstream first

Public

Offered back to the original project wherever it is alive — free and public for the whole community.

Public fork

Public

The canonical maintained source, fully transparent and auditable — for the cases upstream can't take the fix.

Member release

Members

Built, signed artifacts members consume through their existing proxy — the coordinates they already use, no CI change.

Explore all the Work Streams

The concept was proven: first supported lines expected in Q3 2026

Hardened Open Source piloted in bank environments

The alliance has piloted 60 backpatch lines on GitHub, spanning the critical Java projects the sector still runs — starting with these lines, validated end-to-end by member banks through existing proxies with the coordinates they already use.

Apache Camel
2.25.4+backpatch.001
Java · integration
Bouncy Castle
1.47+backpatch.001
Java · cryptography
Netty
3.10.6.Final+backpatch.001
Java · networking
Spring Framework
5.3.39+backpatch.001
Java · app framework
+Build it yourselfAll source is open on GitHub
Members resolve artifacts through their existing corporate proxy with a one line change to coordinate they already use — no code or CI changes. A per-project sponsorship model is in the works, so firms can directly fund the maintenance of the projects they depend on most — register your interest to put one forward. And because every line is open source, you can always build it yourself from GitHub. Members also get built artifacts with signing, VEX and other attestations defined by the Remediation Standards

Explore all hardened project on GitHub

Get involved

Three ways to get involved

Open to institutions of every size and to technology firms with upstream expertise, anywhere in the world. Not sure yet? Review the active workstreams — where the work happens, with participation open to FINOS members — before deciding to become a member. Three ways in — pick yours.

🏦

Financial institutions

Fund and govern the alliance — and consume member-ready patched releases at your scale. A global, sovereign option to reduce operational risk, with General-tier fees sized so smaller FSIs can drastically improve their resiliency too.

Become an OSERA member
🛠

Technology vendors

Become a vendor maintainer and join the OSERA workstreams to contribute to standards and prioritization to reduce downstream friction — open to every FINOS member, no OSERA membership required.

Become a FINOS member
📦

Build it yourself

All OSERA source is public under the upstream project license — explore the backpatch lines and standards on GitHub and build from source yourself. Where upstream is receptive, patches will be submitted to the original maintainers.

Go to GitHub

Become an OSERA member

Member benefits

Two simple tiers and benefits for existing FINOS members. OSERA is a global initiative: the General tier is designed for banks of all sizes, with accessible fees so smaller FSIs anywhere in the world can drastically improve their resiliency.

Premier General FINOS Member
Annual fee $100k $15k–$90k by firm size
Approve / sunset projects for maintenance
Approve maintenance scope, SLAs & vendor maintainer bids
Governing board seat 1 for the whole class
Committees seat 1 for the whole class
Member-only access to patched releases
Propose new projects
Working group participation

Working-group participation — and bidding to become a vendor maintainer — is open to all FINOS members. No OSERA membership required.

Governance

See full charter and not-for-execution participation agreement. Click below to start the enrollment process.

Get involved

Use the form below to propose a project for the alliance to consider maintaining, offer your firm as a tech producer, or share your interest in joining the effort. The FINOS team will follow up with next steps.

Form submissions route to membership@finos.org. Prefer to talk first? Join the weekly Supply Chain Resiliency formation call.