Skip to main content
AI/MLWG_Spotlight

Apr 24, 2024 | OpenSSF

Spotlight on the OpenSSF AI/ML Working Group

By Mihai Maruseac and Jay White What do open source software, security and AI/ML have in common? The intersection of these topics is what the OpenSSF AI/ML Working Group tackles. Almost a year ago, a group of people at the confluence of security and AI/ML came together under the OpenSSF… Read more.
JapanMeetup

Apr 22, 2024 | OpenSSF

In Blog

Join Us at the OSS Security Meetup in Tokyo, Japan With General Manager Omkhar + SOSS Community Day North America Event Report

We are excited to announce that the members of the Open Source Security Foundation (OpenSSF), A cross-industry initiative that brings together the industry’s most important open source security initiatives and the individuals and companies that support them, will hold the Meetup on Monday, May 13th at Cybertrust Japan having OpenSSF… Read more.
Beyond Scores with OpenSSF Scorecard

Apr 17, 2024 | OpenSSF

Beyond Scores with OpenSSF Scorecard: Granular Structured Results for Custom Policy Enforcement

OpenSSF Scorecard is a tool to help open source projects reduce software supply-chain risks. Scorecard analyzes projects against a series of heuristics and generates scores from 0–10 for the project — 0 meaning that the project employs high-risk practices and 10 meaning that the project follows security best practices. Read more.
Social Engineering Takeover Blog

Apr 15, 2024 | OpenSSF

In Blog

Open Source Security (OpenSSF) and OpenJS Foundations Issue Alert for Social Engineering Takeovers of Open Source Projects

The recent attempted XZ Utils backdoor (CVE-2024-3094) may not be an isolated incident as evidenced by a similar credible takeover attempt intercepted by the OpenJS Foundation, home to JavaScript projects used by billions of websites worldwide. The Open Source Security (OpenSSF) and OpenJS Foundations are calling all open source maintainers… Read more.
Golden Egg Award Winners

Apr 15, 2024 | OpenSSF

In Blog

Unveiling the Golden Egg Award Winners: Celebrating Excellence in Open Source Security

We’re excited to announce the winners of the Golden Egg Awards. These awards shine a light on those who go above and beyond in enriching our community. The Golden Egg Award symbolizes the community’s gratitude for selfless dedication to securing open source projects through community engagement, engineering, innovation, and thoughtful… Read more.
What_Not_To_Miss_In_SOSSCD_OSSNA

Apr 12, 2024 | OpenSSF

In Blog

Sessions You Won’t Want to Miss at SOSS Community Day NA and Open Source Summit North America 2024

Get ready for the Secure Open Source Software (SOSS) Community Day NA and Open Source Summit North America 2024, next week in Seattle, Washington! These events are where open source communities converge to collaborate, drive innovation, and foster a vibrant open source ecosystem.  Read more.
pocast_soc

Apr 11, 2024 | OpenSSF

In Blog

“What’s in the SOSS?” Podcast is Now Live

In our first podcast – Vincent Danen and the Art of Vulnerability Management, Omkhar Arasaratnam, General Manager of OpenSSF, talks to Vincent Danen, Vice President of Product Security at Red Hat, who is responsible for security and compliance activities across Red Hat's products and services. He’s also on the Governing Board… Read more.
TTX_Securing_OSS_and_Empowering_Maintainers

Apr 10, 2024 | OpenSSF

In Blog

Join us for a TTX: Securing OSS & Empowering Maintainers

At SOSS Community Day NA on April 15, 2024 the OpenSSF Community will conduct a Tabletop Exercise (TTX). Periodically walking through various scenarios of a supply chain attack in a time of calm helps identify action items that are important to prepare in advance for when real attacks occur. A… Read more.
Static Binary Analysis

Apr 4, 2024 | OpenSSF

Static Binary Analysis: A Final Exam for Software Supply Chain Protection

The compromise of VoIP provider 3CX is just one of the latest incidents to highlight gaps in software supply chain security - and the need for a new approach to supply chain risk management, writes Charlie Jones of ReversingLabs. Read more.
xz Backdoor CVE-2024-3094

Mar 30, 2024 | OpenSSF

In Blog

xz Backdoor CVE-2024-3094

CVE-2024-3094 documents a backdoor in the xz package. While the motivation behind this backdoor remains unknown, the intent was to compromise specific distributions, as the backdoors were only applied to DEB or RPM packages for the x86-64 architecture built with gcc and the gnu linker. Situations like this remind us… Read more.