Navigating the EU’s Cyber Resilience Act (CRA)? Get our free eBook.

Free eBook

The Open Source Security Foundation (OpenSSF) is a community of software developers, security engineers, and more who are working together to secure open source software for the greater public good.

Collaborate on capabilities and best practices that secure open source software.

Participate in the latest community conversations and engage with experts.

Take free courses on secure coding practices as part of our certificate program.

Explore our helpful security guides to help secure your project from the start.

OpenSSF Hosted Events

OpenSSF events are a great opportunity to get involved with the OpenSSF community across the security and open source ecosystem. Join us and share ideas, progress, and collaborate on securing open source software.

Read the Latest Reports From OpenSSF

2026 CRA Awareness and Readiness Report

CRA Awareness and Readiness Report

Securing Open Source in the Age of AI

Securing Open Source in the Age of AI

Gemara: A Governance, Risk, and Compliance Engineering Model for Automated Risk Assessment

Gemara: A Governance, Risk, and Compliance Engineering Model for Automated Risk Assessment

Recent Blog Posts

BlogEU Cyber Resilience ActGuest BlogOpen by Default After AI: The GDS Guidance and the Enforcement Question
September 10, 2026

Open by Default After AI: The GDS Guidance and the Enforcement Question

September 2026 By Sal Kimmich and Simon John Executive Summary In early May 2026, NHS England issued a reported internal guidance note, SDLC-8, mandating the removal of public access to…
BlogOpenSSF at Hacker Summer Camp 2026: Black Hat & DEF CON Highlights and Recap
September 4, 2026

OpenSSF at Hacker Summer Camp 2026: Black Hat & DEF CON Highlights and Recap

Las Vegas was once again the center of the cybersecurity universe from August 1–9 for Black Hat and DEF CON 2026. The Open Source Security Foundation (OpenSSF) had a major…
BlogGuest BlogIntroducing BOMHort: Kubernetes-Native SBOM Visualization & Governance at Scale Joins the OpenSSF Sandbox
August 28, 2026

Introducing BOMHort: Kubernetes-Native SBOM Visualization & Governance at Scale Joins the OpenSSF Sandbox

As regulatory requirements like the EU Cyber Resilience Act (CRA), NIST SSDF, and Executive Order 14028 take effect, generating a Software Bill of Materials (SBOM) has shifted from a best…

Open source software is pervasive in data centers, consumer devices, and applications. Securing open source software requires fostering collaboration, establishing best practices, and developing innovative solutions.

Join the growing list of organizations supporting the advancement of securing open source technology and funding the development and adoption of OpenSSF initiatives.

Explore Membership in OpenSSF