OpenSSF
OpenSSF Newsletter – November 2024
Welcome to the November 2024 edition of the OpenSSF Newsletter! Here’s a roundup of the latest developments, key events, and upcoming opportunities in the Open Source Security community. Apply: Lead...
Understanding the CRA: OpenSSF’s Role in the Cyber Resilience Act Implementation – Part 1
With publishing as Regulation (EU) 2024/2847 in the Official Journal of the European Union, the Cyber Resilience Act (CRA) enters into force (EIF) on December 10, 2024. The CRA will fully apply three years later, on December 11, 2027. The CRA will obligate all products with digital elements, including their remote data processing, put on…
The OpenSSF Armored Goose “Honk”: Advancing Open Source Security
The Open Source Security Foundation (OpenSSF) logo presents a compelling visual narrative featuring “Honk”, an armored goose holding a shield. This unique and creative mascot perfectly embodies the foundation's mission in open source security. Why the goose?
How We Can Learn from Open Source Software to Address the Challenges of AI
With the development of new artificial intelligence (AI) models and capabilities, attention has been drawn to their potential harms and misuse: from generating deepfakes and disinformation, algorithmic bias, or being used to perpetuate other harms or biases.
Red Hat’s Collaboration with the OpenSSF and OSV.dev Yields Results: Red Hat Security Data Now Available in the OSV Format
OSV is an open format for describing software vulnerabilities. It provides security researchers, vendors, and consumers with an easy to understand format for exchanging vulnerability information. OSV.dev is a database that hosts and aggregates OSV data.
OpenSSF Welcomes New Members and Introduces New Initiatives at SOSS Community Day Japan
Growing Member Base and New Initiatives Continue to Advance Open Source Software Security TOKYO, JAPAN – October 30, 2024 – The Open Source Security Foundation (OpenSSF), a global cross-industry initiative...
OpenSSF Adds Minder as a Sandbox Project to Simplify the Integration and Use of Open Source Security Tools
Today, I’m excited to announce that Stacklok is contributing our Minder open source project to the Open Source Security Foundation (OpenSSF). Minder makes it simpler for developers and security teams to adopt a policy-based approach to open source software security; it reduces noise, alerts to risk only when necessary, auto-remediates inconsistencies and spans the entire…