OpenSSF

Alpha-Omega Project Announces Over $1.5M in Grants to Critical Open Source Projects and New Omega Analysis Toolchain

As part of the OpenSSF’s continued investment in critical open-source projects, we are happy to announce new partnerships and tooling from the Alpha-Omega Project. Alpha-Omega will sponsor critical security work with a $460K grant to the Rust Foundation. This work expands on funding previously announced earlier this year, bringing our total investment to over $1.5M…

Introducing the New OpenSSF End Users Working Group

OpenSSF is excited to announce its newest WG (Working Group), the End Users WG. This WG will focus on representing and addressing the challenges enterprises face when adopting (and using) different open-source technologies and products.

Show Off Your Security Score: Announcing Scorecards Badges

We are excited to release new features from the Scorecards project, the OpenSSF tool that helps maintainers follow best security practices. The Scorecards GitHub Action now supports a REST API for quickly viewing project scores, and we’ve added one of our favorite new features: badges! We hope these additions will make interacting with Scorecards smoother…

npm Best Practices for the Supply-Chain

We are excited to announce the v1 release of the “npm Best Practices,” a new guide focused on dependency management and supply chain security for npm. This release is the result of the OpenSSF Best Practice Working Group. It is a critical step to help JavaScript and TypeScript developers reduce risks as they choose open-source…

Capital One Joins Open Source Security Foundation

Capital One joins the Open Source Security Foundation (OpenSSF) as a premier member affirming its commitment to strengthening the open source software supply chain. OpenSSF is a cross-industry organization hosted at the Linux Foundation, designed to inspire and enable the community to secure the open source software we all depend on, including development, testing, fundraising,…

The Linux Foundation and Open Source Software Security Foundation (OpenSSF) Gather Japanese Industry and Government Leaders for Open Source Software Security Summit Japan

The Linux Foundation and the Open Source Software Security Foundation (OpenSSF) backed by the Ministry of Economy, Trade and Industry, Today convene cybersecurity experts from Japanese companies, government agencies, and research institutes at the Open Source Security Summit Japan to share open source software (OSS) security issues and how to accelerate improvements. The meeting will…

Take Survey to Help Improve Software Supply Chain Integrity Practices

A new survey by Chainguard in collaboration with the Eclipse Foundation, the Rust Foundation and OpenSSF aims to understand the software supply chain integrity practices of a broad range of software professionals. The goal of this survey is to learn more about how software professionals use and view key software supply chain integrity practices. 

Join Us at the First OpenSSF Open Source Security Meetup in India

I’m very excited to present at the first ever Open Source Security Foundation (OpenSSF) meetup in India, next Thursday, July 28 in Bangalore, hosted by OpenSSF Premier Member, Wipro. Companies and governments are increasingly recognizing the need to prioritize their software supply chains and the role open source software (OSS) plays in them. Given the increasing…