<?xml version="1.0" encoding="utf-8" standalone="no"?>
<billStatus>
  <version>3.0.0</version>
  <bill>
    <number>917</number>
    <updateDate>2025-05-27T14:15:48Z</updateDate>
    <updateDateIncludingText>2025-05-27T14:15:48Z</updateDateIncludingText>
    <originChamber>Senate</originChamber>
    <originChamberCode>S</originChamberCode>
    <type>S</type>
    <introducedDate>2023-03-22</introducedDate>
    <congress>118</congress>
    <committees>
      <item>
        <systemCode>ssga00</systemCode>
        <name>Homeland Security and Governmental Affairs Committee</name>
        <chamber>Senate</chamber>
        <type>Standing</type>
        <activities>
          <item>
            <name>Reported By</name>
            <date>2023-05-16T18:57:55Z</date>
          </item>
          <item>
            <name>Markup By</name>
            <date>2023-03-29T14:45:32Z</date>
          </item>
          <item>
            <name>Referred To</name>
            <date>2023-03-22T16:03:55Z</date>
          </item>
        </activities>
      </item>
    </committees>
    <committeeReports>
      <committeeReport>
        <citation>S. Rept. 118-32</citation>
      </committeeReport>
    </committeeReports>
    <actions>
      <item>
        <actionDate>2023-05-16</actionDate>
        <sourceSystem>
          <name>Senate</name>
        </sourceSystem>
        <text>Placed on Senate Legislative Calendar under General Orders. Calendar No. 76.</text>
        <type>Calendars</type>
      </item>
      <item>
        <actionDate>2023-05-16</actionDate>
        <committees>
          <item>
            <systemCode>ssga00</systemCode>
            <name>Homeland Security and Governmental Affairs Committee</name>
          </item>
        </committees>
        <sourceSystem>
          <name>Senate</name>
        </sourceSystem>
        <text>Committee on Homeland Security and Governmental Affairs. Reported by Senator Peters with amendments. With written report No. 118-32.</text>
        <type>Committee</type>
      </item>
      <item>
        <actionDate>2023-05-16</actionDate>
        <text>Committee on Homeland Security and Governmental Affairs. Reported by Senator Peters with amendments. With written report No. 118-32.</text>
        <type>Committee</type>
        <actionCode>14000</actionCode>
        <sourceSystem>
          <code>9</code>
          <name>Library of Congress</name>
        </sourceSystem>
        <committees>
          <item>
            <systemCode>ssga00</systemCode>
            <name>Homeland Security and Governmental Affairs Committee</name>
          </item>
        </committees>
      </item>
      <item>
        <actionDate>2023-03-29</actionDate>
        <committees>
          <item>
            <systemCode>ssga00</systemCode>
            <name>Homeland Security and Governmental Affairs Committee</name>
          </item>
        </committees>
        <sourceSystem>
          <name>Senate</name>
        </sourceSystem>
        <text>Committee on Homeland Security and Governmental Affairs. Ordered to be reported without amendment favorably.</text>
        <type>Committee</type>
      </item>
      <item>
        <actionDate>2023-03-22</actionDate>
        <committees>
          <item>
            <systemCode>ssga00</systemCode>
            <name>Homeland Security and Governmental Affairs Committee</name>
          </item>
        </committees>
        <sourceSystem>
          <name>Senate</name>
        </sourceSystem>
        <text>Read twice and referred to the Committee on Homeland Security and Governmental Affairs.</text>
        <type>IntroReferral</type>
      </item>
      <item>
        <actionDate>2023-03-22</actionDate>
        <text>Introduced in Senate</text>
        <type>IntroReferral</type>
        <actionCode>10000</actionCode>
        <sourceSystem>
          <code>9</code>
          <name>Library of Congress</name>
        </sourceSystem>
      </item>
    </actions>
    <sponsors>
      <item>
        <bioguideId>P000595</bioguideId>
        <fullName>Sen. Peters, Gary C. [D-MI]</fullName>
        <firstName>Gary</firstName>
        <lastName>Peters</lastName>
        <party>D</party>
        <state>MI</state>
        <isByRequest>N</isByRequest>
      </item>
    </sponsors>
    <cosponsors>
      <item>
        <bioguideId>H001089</bioguideId>
        <fullName>Sen. Hawley, Josh [R-MO]</fullName>
        <firstName>Josh</firstName>
        <lastName>Hawley</lastName>
        <party>R</party>
        <state>MO</state>
        <sponsorshipDate>2023-03-22</sponsorshipDate>
        <isOriginalCosponsor>True</isOriginalCosponsor>
      </item>
    </cosponsors>
    <cboCostEstimates>
      <item>
        <pubDate>2023-04-06T19:34:00Z</pubDate>
        <title>S. 917, Securing Open Source Software Act of 2023</title>
        <url>https://www.cbo.gov/publication/59036</url>
