🤖 Download the Free eBook: Securing Open Source in the Age of AI

OpenSSF Blog

Guest blog opportunities are open to members, working groups in collaboration, and with limited exceptions for active contributors and thought leaders. Share your insights on open source security with our community.

Jul 22, 2026 | OpenSSF

OpenSSF Community Day North America (NA) First-time Experience

My recent experience in Minneapolis revealed that these gatherings are more than simple meetings; they are collaborative ecosystems. Whether you are a maintainer or a first-time contributor, attending provides invaluable insights, fosters transparency, and accelerates project development. Read more.

Jul 21, 2026 | OpenSSF

Representing OpenSSF at AfricaCyberFest

Open source software is playing an important role in Africa's digital growth. Across the continent, more organizations, developers, and communities are adopting open source to build technology and solve local challenges. Read more.

Jul 16, 2026 | OpenSSF

In Blog

Navigating The OpenSSF is as Easy as Floating Down A Lazy River

Navigating the vast ecosystem of the Open Source Security Foundation (OpenSSF) is now as easy as floating down a lazy river. Discover our newly curated, role-based User Journeys designed to seamlessly guide developers, security engineers, OSPO leaders, marketers, and executives to the exact tools, resources, and communities they need. Read more.

Jun 25, 2026 | OpenSSF

The CRA Readiness Reality: What Changed (and What Didn’t) Between 2025 and 2026?

In 2025, Linux Foundation Research, Linux Foundation Europe, and Open Source Security Foundation (OpenSSF) published Unaware and Uncertain: The Stark Realities of Cyber Resilience Act Readiness in Open Source. It took a survey-based look at how prepared the open source ecosystem was for the European Union's Cyber Resilience Act (EU… Read more.

Jun 23, 2026 | OpenSSF

Bridging the Gap Between Code and Research: Why SCORED ’26 Matters for Open Source Security

Let’s be completely honest about how we’ve historically handled security research: academia and open source practitioners have basically been living on two different planets. That’s why we created SCORED (the Workshop on Software Supply Chain Offensive and Defensive Research). It’s a complete reimagining of the traditional academic model. Read more.

Jun 10, 2026 | OpenSSF

Mini Shai-Hulud: Where SLSA’s Boundaries Fall

The “Mini Shai-Hulud” attack chained a GitHub Actions workflow misconfiguration, cache poisoning, and OIDC token extraction to publish malicious packages through legitimate CI/CD pipelines. Read more.

Jun 5, 2026 | OpenSSF

In Blog

The “Skyway” to OSS Security: OpenSSF Community Day North America 2026 Recap

The open source community recently gathered in Minneapolis for Open Source Summit North America and OpenSSF Community Day North America 2026. Functioning as a collaborative “Skyway,” the Open Source Security Foundation (OpenSSF) successfully brought together diverse working groups, security researchers, and enterprise maintainers to unify tooling, address artificial intelligence security… Read more.

May 29, 2026 | OpenSSF

Aligning on Machine-Readable Signals as the Foundation for Due Diligence

By Madalin Neag, EU Policy Advisor, OpenSSF Introduction The software supply chain has reached a level of complexity where manual oversight is no longer a viable strategy for security or regulatory compliance. Modern systems depend on vast, rapidly evolving networks of components, making manual, paper-based approaches to due diligence impractical.… Read more.

May 21, 2026 | OpenSSF

OpenSSF Notes Quarter of Growth with New Members, Added AI Security Resources, and Growing Community

Foundation celebrates five additional members, new cyber reasoning sandbox project, and release of v1.0.0 Python Secure Coding Guide to support open source security globally MINNEAPOLIS – OpenSSF Community Day North America – May 21, 2026 – The Open Source Security Foundation (OpenSSF), a cross-industry initiative of the Linux Foundation focused… Read more.

May 21, 2026 | OpenSSF

In Blog

Introducing the First Cohort of the OpenSSF Ambassador Program

Securing the open source software ecosystem is a monumental task, and it is not one we can tackle alone. It requires collaboration, education, and passionate advocates who are willing to share their knowledge across the globe. Today, at OpenSSF Community Day, we are beyond excited to announce the launch of… Read more.