May 3, 2021 |
In Blog
Introducing the Security Metrics Initiative
Author: Michael Scovetta, on behalf of the Identifying Security Threats Working Group The OpenSSF would like to announce the initial release of the Security Metrics initiative. The primary objective of this initiative is to provide valuable decisive information about threats and risks associated with open source projects. Security Metrics comes… Read more.
Apr 14, 2021 |
In Blog
Upcoming OpenSSF Town Hall on May 3, 2021
The OpenSSF community has been working diligently to improve the security of the open source ecosystem. We would like to share all of the great work that is happening and invite you to participate. We hope to see you at our next OpenSSF Town Hall Meeting on Monday, May 3,… Read more.
Feb 3, 2021 |
In Blog
Upcoming OpenSSF Town Hall on February 22
The OpenSSF community has been working fast and furious since its formation last year to improve the security of the open-source ecosystem. We all know this is no small mission and so we’re taking a moment to report out on all the work that’s happening and invite you to participate.… Read more.
Jan 28, 2021 |
In Blog
January 2021 Update: New Technical Vision Informs Working Group Progress
The OpenSSF community has been working fast and furious since its formation last year to improve the security of the open source ecosystem. We all know this is no small mission and so we’re taking a moment to report out on all the work that’s happening and invite you to… Read more.
Jan 27, 2021 |
In Blog
Digital Identity Attestation Roundup
Author: Kim Lewandowski, on behalf of the Digital Identity Attestation Working Group We kicked off the first Digital Identity Attestation Working Group meeting under the OpenSSF in August, 2020. The objective of this working group is to enable open source maintainers, contributors and end-users to understand and make decisions on… Read more.
Dec 9, 2020 |
In Blog
Introducing the OpenSSF CVE Benchmark
Author: Bas van SchaikToday, at Black Hat Europe, the Open Source Security Foundation (OpenSSF) unveiled its latest initiative: the OpenSSF CVE Benchmark. The benchmark consists of vulnerable code and metadata for over 200 historical JavaScript/TypeScript vulnerabilities (CVEs). It includes tooling for analyzing the real-world codebases that were affected by these… Read more.
Nov 23, 2020 |
In Blog
OpenSSF Town Hall Recording: Now Available!
The video recording of the Open Source Security Foundation (OpenSSF) “Public Town Hall” meeting of November 9, 2020 is now available! This meeting shares updates and celebrates accomplishments during the first three months of the OpenSSF. It includes presentations from the OpenSSF Governing Board, Technical Advisory Council, and Working Group… Read more.
Nov 6, 2020 |
In Blog
Security Scorecards for Open Source Projects
Author: Kim Lewandowski, Google Product Manager One of the first things I wanted to do when the OpenSSF launched was help people make better decisions about security when consuming open source projects, and draw more awareness to the health of these critical projects we all depend on. Some might argue… Read more.
Oct 29, 2020 |
In Blog
Announcing: Secure Software Development EdX course, Sign Up Today!
The Open Source Security Foundation (OpenSSF) has developed a trio of free courses on how to develop secure software. These courses are part of the Secure Software Development Fundamentals Professional Certificate program, all available on the edX platform. This material is intended for all software developers so they can learn… Read more.
Oct 21, 2020 |
In Blog
OpenSSF Public Town Hall – November 9 2020, 10am Pacific
Please join us for the first-ever OpenSSF Town Hall Meeting on November 9, 2020 from 10 AM to 12 PM Pacific Time (US and Canada). In this meeting, we will share updates and celebrate accomplishments during the first three months of the project. Attendees will hear from the Governing Board,… Read more.