        <description>As ordered reported by the Senate Committee on Homeland Security and Governmental Affairs on March 29, 2023</description>
      </item>
    </cboCostEstimates>
    <policyArea>
      <name>Government Operations and Politics</name>
    </policyArea>
    <subjects>
      <legislativeSubjects>
        <item>
          <name>Advisory bodies</name>
          <updateDate>2023-04-12T20:15:17Z</updateDate>
        </item>
        <item>
          <name>Computer security and identity theft</name>
          <updateDate>2023-04-12T20:15:17Z</updateDate>
        </item>
        <item>
          <name>Computers and information technology</name>
          <updateDate>2023-04-12T20:15:17Z</updateDate>
        </item>
        <item>
          <name>Congressional oversight</name>
          <updateDate>2023-04-12T20:15:17Z</updateDate>
        </item>
        <item>
          <name>Government information and archives</name>
          <updateDate>2023-04-12T20:15:17Z</updateDate>
        </item>
        <item>
          <name>Government studies and investigations</name>
          <updateDate>2023-04-12T20:15:17Z</updateDate>
        </item>
        <item>
          <name>Performance measurement</name>
          <updateDate>2023-04-12T20:15:17Z</updateDate>
        </item>
      </legislativeSubjects>
      <policyArea>
        <name>Government Operations and Politics</name>
        <updateDate>2023-03-27T20:32:51Z</updateDate>
      </policyArea>
    </subjects>
    <summaries>
      <summary>
        <versionCode>00</versionCode>
        <actionDate>2023-03-22</actionDate>
        <actionDesc>Introduced in Senate</actionDesc>
        <updateDate>2023-10-03T12:55:46Z</updateDate>
        <cdata>
          <text>&lt;p&gt;&lt;strong&gt;Securing Open Source Software Act of 2023&lt;/strong&gt;&lt;/p&gt; &lt;p&gt;This bill sets forth the duties of the Cybersecurity and Infrastructure Security Agency (CISA) regarding open source software security. &lt;/p&gt; &lt;p&gt;&lt;em&gt;Open source software&lt;/em&gt; means software for which the human-readable source code is made available to the public for use, study, reuse, modification, enhancement, and redistribution.&lt;/p&gt; &lt;p&gt;Specifically, CISA must&lt;/p&gt; &lt;ul&gt; &lt;li&gt;perform outreach and engagement to bolster the security of open source software; &lt;/li&gt; &lt;li&gt; support federal efforts to strengthen open source software security; &lt;/li&gt; &lt;li&gt; coordinate with nonfederal entities on efforts to ensure long-term open source software security; &lt;/li&gt; &lt;li&gt; serve as a public point of contact regarding open source software security for nonfederal entities; and &lt;/li&gt; &lt;li&gt; support federal and nonfederal supply chain security efforts by encouraging efforts to bolster open source software security.&lt;/li&gt; &lt;/ul&gt; &lt;p&gt;CISA must (1) publish a framework, incorporating government, industry, and open source software community frameworks and best practices, for assessing the risk of open source software components; (2) update the framework at least annually; and (3) ensure, to the greatest extent practicable, that the framework is usable by the open source software community.&lt;/p&gt; &lt;p&gt;The bill requires CISA to assess open source software components used by federal agencies based on the framework and provides for a pilot assessment of critical infrastructure.&lt;/p&gt; &lt;p&gt;CISA's Cybersecurity Advisory Committee may establish a software security subcommittee.&lt;/p&gt; &lt;p&gt;The Office of Management and Budget, in coordination with CISA, the Office of the National Cyber Director, and the General Services Administration, shall issue guidance on the responsibilities of the chief information officers at specified agencies regarding open source software. &lt;/p&gt;</text>
        </cdata>
      </summary>
      <summary>
        <versionCode>25</versionCode>
        <actionDate>2023-05-16</actionDate>
        <actionDesc>Reported to Senate</actionDesc>
        <updateDate>2023-10-18T19:37:52Z</updateDate>
        <cdata>
          <text>&lt;p&gt;&lt;strong&gt;Securing Open Source Software Act of 2023&lt;/strong&gt;&lt;/p&gt; &lt;p&gt;This bill sets forth the duties of the Cybersecurity and Infrastructure Security Agency (CISA) regarding open source software security. &lt;/p&gt; &lt;p&gt;&lt;em&gt;Open source software&lt;/em&gt; means software for which the human-readable source code is made available to the public for use, study, reuse, modification, enhancement, and redistribution.&lt;/p&gt; &lt;p&gt;Specifically, CISA must&lt;/p&gt; &lt;ul&gt; &lt;li&gt;perform outreach and engagement to bolster the security of open source software; &lt;/li&gt; &lt;li&gt; support federal efforts to strengthen open source software security; &lt;/li&gt; &lt;li&gt; coordinate with nonfederal entities on efforts to ensure long-term open source software security; &lt;/li&gt; &lt;li&gt; serve as a public point of contact regarding open source software security for nonfederal entities; and &lt;/li&gt; &lt;li&gt; support federal and nonfederal supply chain security efforts by encouraging efforts to bolster open source software security.