Skip to main content

📩 Stay Updated! Follow us on LinkedIn and join our mailing list for the latest news!

Sep 12, 2023 | OpenSSF

In Blog

CISA’s Open Source Software Security Roadmap

We’re excited about the announcement of the US Cybersecurity and Infrastructure Security Agency (CISA)’s Open Source Software Security Roadmap. The Roadmap, released today, clearly articulates a risk assessment and implementation plan to help secure open source software (OSS) usage in the US Federal Government and private sector. Read more.

Sep 11, 2023 | jbly

In Blog

Sessions Not to Miss at Open Source Summit and OpenSSF Day Europe

Open Source Summit Europe in Bilbao, Spain is only one week away! Join us as in-person or virtual attendee for both OpenSSF Day Europe and Open Source Summit Europe. Here are some sessions you won’t want to miss from both events. Read more.
Alpha-Omega Mentorship Program

Sep 8, 2023 | OpenSSF

In Blog

Behind the Scenes of the Alpha-Omega Summer Mentorship Program

The Alpha Omega Summer Mentorship Program recently wrapped up and was a resounding success. The program connected senior software security engineers with newcomers to open source, software development, and security research. Entry-level contributors had the opportunity to help accelerate Omega's mission under the guidance of experienced mentors. Get a behind-the-scenes… Read more.
VDR-VEX-OpenVEX-CSAF

Sep 7, 2023 | OpenSSF

VDR, VEX, OpenVEX and CSAF

Early adopters of SBOM have proposed new standards as well as updates to existing standards to specify the status of each vulnerability alongside the SBOM itself. In this context, existing practices such as VDR, CSAF, and emerging standards VEX and OpenVEX are playing a key role. Read more.
OpenSSF Strengthening Open Source Software

Sep 6, 2023 | OpenSSF

Strengthening Open Source Software: Best Practices for Enhanced Security

Securing the open source ecosystem isn't a passive act. It calls for proactive participation through regular code reviews, vulnerability assessments, or simply staying updated with the latest security protocols. Every user, every developer, and every enthusiast has a role to play. Read more.

Aug 31, 2023 | OpenSSF

In Blog

Introducing RSTUF, Repository Service for TUF

We’re thrilled to announce that RSTUF, Repository Service for TUF, has joined the OpenSSF as an OpenSSF Sandbox Project. This is a major step forward in ensuring we can improve secure content distribution. RSTUF helps address a major challenge: securing software repositories, particularly ensuring the integrity of software updates, is… Read more.
OpenSSF Securing Software Repositories Working Group

Aug 30, 2023 | OpenSSF

In Blog

OpenSSF Securing Software Repositories Working Group: Repositories, Registries, and Tools

The OpenSSF Securing Software Repositories Working Group focuses on the maintainers of software repositories, software registries, and the tools that rely on them. By repositories, we include all platforms where software is developed, including GitHub and other platforms. By registries, we include platforms such as package registries and other ways… Read more.
Tokyo_CFP_2023

Aug 28, 2023 | OpenSSF

In Blog

Submit to Speak at OpenSSF Day Japan

We are pleased to announce that OpenSSF Day Japan will be taking place on December 4, 2023 at the Ariake Central Tower Hall & Conference, colocated with Open Source Summit Japan in Tokyo, Japan. Registration is now open, and you are invited to submit your talk to the call for… Read more.

Aug 28, 2023 | OpenSSF

In Blog

OpenSSF Scorecard Launches v4.12 with Support for GitLab

Today, we are excited to announce OpenSSF Scorecard v4.12. This release adds support for GitLab and brings the project closer to its longer-term goal of supporting all types of hosted repositories. Previously, Scorecard has been limited to GitHub-based repositories along with some support for local Git repositories.  Read more.
Security Green Lock Black Background

Aug 25, 2023 | OpenSSF

In Blog

What You Need to Know About the US Federal Government’s RFI on Open Source Software Security

The US Federal Government's recent Request for Information (RFI) on Open Source Software Security (announced by the US White House) is a noteworthy development for open source software (OSS). This RFI originated from the Open-Source Software Security Initiative (OS3I) interagency working group created to improve OSS security. This blog post… Read more.