OpenSSF

Inaugural OpenSSF Hong Kong Meetup on March 1

We’re delighted to announce the first-ever Open Source Security Foundation (OpenSSF) Meetup in Hong Kong! Whether you’re a member of technical staff or a business executive, if you want to hear the latest on the pressing challenges and leading initiatives in OSS security – please join us. All are welcome.

Join Us at the First OSS Security Meetup in Tokyo, Japan

We are excited to present at the first ever OSS Security Meetup in Japan, on February 28 in Tokyo, hosted by Open Source Security Foundation (OpenSSF) Members. We aim to create a place where people with the same awareness and challenges related to OSS security can gather, share information mainly in Japanese, and move forward…

Independent Security Audit Impact Report

Security audits are an extremely effective tool for improving the security of critical projects. In 2022, OpenSSF and Google sponsored a number of security audits and associated work via strategic partner Open Source Technology Improvement Fund (OSTIF). Today OSTIF released its Independent Security Audit Impact Report.

Engaging Policy Makers and the Ecosystem on Open Source Software Globally

Throughout 2022, the Linux Foundation and OpenSSF in particular have been at the heart of a number of important conversations concerning the open source software (OSS) community and sustainability of the ecosystem. A large part of our global engagement efforts have been focused on collaborating with leaders in the public and private sector to further…

Takeaways from OpenSSF Day Japan

On December 5th during Open Source Summit Japan, the Open Source Security Foundation (OpenSSF) hosted OpenSSF Day Japan 2022, a half-day event dedicated to exploring ongoing efforts to improve the security of open source software (OSS). Throughout the day, contributors and thought leaders shared their ideas and experiences with OSS security through sessions on subjects…

Alpha-Omega Project First Year In Review, Plus New Funding Pledge

Alpha-Omega is an OpenSSF project, established in February 2022, with a mission to protect society by improving the security of open source software through direct maintainer engagement and expert analysis, trying to build a world where critical open source projects are secure and that security vulnerabilities are found and fixed quickly. During our first year,…

OpenSSF Expands Supply Chain Integrity Efforts with S2C2F

A robust strategy around securing how developers consume and manage open source software (OSS) dependencies when building software is essential. The Secure Supply Chain Consumption Framework (S2C2F) is a consumption-focused/consumer-focused framework that uses a threat-based, risk-reduction approach to mitigate real world threats in Open Source Software (OSS). Today, we are pleased to announce that it…