OpenSSF

Secure Coding Guide for Python (pyscg) First Release

New developers require a single, framework-independent resource to establish a baseline in secure coding practices. Python is one of the most widely adopted programming languages in the world, powering everything from web applications and data pipelines to AI/ML systems and cloud infrastructure.

OpenSSF Newsletter – April 2026

TL;DR: 🚀 OpenSSF Community Day NA → Agenda live, read the session highlights. ⚖️ TPN & SBOM Evolution → New frameworks aim to turn "dead" PDF notices and static SBOMs into active security intelligence.  🤖 Agentic AI Security → OpenSSF welcomes OSS-CRS and examines using SAFE-MCP to secure non-deterministic AI agents.  📦 Project Milestones →…

Secure Your Spot: The OpenSSF Community Day North America 2026 Agenda is Live!

The 2026 OpenSSF Community Day North America agenda is live, and we invite the open source community to join us on Thursday, May 21, in Minneapolis, MN. Co-located with Open Source Summit North America, this event will serve as a collaborative space for maintainers, security researchers, and industry leaders to discuss the state and future…

OpenSSF Tech Talk Recap: Securing Agentic AI

At our recent Open Source Security Foundation (OpenSSF) Tech Talk, experts from Microsoft, Thread AI, Canonical, and the OpenSSF AI/ML Security Working Group joined forces to dismantle the "black box" of AI security.