Dec 9, 2024 |
In the Face of Mounting Regulatory Oversight, Honda and Guidewire Join Industry Leaders Securing Software Development at the Open Source Security Foundation (OpenSSF)
Growing Member Base and Launch of SOSS Community Day India Continue to Advance Open Source Software Security Delhi, India – December 10, 2024 – The Open Source Security Foundation (OpenSSF), a global cross-industry initiative of the Linux Foundation, helps individuals and organizations build secure software by providing guidance, tools, and… Read more.
Dec 9, 2024 |
In Blog
The OpenSSF 2024 Annual Report Is Live!
We’re excited to announce the release of the OpenSSF 2024 Annual Report, highlighting a year of significant progress, collaboration, and impact within the open source software (OSS) ecosystem. From new member milestones to groundbreaking initiatives, this report captures the collective achievements of our projects, working groups, and vibrant community. Here’s… Read more.
Dec 4, 2024 |
Open Source Usage Trends and Security Challenges Revealed in New Study
SAN FRANCISCO, Dec. 4, 2024 -- The Linux Foundation, the nonprofit organization enabling mass innovation through open source, today announced the release of "Census III of Free and Open Source Software – Application Libraries" (Census III) in collaboration with the Laboratory for Innovation Science at Harvard. The study identifies the most widely-used free and open… Read more.
Nov 27, 2024 |
In Blog
Shaping the Future of Generative AI: A Focus on Security
Open Source Security Foundation (OpenSSF), with its focus on securing open source software, plays a pivotal role in establishing best practices for developing secure AI systems. In 2024, the OpenSSF AI/ML Working Group launched a new project focused on model signing. This initiative is developing a proof of concept for model signing… Read more.
Nov 25, 2024 |
In Blog
Understanding the CRA: OpenSSF’s Role in the Cyber Resilience Act Implementation – Part 1
With publishing as Regulation (EU) 2024/2847 in the Official Journal of the European Union, the Cyber Resilience Act (CRA) enters into force (EIF) on December 10, 2024. The CRA will fully apply three years later, on December 11, 2027. The CRA will obligate all products with digital elements, including their… Read more.
Nov 11, 2024 |
In Blog
The OpenSSF Armored Goose “Honk”: Advancing Open Source Security
The Open Source Security Foundation (OpenSSF) logo presents a compelling visual narrative featuring “Honk”, an armored goose holding a shield. This unique and creative mascot perfectly embodies the foundation's mission in open source security. Why the goose? Read more.
Nov 4, 2024 |
In Blog
How We Can Learn from Open Source Software to Address the Challenges of AI
With the development of new artificial intelligence (AI) models and capabilities, attention has been drawn to their potential harms and misuse: from generating deepfakes and disinformation, algorithmic bias, or being used to perpetuate other harms or biases. Read more.
Nov 1, 2024 |
Red Hat’s Collaboration with the OpenSSF and OSV.dev Yields Results: Red Hat Security Data Now Available in the OSV Format
OSV is an open format for describing software vulnerabilities. It provides security researchers, vendors, and consumers with an easy to understand format for exchanging vulnerability information. OSV.dev is a database that hosts and aggregates OSV data. Read more.
Oct 29, 2024 |
OpenSSF Welcomes New Members and Introduces New Initiatives at SOSS Community Day Japan
Growing Member Base and New Initiatives Continue to Advance Open Source Software Security TOKYO, JAPAN – October 30, 2024 – The Open Source Security Foundation (OpenSSF), a global cross-industry initiative of the Linux Foundation that focuses on sustainably securing open source software (OSS), is excited to announce new members from… Read more.
Oct 29, 2024 |
OpenSSF Expands Secure Development Course with Interactive Labs
The Open Source Security Foundation (OpenSSF) today announced an expansion of its free course “Developing Secure Software” (LFD121). The course now features interactive learning scenarios to better equip developers to build software that resists modern cyberattacks. Read more.