OpenSSF Blog

Guest blog opportunities are open to members, working groups in collaboration, and with limited exceptions for active contributors and thought leaders. Share your insights on open source security with our community.

Aug 28, 2026 | OpenSSF

Introducing BOMHort: Kubernetes-Native SBOM Visualization & Governance at Scale Joins the OpenSSF Sandbox

As regulatory requirements like the EU Cyber Resilience Act (CRA), NIST SSDF, and Executive Order 14028 take effect, generating a Software Bill of Materials (SBOM) has shifted from a best practice to a strict requirement. However, for platform and security teams, generating SBOMs is only half the battle. Managing, querying,… Read more.

Aug 27, 2026 | OpenSSF

In Blog

Join OpenSSF at AGNTCon + MCPCon North America: Securing Agentic AI

Join OpenSSF at AGNTCon + MCPCon North America this October to explore the Secure Agentic Framework (SAF) and learn how to secure the future of agentic AI ecosystems. Read more.

Aug 26, 2026 | OpenSSF

Case Study: Conquering the EU Cyber Resilience Act (CRA) with 1,400 Upstream Security Fixes

Ericsson Software Technology successfully met the stringent obligations of the EU Cyber Resilience Act (CRA) by fundamentally shifting to upstream collaboration. Guided by OpenSSF principles, they eliminated private forks and contributed over 1,400 dependency updates and security fixes directly to open source communities. Read more.
Tech Talk: CRA Readiness: A Practitioner’s Guide to Compliance

Aug 11, 2026 | aliu

CRA Readiness: A Practitioner’s Guide to Compliance

The EU Cyber Resilience Act (CRA) is no longer a future regulatory discussion; it is an immediate operational reality. With the September 2026 reporting deadline rapidly approaching and full compliance required by December 2027, software manufacturers, commercial entities, open source stewards, and foundations must establish a clear, pragmatic path forward.… Read more.

Aug 6, 2026 | OpenSSF

Announcing OpenBao v2.6!

We are thrilled to announce the availability of OpenBao v2.6, adding per-namespace sealing and the new workflow engine for cross-plugin communication! Read more.

Jul 29, 2026 | aliu

In Blog

OpenSSF Community Day Europe 2026: Schedule Highlights & What to Expect

OpenSSF Community Day Europe 2026 (October 6 in Prague), focuses on open source software security, regulatory compliance like the EU CRA, and AI supply chain risks. The one-day event features technical sessions on tools like VEX, Gemara, and Sigstore, offering direct collaboration with maintainers and security experts. Read more.

Jul 28, 2026 | OpenSSF

What Is a Dependency Firewall?

A dependency firewall is a security checkpoint that evaluates open source packages before they are installed. It can protect developer workstations, build environments, CI/CD pipelines, and AI coding agents by blocking packages that appear malicious, suspicious, or inconsistent with organizational policy. Read more.

Jul 22, 2026 | OpenSSF

OpenSSF Community Day North America (NA) First-time Experience

My recent experience in Minneapolis revealed that these gatherings are more than simple meetings; they are collaborative ecosystems. Whether you are a maintainer or a first-time contributor, attending provides invaluable insights, fosters transparency, and accelerates project development. Read more.

Jul 21, 2026 | OpenSSF

Representing OpenSSF at AfricaCyberFest

Open source software is playing an important role in Africa's digital growth. Across the continent, more organizations, developers, and communities are adopting open source to build technology and solve local challenges. Read more.

Jul 16, 2026 | OpenSSF

In Blog

Navigating The OpenSSF is as Easy as Floating Down A Lazy River

Navigating the vast ecosystem of the Open Source Security Foundation (OpenSSF) is now as easy as floating down a lazy river. Discover our newly curated, role-based User Journeys designed to seamlessly guide developers, security engineers, OSPO leaders, marketers, and executives to the exact tools, resources, and communities they need. Read more.