🎙️ Submit your talk for: OpenSSF Community Day Europe by July 12

OpenSSF

Join us for a TTX: Securing OSS & Empowering Maintainers

At SOSS Community Day NA on April 15, 2024 the OpenSSF Community will conduct a Tabletop Exercise (TTX). Periodically walking through various scenarios of a supply chain attack in a time of calm helps identify action items that are important to prepare in advance for when real attacks occur. A TTX is an important planning…

xz Backdoor CVE-2024-3094

CVE-2024-3094 documents a backdoor in the xz package. While the motivation behind this backdoor remains unknown, the intent was to compromise specific distributions, as the backdoors were only applied to DEB or RPM packages for the x86-64 architecture built with gcc and the gnu linker. Situations like this remind us all that we need to…

VulnCon 2024 Wrap-up: Securing the Ecosystem through Global Cooperation

The OpenSSF was pleased to be one of the sponsors that helped contribute to the inaugural 2024 VulnCon conference that brought together experts from across industry, government, security researchers, and community members throughout 3 days and nearly 40 sessions.  Brought together by the FIRST PSIRT SIG and the CVE Board. Christopher “CRob” Robinson, OpenSSF TAC Chair…

How Intel Uses OpenSSF Scorecard To Better Secure Its Software Portfolio

Scorecard is an automated tool from the OpenSSF that assesses 19 different vectors with heuristics ("checks") associated with important software security aspects and assigns each check a score of 0-10. You can use these scores to understand specific areas to improve in order to strengthen the security posture of your project. Intel currently uses Scorecard to…

OpenSSF Scorecard Tech Talk Highlights

Last week the community convened for the first OpenSSF Tech Talk of the year, shining a spotlight on OpenSSF Scorecard. OpenSSF Scorecard aids developers and open source consumers in assessing how well an open source project adheres to best practices. It evaluates projects for security risks using a series of automated checks. The Tech Talk…