🎉 2025 OpenSSF Annual Report is now live! Download Report

🎉 The 2025 OpenSSF Annual Report Has ArrivedDiscover the milestones, community momentum, and ecosystem-wide wins

Read & Download Now

The Open Source Security Foundation (OpenSSF) is a community of software developers, security engineers, and more who are working together to secure open source software for the greater public good.

Collaborate on capabilities and best practices that secure open source software.

Participate in the latest community conversations and engage with experts.

Take free courses on secure coding practices as part of our certificate program.

Explore our helpful security guides to help secure your project from the start.

Members

Meet Our Members

OpenSSF Hosted Events

OpenSSF events are a great opportunity to get involved with the OpenSSF community across the security and open source ecosystem. Join us and share ideas, progress, and collaborate on securing open source software.

Read the Latest Reports From OpenSSF

OpenSSF Annual Report

2025 Annual Report

Secure Open Source Software Vision Brief 2025

Improving Risk Management Decisions with SBOM Data

Practical Guide for Building Robust AI/ML Pipeline Security

Practical Guide for Building Robust AI/ML Pipeline Security

Recent Blog Posts

BlogRecap: OpenSSF Community Day Korea 2025
December 5, 2025

Recap: OpenSSF Community Day Korea 2025

OpenSSF Community Day Korea took place on November 4, 2025, in Seoul, bringing developers and security engineers together for a day of practical discussions on software security.
BlogKubeCon Keynote Recap: “Supply Chain Reaction” and Why the OSPS Baseline Matters More Than Ever
November 19, 2025

KubeCon Keynote Recap: “Supply Chain Reaction” and Why the OSPS Baseline Matters More Than Ever

At KubeCon+CloudNativeCon North America, Stacey Potter (OpenSSF) and Adolfo GarcĂ­a Veytia delivered one of the most memorable and entertaining keynotes of the week: “Supply Chain Reaction: A Cautionary Tale in…
Tech Talk Recap: Simplifying DevSecOps in Air-Gapped Environments with ZarfBlogTech Talk Recap: Simplifying DevSecOps in Air-Gapped Environments with Zarf
November 18, 2025

Tech Talk Recap: Simplifying DevSecOps in Air-Gapped Environments with Zarf

In the latest OpenSSF Tech Talk, we focused on a significant hurdle in software supply chain security: managing software delivery and upkeep within air-gapped and restricted network environments. You can…

Open source software is pervasive in data centers, consumer devices, and applications. Securing open source software requires fostering collaboration, establishing best practices, and developing innovative solutions.

Join the growing list of organizations supporting the advancement of securing open source technology and funding the development and adoption of OpenSSF initiatives.

Explore Membership in OpenSSF