TL;DR
The NHS closed public access to open source repositories after receiving vulnerability reports, raising concerns about security transparency. GDS (Government Digital Service) commented on this decision, arguing that closing repositories may harm rather than help security.
✦ Why It Matters
Understand how government technology decisions about code transparency affect security practices and open source adoption strategies.
Key Takeaways
Full Summary
The NHS recently decided to close access to its open source repositories due to reported vulnerabilities from Project Glasswing, a move criticized by Terence Eden. The Government Digital Service (GDS) responded with a report advocating for 'open by default' policies in the public sector.
They argue that making everything private incurs additional costs and limits the potential for code reuse and public scrutiny. GDS's stance reflects a broader concern about the implications of restricting access to public sector code, suggesting that openness should be prioritized unless closure is absolutely necessary.
This public disagreement within the UK's Civil Service is notable, as such discussions typically remain internal. The GDS's recommendations could influence future policies regarding open source in government projects.
Related