Are you an OpenSSF contributor with insights on open source security? Write a guest post for our blog and share your expertise with the community!
OpenSSF Blog
Apr 14, 2025 |
In Blog
Key Takeaways from VulnCon 2025: Insights from the OpenSSF Community
By Christopher Robinson (CRob), Chief Security Architect, OpenSSF VulnCon 2025 has once again proven to be an essential gathering for security professionals, fostering collaboration, innovation, and progress in vulnerability management. This matches well with the OpenSSF continued championing for transparency and best practices in open source security. Practitioners from around… Read more.
Apr 14, 2025 |
In Blog
Tech Talk Preview: Strengthening Open Source Through Security Standards and Global Policy
Open source is the backbone of today’s digital infrastructure—but with great power comes great responsibility. As cybersecurity threats grow in complexity and regulatory landscapes shift globally, open source projects are under increasing pressure to meet stringent security expectations. Read more.
Apr 9, 2025 |
In Blog
OpenSSF Community Day NA 2025 Agenda Live!
We’re excited to share that the agenda for OpenSSF Community Day North America 2025 is now live! Join us on June 26 in Denver, Colorado, for a day filled with collaboration, technical insights, and future-focused conversations on securing the open source ecosystem. Read more.
Apr 4, 2025 |
Launch of Model Signing v1.0: OpenSSF AI/ML Working Group Secures the Machine Learning Supply Chain
We are pleased to announce the launch of version 1.0 of the model-signing project, an OpenSSF project developed in the past year as part of the OpenSSF AI/ML working group. The aim of the project is to provide a library and CLI for signing and verification of ML models, supporting… Read more.
Mar 28, 2025 |
GuardDog: Strengthening Open Source Security Against Supply Chain Attacks
Datadog is a proud Open Source Security Foundation (OpenSSF) member, and we believe that being a part of this security community will lead us all to a safer place. Attackers are increasingly turning to supply chain attacks to distribute their malicious code, and the Open Source Vulnerabilities (OSV) database, to… Read more.
Mar 25, 2025 |
In Blog
Beyond the Software Bill of Materials (SBOM): Ensuring Integrity with Attestations – Event Recap
On March 5th, the SBOMit community hosted the Beyond the SBOM: Ensuring Integrity with Attestations event at The National Press Club in Washington, D.C. This event, co-located with OpenSSF Policy Summit DC, brought together industry leaders to address the limitations of single SBOMs and even signed SBOMs in ensuring software… Read more.
Mar 24, 2025 |
What will my business need to do for the EU CRA?
The European Union’s Cyber Resilience Act (CRA) is a piece of legislation that covers all countries within the EU and the EAA and entered into force on 10th December 2024. It covers many types of devices and applications that are either sold or otherwise made commercially available in Europe and… Read more.
Mar 18, 2025 |
Linux Foundation Research Reports Reveal Wide Spectrum for Cyber Resilience Act Readiness and Compliance
SAN FRANCISCO – March 18, 2024 – The Linux Foundation, the nonprofit organization enabling mass innovation through open source, today announced the publication of two groundbreaking research reports, both in partnership with the Open Source Security Foundation (OpenSSF) and Linux Foundation Europe (LF Europe), that explore community-driven strategies to address open source security and the European Union’s… Read more.
Mar 17, 2025 |
In Blog
CNCF & OpenSSF Announce Open Source SecurityCon 2025
The Cloud Native Computing Foundation (CNCF) and the Open Source Security Foundation (OpenSSF) are thrilled to introduce Open Source SecurityCon 2025—a premier event focused on strengthening cloud-native and open source software security. Read more.
Mar 14, 2025 |
OpenSSF Policy Summit DC 2025 Recap
The OpenSSF Policy Summit DC 2025 brought together open source, government, and industry leaders to tackle pressing security challenges. The event fostered open dialogue under the Chatham House Rule, emphasizing shared responsibility and commitment to strengthening the open source ecosystem. A Message from Steve Fernandez, OpenSSF General Manager, "The OpenSSF… Read more.