OSERA is the Open Source Enterprise Resiliency Alliance: a FINOS initiative helping regulated institutions close patch coverage gaps and operationalize remediation at scale. We help participants prioritize vulnerabilities, sponsor open back-patches, define shared consumption standards, and apply patches from upstream, vendors, and elsewhere - with greater consistency and evidence. A neutral, member-governed answer to a global problem — built so institutions of every size, in every jurisdiction, can consume it. Operational resilience, without the lock-in.
The sector runs strikingly similar software — the same core libraries, in the same versions — so a flaw in one is a flaw in all. J.P. Morgan's Patchmageddon report puts numbers on it: disclosures have outrun the sector's capacity to patch, and exploitation now starts the day a CVE goes public. And the weakest links are rarely the largest firms: systemic resilience only works if institutions of every size, in every country, can afford the same fix. Incubated in financial services, where the regulatory bar is highest, the model is built to serve any regulated enterprise. Open collaboration is the neutral, sovereign way to provide the shared answer — no single vendor, and no single jurisdiction, controls it.
of open source dependencies sit unmanaged and outdated — resilience is a consumption problem, not just a patching one.
institutions are confident the components they consume are maintained and current. The rest are the weak links.
of exploitations now begin on or before the day the CVE is disclosed — up from 19% in 2018. The window to apply a known fix has collapsed.
financial services firms report different teams independently maintaining forks of the same open source project — the "fork tax", paid many times over.
We apply fixes for known CVEs to the exact projects and versions the sector still runs — prioritised across firms in Risk Navigator, and accepted into the repository only through the Remediation Standards gate. The source stays open and offered upstream; member-ready release sits behind membership.
Offered back to the original project wherever it is alive — free and public for the whole community.
The canonical maintained source, fully transparent and auditable — for the cases upstream can't take the fix.
Built, signed artifacts members consume through their existing proxy — the coordinates they already use, no CI change.
The alliance has piloted 60 backpatch lines on GitHub, spanning the critical Java projects the sector still runs — starting with these lines, validated end-to-end by member banks through existing proxies with the coordinates they already use.
Open to institutions of every size and to technology firms with upstream expertise, anywhere in the world. Not sure yet? Review the active workstreams — where the work happens, with participation open to FINOS members — before deciding to become a member. Three ways in — pick yours.
Fund and govern the alliance — and consume member-ready patched releases at your scale. A global, sovereign option to reduce operational risk, with General-tier fees sized so smaller FSIs can drastically improve their resiliency too.
Become an OSERA memberBecome a vendor maintainer and join the OSERA workstreams to contribute to standards and prioritization to reduce downstream friction — open to every FINOS member, no OSERA membership required.
Become a FINOS memberAll OSERA source is public under the upstream project license — explore the backpatch lines and standards on GitHub and build from source yourself. Where upstream is receptive, patches will be submitted to the original maintainers.
Go to GitHubTwo simple tiers and benefits for existing FINOS members. OSERA is a global initiative: the General tier is designed for banks of all sizes, with accessible fees so smaller FSIs anywhere in the world can drastically improve their resiliency.
| Premier | General | FINOS Member | |
|---|---|---|---|
| Annual fee | $100k | $15k–$90k by firm size | |
| Approve / sunset projects for maintenance | ✓ | ||
| Approve maintenance scope, SLAs & vendor maintainer bids | ✓ | ||
| Governing board seat | ✓ | 1 for the whole class | |
| Committees seat | ✓ | 1 for the whole class | |
| Member-only access to patched releases | ✓ | ✓ | |
| Propose new projects | ✓ | ✓ | |
| Working group participation | ✓ | ✓ | ✓ |
Working-group participation — and bidding to become a vendor maintainer — is open to all FINOS members. No OSERA membership required.
See full charter and not-for-execution participation agreement. Click below to start the enrollment process.
Use the form below to propose a project for the alliance to consider maintaining, offer your firm as a tech producer, or share your interest in joining the effort. The FINOS team will follow up with next steps.
Form submissions route to membership@finos.org. Prefer to talk first? Join the weekly Supply Chain Resiliency formation call.