Navigating the EU’s Cyber Resilience Act (CRA)? Get our free eBook.

Free eBook

The Open Source Security Foundation (OpenSSF) is a community of software developers, security engineers, and more who are working together to secure open source software for the greater public good.

Collaborate on capabilities and best practices that secure open source software.

Participate in the latest community conversations and engage with experts.

Take free courses on secure coding practices as part of our certificate program.

Explore our helpful security guides to help secure your project from the start.

OpenSSF Hosted Events

OpenSSF events are a great opportunity to get involved with the OpenSSF community across the security and open source ecosystem. Join us and share ideas, progress, and collaborate on securing open source software.

Read the Latest Reports From OpenSSF

2026 CRA Awareness and Readiness Report

CRA Awareness and Readiness Report

Securing Open Source in the Age of AI

Securing Open Source in the Age of AI

Gemara: A Governance, Risk, and Compliance Engineering Model for Automated Risk Assessment

Gemara: A Governance, Risk, and Compliance Engineering Model for Automated Risk Assessment

Recent Blog Posts

BlogGuest BlogIntroducing BOMHort: Kubernetes-Native SBOM Visualization & Governance at Scale Joins the OpenSSF Sandbox
August 28, 2026

Introducing BOMHort: Kubernetes-Native SBOM Visualization & Governance at Scale Joins the OpenSSF Sandbox

As regulatory requirements like the EU Cyber Resilience Act (CRA), NIST SSDF, and Executive Order 14028 take effect, generating a Software Bill of Materials (SBOM) has shifted from a best…
BlogJoin OpenSSF at AGNTCon + MCPCon North America: Securing Agentic AI
August 27, 2026

Join OpenSSF at AGNTCon + MCPCon North America: Securing Agentic AI

Join OpenSSF at AGNTCon + MCPCon North America this October to explore the Secure Agentic Framework (SAF) and learn how to secure the future of agentic AI ecosystems.
BlogCase StudiesEU Cyber Resilience ActCase Study: Conquering the EU Cyber Resilience Act (CRA) with 1,400 Upstream Security Fixes
August 26, 2026

Case Study: Conquering the EU Cyber Resilience Act (CRA) with 1,400 Upstream Security Fixes

Ericsson Software Technology successfully met the stringent obligations of the EU Cyber Resilience Act (CRA) by fundamentally shifting to upstream collaboration. Guided by OpenSSF principles, they eliminated private forks and…

Open source software is pervasive in data centers, consumer devices, and applications. Securing open source software requires fostering collaboration, establishing best practices, and developing innovative solutions.

Join the growing list of organizations supporting the advancement of securing open source technology and funding the development and adoption of OpenSSF initiatives.

Explore Membership in OpenSSF