OpenSSF Blog

Guest blog opportunities are open to members, working groups in collaboration, and with limited exceptions for active contributors and thought leaders. Share your insights on open source security with our community.

Sep 16, 2026 | OpenSSF

In Blog

We’re In: Enterprise Commitment to Sustainable Package Registries

The OpenSSF Governing Board and major tech enterprises are partnering to support sustainable funding models for public package registries. This commitment aims to secure and scale the global software supply chain while ensuring open source stays free and accessible for individual developers. Read more.

Sep 15, 2026 | OpenSSF

Grow CRA Readiness: Find Your Path Through the European Union Cyber Resilience Act

Discover how the EU Cyber Resilience Act (CRA) impacts your open source work. OpenSSF’s new community garden user journey helps maintainers, software stewards, and manufacturers navigate legal requirements and find essential tools for CRA readiness. Read more.

Sep 14, 2026 | OpenSSF

Empowering Open Source Security with Scalable Infrastructure

How can open source projects maintain secure infrastructure without financial strain? OpenSSF Premier Member, Amazon Web Services (AWS) addresses this by providing critical funding and scalable compute resources. Read more.

Sep 11, 2026 | OpenSSF

A Community Guide to the EU CRA September 11 Deadline for Manufacturers

The EU Cyber Resilience Act (CRA) introduces new cybersecurity requirements for products with digital elements. Discover what the September 11, 2026 reporting deadline for manufacturers means for the open source community, maintainers, and stewards, and how you can prepare to support downstream ecosystems. Read more.

Sep 10, 2026 | aliu

In Blog

Tech Talk Recap: A Practitioner’s Guide to CRA Readiness

The EU Cyber Resilience Act is no longer a distant regulatory concept. With vulnerability reporting obligations to ENISA arriving on September 11 and the full weight of the law landing in December 2027, open source maintainers, foundations, and the companies who build on top of open source all have real… Read more.

Sep 10, 2026 | OpenSSF

Open by Default After AI: The GDS Guidance and the Enforcement Question

September 2026 By Sal Kimmich and Simon John Executive Summary In early May 2026, NHS England issued a reported internal guidance note, SDLC-8, mandating the removal of public access to several hundred GitHub repositories. The stated reason was AI-accelerated vulnerability discovery. The actual effect was to contradict years of established… Read more.

Sep 4, 2026 | OpenSSF

In Blog

OpenSSF at Hacker Summer Camp 2026: Black Hat & DEF CON Highlights and Recap

Las Vegas was once again the center of the cybersecurity universe from August 1–9 for Black Hat and DEF CON 2026. The Open Source Security Foundation (OpenSSF) had a major presence throughout the week, engaging with security leaders, project maintainers, and the broader community to advance open source security. Read more.

Aug 28, 2026 | OpenSSF

Introducing BOMHort: Kubernetes-Native SBOM Visualization & Governance at Scale Joins the OpenSSF Sandbox

As regulatory requirements like the EU Cyber Resilience Act (CRA), NIST SSDF, and Executive Order 14028 take effect, generating a Software Bill of Materials (SBOM) has shifted from a best practice to a strict requirement. However, for platform and security teams, generating SBOMs is only half the battle. Managing, querying,… Read more.

Aug 27, 2026 | OpenSSF

In Blog

Join OpenSSF at AGNTCon + MCPCon North America: Securing Agentic AI

Join OpenSSF at AGNTCon + MCPCon North America this October to explore the Secure Agentic Framework (SAF) and learn how to secure the future of agentic AI ecosystems. Read more.

Aug 26, 2026 | OpenSSF

Case Study: Conquering the EU Cyber Resilience Act (CRA) with 1,400 Upstream Security Fixes

Ericsson Software Technology successfully met the stringent obligations of the EU Cyber Resilience Act (CRA) by fundamentally shifting to upstream collaboration. Guided by OpenSSF principles, they eliminated private forks and contributed over 1,400 dependency updates and security fixes directly to open source communities. Read more.