Guest blog opportunities are open to members, working groups in collaboration, and with limited exceptions for active contributors and thought leaders. Share your insights on open source security with our community.
OpenSSF Blog
Aug 28, 2026 |
Introducing BOMHort: Kubernetes-Native SBOM Visualization & Governance at Scale Joins the OpenSSF Sandbox
As regulatory requirements like the EU Cyber Resilience Act (CRA), NIST SSDF, and Executive Order 14028 take effect, generating a Software Bill of Materials (SBOM) has shifted from a best practice to a strict requirement. However, for platform and security teams, generating SBOMs is only half the battle. Managing, querying,… Read more.
Aug 27, 2026 |
In Blog
Join OpenSSF at AGNTCon + MCPCon North America: Securing Agentic AI
Join OpenSSF at AGNTCon + MCPCon North America this October to explore the Secure Agentic Framework (SAF) and learn how to secure the future of agentic AI ecosystems. Read more.
Aug 26, 2026 |
Case Study: Conquering the EU Cyber Resilience Act (CRA) with 1,400 Upstream Security Fixes
Ericsson Software Technology successfully met the stringent obligations of the EU Cyber Resilience Act (CRA) by fundamentally shifting to upstream collaboration. Guided by OpenSSF principles, they eliminated private forks and contributed over 1,400 dependency updates and security fixes directly to open source communities. Read more.
Aug 11, 2026 |
CRA Readiness: A Practitioner’s Guide to Compliance
The EU Cyber Resilience Act (CRA) is no longer a future regulatory discussion; it is an immediate operational reality. With the September 2026 reporting deadline rapidly approaching and full compliance required by December 2027, software manufacturers, commercial entities, open source stewards, and foundations must establish a clear, pragmatic path forward.… Read more.
Aug 6, 2026 |
Announcing OpenBao v2.6!
We are thrilled to announce the availability of OpenBao v2.6, adding per-namespace sealing and the new workflow engine for cross-plugin communication! Read more.
Jul 29, 2026 |
In Blog
OpenSSF Community Day Europe 2026: Schedule Highlights & What to Expect
OpenSSF Community Day Europe 2026 (October 6 in Prague), focuses on open source software security, regulatory compliance like the EU CRA, and AI supply chain risks. The one-day event features technical sessions on tools like VEX, Gemara, and Sigstore, offering direct collaboration with maintainers and security experts. Read more.
Jul 28, 2026 |
What Is a Dependency Firewall?
A dependency firewall is a security checkpoint that evaluates open source packages before they are installed. It can protect developer workstations, build environments, CI/CD pipelines, and AI coding agents by blocking packages that appear malicious, suspicious, or inconsistent with organizational policy. Read more.
Jul 22, 2026 |
OpenSSF Community Day North America (NA) First-time Experience
My recent experience in Minneapolis revealed that these gatherings are more than simple meetings; they are collaborative ecosystems. Whether you are a maintainer or a first-time contributor, attending provides invaluable insights, fosters transparency, and accelerates project development. Read more.
Jul 21, 2026 |
Representing OpenSSF at AfricaCyberFest
Open source software is playing an important role in Africa's digital growth. Across the continent, more organizations, developers, and communities are adopting open source to build technology and solve local challenges. Read more.
Jul 16, 2026 |
In Blog
Navigating The OpenSSF is as Easy as Floating Down A Lazy River
Navigating the vast ecosystem of the Open Source Security Foundation (OpenSSF) is now as easy as floating down a lazy river. Discover our newly curated, role-based User Journeys designed to seamlessly guide developers, security engineers, OSPO leaders, marketers, and executives to the exact tools, resources, and communities they need. Read more.









