Skip to main content
openssf npm best practices guide

Sep 1, 2022 | OpenSSF

In Blog

npm Best Practices for the Supply-Chain

We are excited to announce the v1 release of the “npm Best Practices,” a new guide focused on dependency management and supply chain security for npm. This release is the result of the OpenSSF Best Practice Working Group. It is a critical step to help JavaScript and TypeScript developers reduce… Read more.
Open Source Software Security Summit Japan

Aug 24, 2022 | amartin

In Blog

Outcomes from Open Source Software Security Summit in Japan

On August 23rd, we at the OpenSSF and Linux Foundation Japan hosted the Open Source Security Summit Japan. We were joined by senior cybersecurity representatives from more than 20 leading Japanese firms. We convened to discuss open source software (OSS) security challenges, modern challenges to the global software supply chain,… Read more.
OpenSSF Welcomes Capital One

Aug 24, 2022 | OpenSSF

Capital One Joins Open Source Security Foundation

Capital One joins the Open Source Security Foundation (OpenSSF) as a premier member affirming its commitment to strengthening the open source software supply chain. OpenSSF is a cross-industry organization hosted at the Linux Foundation, designed to inspire and enable the community to secure the open source software we all depend… Read more.
August OpenSSF Town Hall Q&A

Aug 22, 2022 | jbly

In Blog

Upleveling Everybody to Secure the OSS Supply Chain – OpenSSF August Town Hall Highlights

The August OpenSSF Town Hall brought together the open source community to hear the latest and greatest about the work going on to secure the open source software supply chain. Both the Town Hall slide deck and event recording are available for you to view. Read more.
OpenSSF Day EU

Aug 15, 2022 | jbly

In Blog

Announcing OpenSSF Day at Open Source Summit Europe

We’re pleased to announce we will be hosting the second ever  OpenSSF Day at Open Source Summit Europe on Tuesday, September 13th. This is your chance to find out what the OpenSSF community is doing to secure the open source ecosystem and how you can get involved. Read more.

Aug 11, 2022 | OpenSSF

In Blog

Secure Coding Practice – A Developer’s Learning Experience of Developing Secure Software Course

My learning experience taking the “DEVELOPING SECURE SOFTWARE (LFD121)” course was positive, and I immediately started applying these learnings in my work as a software architect and developer. Read more.
OpenSSF_TownHall_August2022

Aug 2, 2022 | jbly

In Blog

Get Up to Speed with OpenSSF at Next Virtual Town Hall

At the next virtual OpenSSF Town Hall you will get an in-depth tour of several key initiatives and find out how to get involved yourself in the exciting work of the OpenSSF. Read more.
Software Supply Chain Security Survey Header

Jul 26, 2022 | OpenSSF

In Blog

Take Survey to Help Improve Software Supply Chain Integrity Practices

A new survey by Chainguard in collaboration with the Eclipse Foundation, the Rust Foundation and OpenSSF aims to understand the software supply chain integrity practices of a broad range of software professionals. The goal of this survey is to learn more about how software professionals use and view key software… Read more.
OpenSSF Meetup in India July 28

Jul 22, 2022 | OpenSSF

In Blog

Join Us at the First OpenSSF Open Source Security Meetup in India

I’m very excited to present at the first ever Open Source Security Foundation (OpenSSF) meetup in India, next Thursday, July 28 in Bangalore, hosted by OpenSSF Premier Member, Wipro. Companies and governments are increasingly recognizing the need to prioritize their software supply chains and the role open source software (OSS) plays… Read more.
OpenSSF Logo Banner

Jul 20, 2022 | OpenSSF

In Blog

OpenSSF Supports Movements toward Multi-Factor Authentication

By: The OpenSSF Technical Advisory Council  On July 8th, 2022, the Python Package Index (PyPI) announced a security key giveaway for maintainers of critical projects, where “critical” is a label given to the top 1% of packages on PyPI by download count during the prior six months. The giveaway included… Read more.