Workstreams

Where the work happens — in the open.

Three workstreams carry the alliance's mission: an open remediation standard so fixes are portable and verifiable, shared tooling that prioritises the backlog on one neutral basis, and the road to regulated consumption at scale. All of it runs under the OSERA Guiding Principles — open, portable, and lock-in-free.

The workstreams

Three streams, one mission

The alliance's workstreams are live and open. Any FINOS member can participate in the working groups — no OSERA membership required.

WS1 · ACTIVE — WORKING GROUP

Remediation Standards

One open standard so a fix from any producer is portable, verifiable and lock-in-free: it defines when a patched release is accepted into the OSERA repository — evidencing, signing, attestations, testing and conformance automation — aligned with Akrites, OpenSSF and the SCA ecosystem. Chaired by Dov Katz (Morgan Stanley).

WS2 · ACTIVE — SHARED TOOLING

Risk Navigator

Where shared prioritisation happens. Cross-firm demand, severity and exposure are scored on one neutral basis to order the shared remediation backlog — so machine-speed CVE waves are triaged automatically, not in committee.

WS3 · FUTURE FOCUS

Regulated Consumption at Scale

The next frontier: consuming fixes in time across a regulated estate — and proving it. Regulatory compliance evidencing and shared consumption tools and recipes, alongside FINOS CALM.

  • Consumption evidence, mapped to DORA, NIS2 & CRA
  • Shared tools & recipes for rollout at scale
  • Working group proposed for ratification next
  • Register your interest

How to participate

Working-group meetings and mailing lists are open to FINOS members only — but no OSERA membership is required. Not yet a member? Become a FINOS member.

An initial draft of proposed patching standards is available at standards.osera.finos.org

FINOS Labs
Available tooling

Prioritise open source remediation with Risk Navigator

Risk Navigator is where the alliance's shared prioritisation happens: it turns dependency and vulnerability data into one neutral remediation view — what is exposed, which projects are affected, and where upgrades or backpatches should be prioritised across firms.

From vulnerable libraries to action

Use the overview to inspect vulnerable packages, CVEs, affected projects, safe versions, and backpatch candidates before bringing work into the OSERA formation process.

  • Rank libraries by CVSS, KEV, EPSS, project footprint, and upgrade path.
  • See which applications are directly or transitively exposed.
  • Identify candidates for upgrade guidance, OpenRewrite recipes, or backpatch work.
Risk Navigator prioritization interface showing vulnerable libraries, CVEs, affected projects, and remediation details
The output feeds the alliance's shared backlog: the 60 backpatch lines already maintained on GitHub started here. See how the whole loop works.

Ready to roll up your sleeves?

Tech vendors join the working groups and bid to maintain through FINOS membership. Financial institutions fund and govern through OSERA membership. And because every line is open source, anyone can build it themselves.