&lt;/li&gt; &lt;/ul&gt; &lt;p&gt;CISA must (1) publish a framework, incorporating government, industry, and open source software community frameworks and best practices, for assessing the risk of open source software components; (2) update the framework at least annually; and (3) ensure, to the greatest extent practicable, that the framework is usable by the open source software community.&lt;/p&gt; &lt;p&gt;The bill requires CISA to assess open source software components used by federal agencies based on the framework and provides for a pilot assessment of critical infrastructure.&lt;/p&gt; &lt;p&gt;CISA's Cybersecurity Advisory Committee may establish a software security subcommittee.&lt;/p&gt; &lt;p&gt;The Office of Management and Budget, in coordination with CISA, the Office of the National Cyber Director, and the General Services Administration, shall issue guidance on the responsibilities of the chief information officers at specified agencies regarding open source software. &lt;/p&gt;</text>
        </cdata>
      </summary>
    </summaries>
    <title>Securing Open Source Software Act of 2023</title>
    <titles>
      <item>
        <titleType>Display Title</titleType>
        <titleTypeCode>45</titleTypeCode>
        <title>Securing Open Source Software Act of 2023</title>
        <updateDate>2024-07-24T15:22:19Z</updateDate>
      </item>
      <item>
        <titleType>Short Title(s) as Introduced</titleType>
        <titleTypeCode>101</titleTypeCode>
        <title>Securing Open Source Software Act of 2023</title>
        <updateDate>2024-05-24T13:41:52Z</updateDate>
        <billTextVersionName>Introduced in Senate</billTextVersionName>
        <billTextVersionCode>IS</billTextVersionCode>
      </item>
      <item>
        <titleType>Short Title(s) as Reported to Senate</titleType>
        <titleTypeCode>103</titleTypeCode>
        <title>Securing Open Source Software Act of 2023</title>
        <updateDate>2024-05-24T13:40:15Z</updateDate>
        <chamberCode>S</chamberCode>
        <chamberName>Senate</chamberName>
        <billTextVersionName>Reported to Senate</billTextVersionName>
        <billTextVersionCode>RS</billTextVersionCode>
      </item>
      <item>
        <titleType>Official Title as Introduced</titleType>
        <titleTypeCode>6</titleTypeCode>
        <title>A bill to establish the duties of the Director of the Cybersecurity and Infrastructure Security Agency regarding open source software security, and for other purposes.</title>
        <updateDate>2023-03-24T01:58:49Z</updateDate>
        <billTextVersionName>Introduced in Senate</billTextVersionName>
        <billTextVersionCode>IS</billTextVersionCode>
      </item>
    </titles>
    <textVersions>
      <item>
        <type>Reported to Senate</type>
        <date>2023-05-16T04:00:00Z</date>
        <formats>
          <item>
            <url>https://www.govinfo.gov/content/pkg/BILLS-118s917rs/xml/BILLS-118s917rs.xml</url>
          </item>
        </formats>
      </item>
      <item>
        <type>Introduced in Senate</type>
        <date>2023-03-22T04:00:00Z</date>
        <formats>
          <item>
            <url>https://www.govinfo.gov/content/pkg/BILLS-118s917is/xml/BILLS-118s917is.xml</url>
          </item>
        </formats>
      </item>
    </textVersions>
    <latestAction>
      <actionDate>2023-05-16</actionDate>
      <text>Placed on Senate Legislative Calendar under General Orders. Calendar No. 76.</text>
    </latestAction>
  </bill>
  <dublinCore xmlns:dc="http://purl.org/dc/elements/1.1/">
    <dc:format>text/xml</dc:format>
    <dc:language>EN</dc:language>
    <dc:rights>Pursuant to Title 17 Section 105 of the United States Code, this file is not subject to copyright protection and is in the public domain.</dc:rights>
    <dc:contributor>Congressional Research Service, Library of Congress</dc:contributor>
    <dc:description>This file contains bill summaries and statuses for federal legislation. A bill summary describes the most significant provisions of a piece of legislation and details the effects the legislative text may have on current law and federal programs. Bill summaries are authored by the Congressional Research Service (CRS) of the Library of Congress. As stated in Public Law 91-510 (2 USC 166 (d)(6)), one of the duties of CRS is "to prepare summaries and digests of bills and resolutions of a public general nature introduced in the Senate or House of Representatives". For more information, refer to the User Guide that accompanies this file.</dc:description>
  </dublinCore>
</billStatus>
