By codifying guidelines for each category, Aqua Security and CIS aim to establish industry-wide best practices and recommendations for mitigating open-source software risks, and to support new standards including supply-chain levels for software artifacts (SLSA) and the update framework (TUF).