Guest blog opportunities are open to members, with limited exceptions for active contributors and thought leaders. Share your insights on open source security with our community.
OpenSSF Blog
Deprecated: Invalid characters passed for attempted conversion, these have been ignored in /code/wp-content/themes/salient-child/vc-addons/recent-posts-linux.php on line 455
Warning: Undefined variable $tag_slugs in /code/wp-content/themes/salient-child/vc-addons/recent-posts-linux.php on line 547
Warning: Undefined variable $author_id in /code/wp-content/themes/salient-child/vc-addons/recent-posts-linux.php on line 805
Oct 10, 2023 |
In Blog
HTTP/2 Rapid Reset Vulnerability Highlights Need for Rapid Response
Open Source Software is used in critical infrastructure worldwide. As vulnerabilities like Looney Tunables, Rapid Reset, and the forthcoming cURL vulnerabilities are discovered, organizations must have a well-practiced incident response plan. We believe in risk-based responses based on business criticality. A well-informed inventory based on SBOMs is key to this… Read more.
Oct 9, 2023 |
In Blog
Recap of OpenSSF Day Europe
On September 18, 2023, we hosted OpenSSF Day Europe at the Open Source Summit Europe in Bilbao, Spain. Throughout the day, we hosted a number of sessions around the state of open source software security, discussed current initiatives and what’s next. If you weren’t able to attend, check out our… Read more.
Oct 3, 2023 |
Running Sigstore as a Managed Service: A Tour of Sigstore’s Public Good Instance
While several articles have been published about how to run your own Sigstore instance, it’s useful to understand how the public good instance is administered – both in terms of configuration and also policies and best practices. Read more.
Oct 2, 2023 |
In Blog
OpenSSF Welcomes New Chief Architect, Dana Wang
The OpenSSF is pleased to welcome new Chief Architect, Dana Wang! Dana Wang is a technology leader with a track record of delivering results and making impacts at enterprise scale. Dana was formerly the Executive Director of Public Cloud Network Security at JPMorgan Chase. She led the public cloud edge… Read more.
Sep 29, 2023 |
In Blog
Announcing sigstore-python 2.0
We are delighted to announce the 2.0 release of sigstore-python, a Python client for signing and verifying Sigstore signatures! This release has been in the works for a while and contains a number of significant improvements and breaking changes to both the sigstore CLI and Python APIs. Read more.
Sep 28, 2023 |
In Blog
OpenSSF Securing Critical Projects Working Group: Identifying and Helping Improve Top Open Source Projects
The Securing Critical Projects WG aims to solve the problem of insecure (and often unknown) critical projects. First, we focus on helping identify which projects are critical, which will allow discovery of projects that can benefit from additional security focus. We’ve been working on curating a set of identified open… Read more.
Sep 27, 2023 |
In Blog
Threat Modeling the Supply Chain for Software Consumers
From a software consumer perspective, how do we know where to start to address the real supply chain threats? Which risks are more critical than others? What framework or standard should be adopted quickly? Those were the questions posed in the OpenSSF End Users Working Group where engineers got together… Read more.
Sep 18, 2023 |
Advancing Rustls and Rust for Linux with OpenSSF Support
Prossimo continues to advance the functionality and scalability of the Rustls TLS library and the Rust for Linux effort thanks to $530,000 in funding from the OpenSSF’s Alpha-Omega project. This funding will further Prossimo’s efforts to bring memory safety to critical components of the Internet and further OpenSSF’s Alpha-Omega project’s… Read more.
Sep 18, 2023 |
OpenSSF Welcomes New Members in Support of Securing Open Source Software
We welcome six new members from leading technology firms to the OpenSSF. New general members include Mend.io, RTX, Shopify, SlimAI, and Stacklok. New associate member, the Rust Foundation, also joins. Technical communities continue to prioritize investment in open source security and recognize the role of supporting and sustaining open source… Read more.
Sep 15, 2023 |
In Blog
Join us for an OpenSSF Tech Talk on SLSA
Join us for an OpenSSF Tech Talk on SLSA. We’ll delve into the world of SLSA and its transformative impact on software supply chain security. You will get a comprehensive overview of SLSA and dig into SLSA fundamentals, trust and transparency in software artifacts, SLSA framework levels, the industry impact… Read more.