Video by FINOS via YouTube

Learn how to scale open-source remediation across 50,000+ repositories using OSERA standards and new tooling.
Dov Katz (Managing Director at Morgan Stanley) addresses the massive operational challenge of remediating software vulnerabilities across enterprises maintaining tens of thousands of source code repositories. He details how the OSERA (Open Source Enterprise Resiliency Alliance) initiative establishes low-risk back-patching tooling – such as the open-source Risk Navigator – and unifies financial industry standards to push back against fragmented, unstandardized private security patches.
π½ Catch Us in New York! Join global financial leaders shaping open-source supply chain standards and enterprise security at OSFF New York on November 4β5, 2026.
ποΈ Register Now: https://hubs.ly/Q04n_bZL0
π₯ 20% OFF DISCOUNT CODE: 26YTOSFFNY20C
π Timestamps:
0:00 Managing Security Across 50,000+ Source Code Repositories
1:00 OSERA Tools & Operating Model: Local Scans & Low-Risk Back-Patching
2:14 Setting Industry Standards: Pushing Back on Proprietary Patches
3:20 Standardized Naming Conventions: Unifying the Voice of the Industry
π The Problem: The Enterprise Repository Patching Flood
Large financial institutions maintain tens of thousands of source code repositories (often exceeding 50,000 repos). When vendors and third parties flood the market with uncoordinated, private patches lacking standardized version numbers or uniform labeling, enterprise platform teams face paralysis. Without agreed-upon naming conventions, institutions cannot safely determine upgrade paths or automate remediation across their entire software estate without risking production breakage. ποΈ The Solution: OSERA Tooling & Unified Naming Standards
Dov Katz outlines OSERAβs dual approach to scaling vulnerability remediation: Risk Navigator Tooling: Scanning internal software estates locally to isolate "dead-end" dependencies and execute low-risk, adjacent-version back-patches instead of forcing dangerous major version upgrades. Collective Industry Voice: Establishing clear, standardized naming conventions and public back-patching principles so institutions can present unified requirements to patch providers and design partners.
βοΈ Why This Matters for Financial EngineeringEliminating Upgrade Friction:
Standardized patch metadata allows automated tooling and agentic fleets to parse and apply dependency updates across 50,000+ repositories deterministically. Safe Space Collaboration: Financial institutions work together in a neutral venue to mutualize patch capacity and compel upstream suppliers to adhere to enterprise security standards.
Managing security at scale is a significant hurdle for financial institutions. Patching vulnerabilities individually is no longer sufficient when dealing with thousands of repositories. This session outlines the OSERA framework, designed to move beyond fragmented fixes toward a unified industry approach for the software supply chain.
By implementing consistent security standards, teams can prioritize effectively and reduce technical debt. We explore how tools like Risk Navigator facilitate this, offering a path to deploy critical patches within hours rather than weeks. This proof of concept demonstrates how an open operating model can streamline your entire maintenance lifecycle.
π More about FINOS: https://www.finos.org/
π§ Join our newsletter: https://www.finos.org/sign-up
ποΈ Listen to our Open Source in Finance Podcast: https://www.youtube.com/@FINOS/podcasts
LinkedIn: https://www.linkedin.com/company/finosfoundation
#FINOS #OSFFNewYork #OSERA #MorganStanley #DevSecOps #SupplyChainSecurity #PatchManagement #OpenSource #fintech