Backpatch Alliance is the fellowship of the fix.
AI-accelerated vulnerability discovery in OSS drives the need for backpatches to quickly close security gaps. EOL OSS backpatch vendors are predatory. Join the community to fight back.
The community funds the production of patches; members own the fix in perpetuity. Fixes are in the open, so you can see exactly what changed, how it was tested and published.
Moderne experts drive production of patches at cost, because it complements Moderne’s core value of multi-repo code change distribution (patch installation).
Add the repository to your build, then change the version of the library you are patching.
A backpatch applies an upstream security fix to an open source release that no longer receives fixes, and
publishes it under a version derived from that release. A fix for 2.14.1 ships as
2.14.1.1-backpatch-00001.
Anyone can browse the catalog, open any pom, module metadata, CycloneDX document, checksum or signature, and read the feeds. Downloading a backpatch requires an Alliance membership, which comes with a username and an access token.
Credentials go where they would for any other private repository, with your access token as the password.
Maven in settings.xml
The profile adds the repository to every build on the machine, and the server entry supplies the credentials
Maven sends to it. Both use the same backpatch id.
<settings>
<servers>
<server>
<id>backpatch</id>
<username>acme</username>
<password>bpa_…</password>
</server>
</servers>
<profiles>
<profile>
<id>backpatch</id>
<repositories>
<repository>
<id>backpatch</id>
<url>https://backpatch.moderne.io/maven/</url>
</repository>
</repositories>
</profile>
</profiles>
<activeProfiles>
<activeProfile>backpatch</activeProfile>
</activeProfiles>
</settings>
Then set the dependency to the backpatch version the catalog lists.
<dependency>
<groupId>com.google.code.gson</groupId>
<artifactId>gson</artifactId>
<version>2.8.8.1-backpatch-00001</version>
</dependency>
Gradle in build.gradle.kts
Declare the repository alongside Maven Central, and keep the token in ~/.gradle/gradle.properties
rather than in the build script.
repositories {
mavenCentral()
maven {
url = uri("https://backpatch.moderne.io/maven/")
credentials {
username = providers.gradleProperty("backpatchUser").get()
password = providers.gradleProperty("backpatchToken").get()
}
}
}
dependencies {
implementation("com.google.code.gson:gson:2.8.8.1-backpatch-00001")
}
Your scanner needs the a feed to stop reporting a CVE that a backpatch fixed.
Scanners compare versions against advisory ranges, and a backpatch version still falls inside the range of the release it patches. The feeds page shows how Grype, Trivy, JFrog Xray, Sonatype, and Dependency-Track read the statements that mark those findings as fixed.
Backpatch Alliance dual publishes VEX and CycloneDX data to support scanners as they are.