Skip to main content
Photo Collage from OpenSSF Day at Open Source Summit NA

Jul 19, 2022 | jbly

In Blog

OpenSSF Day Videos Now Available from Open Source Summit North America

The first ever OpenSSF Day at the Open Source Summit North America (OSS NA) was a big success. On June 20th, we gathered in Austin, Texas and online to understand how to solve some of the biggest security challenges in the open source industry, steps being taken, and what’s next.  Read more.
Security Audit Results for sigstore and slf4j

Jul 18, 2022 | OpenSSF

Results of Sigstore and slf4j Security Audits Including 1 High Risk Vulnerability Found and Fixed

We’re excited to report the results of two security audits, one for Sigstore and one for slf4j. The goal of security audits is to find vulnerabilities so they can be fixed before attackers exploit them, as well as to identify opportunities to harden a project’s implementation and processes to counter… Read more.
Securing Your Software Supply Chain with Sigstore Course

Jun 22, 2022 | David Wheeler

Free Training Course Teaches How to Secure a Software Supply Chain with Sigstore

To make it easier to use Sigstore’s toolkit to its full potential, OpenSSF and Linux Foundation Training & Certification released a free online training course, Securing Your Software Supply Chain with Sigstore (LFS182x), designed with end users of Sigstore tooling in mind: software developers, DevOps engineers, security engineers, software maintainers,… Read more.
State of Open Source Report

Jun 21, 2022 | OpenSSF

In Blog

State of Open Source Security 2022 from Snyk & the Linux Foundation

Snyk has teamed up with the Linux Foundation to research and report on security concerns in the open source ecosystem. The 2022 State of Open Source Security report shows that many organizations still don’t have good policies and governance around open source security in spite of the popularity of open… Read more.
brian behlendorf episode untold stories of open source podcast

Jun 20, 2022 | jbly

In Blog

New Untold Stories of Open Source Podcast Features OpenSSF’s Brian Behlendorf on his Journey to Securing the FOSS Software Supply Chain

The Linux Foundation released a new podcast series, “The Untold Stories of Open Source.” Join us each week as we meet the people behind the code, discover their often unconventional journey to the world of open source, and learn the challenges they faced along the way. Read more.

Jun 20, 2022 | David Wheeler

In Blog

OpenSSF Makes Secure Software Development Training Available on Organizations’ Learning Management Systems

The free "Developing Secure Software" (LFD121) online training course is now available through SCORM Connect, so that organizations with their own SCORM-compliant Learning Management Systems (LMSs) can integrate the course into their own LMSs. Making this training that is available for free through Linux Foundation Training & Certification also accessible… Read more.

Jun 20, 2022 | amartin

OpenSSF Funds Python and Eclipse Foundations and Acquires SOS.dev through Alpha-Omega Project

As part of the OpenSSF’s continued investment in critical open-source projects, we are pleased to announce that the OpenSSF’s Alpha-Omega Project has committed to $800,000 in funding split equally among the Python Software Foundation (PSF) and the Eclipse Foundation to fund critical security roles. We are also happy to announce… Read more.

Jun 9, 2022 | OpenSSF

In Blog

Introducing Fuzz Introspector, an OpenSSF Tool to Improve Fuzzing Coverage

We are excited to announce an initial release of Fuzz Introspector, a collaborative effort from OpenSSF members, that provides actionable insights for developers to identify fuzzing coverage blockers by analyzing functions, static call graphs, and runtime coverage information. Resolving these blockers will help unlock improved fuzzing coverage, resulting in more… Read more.

May 11, 2022 | OpenSSF

In Blog

Testimony to the US House Committee on Science and Technology

We’re pleased to share that Brian Behlendorf, OpenSSF General Manager, testified to the United States House of Representatives Committee on Science, Space, and Technology today. Brian's testimony shares the work being done within the Open Source Security Foundation and broader open source software community to improve security and trustworthiness of… Read more.

Apr 28, 2022 | OpenSSF

In Blog

Introducing Package Analysis: Scanning open source packages for malicious behavior

By Caleb Brown and David A. Wheeler, on behalf of Securing Critical Projects Working Group Today we're pleased to announce the initial prototype version of the Package Analysis project, an OpenSSF project addressing the challenge of identifying malicious packages in popular open source repositories. In just one month of analysis,… Read more.