Neo Malware: Malicious Open Source Packages
Malware is at the top of the list among things that keep security and development organizations on edge.Â
Malware is at the top of the list among things that keep security and development organizations on edge.Â
Open source package repositories (like npm, PyPI, RubyGems, and others) serve out billions of packages per day. Most of the software we all use includes packages from these repositories, making them a critical part of securing software.
OpenSSF Welcomes Datadog as Premier Member
We're thrilled to announce that the agenda for Secure Open Source Software (SOSS) Community Day EU on September 19, 2024, is now live! Join us for a day filled with insightful technical talks, engaging panels, and a hands-on Table Top Exercise (TTX). SOSS Community Day EU will be co-located with the Open Source Summit Europe…
As the Call for Proposals (CFP) for the Secure Open Source Software (SOSS) Fusion Conference wrapped up, we wanted to share some insights about the submissions that highlight how Fusion...
Welcome to the July 2024 edition of the OpenSSF Newsletter, with our latest information on what’s been happening lately and what’s on our radar. DOWNLOAD: What’s in the SOSS? An...
As we unveiled the Golden Egg Award winners in April during the SOSS Community Day North America, we recognized those who go above and beyond in enriching our community. Today, we spotlight Christopher “CRob” Robinson, the winner of the Golden Egg Award for OpenSSF Community Engagement. CRob has made continuous impactful contributions as the chair…
Submitting a nomination is easy! Fill out the nomination form, providing details about the nominee’s contributions and why you believe they deserve the Golden Egg Award.
In part 1 we discussed the Artificial Intelligence Cyber Challenge (AIxCC), a two-year competition to create AI systems that find software vulnerabilities and develop fixes to them. We also discussed a specific vulnerability in the Linux kernel, called needle, as an example of the kind of vulnerability we’d like such tools to find and fix. …
Findings show nearly one-third of industry professionals are not familiar with secure software development practices