Skip to main content

OpenSSF Blog

Guest blog opportunities are open to members, with limited exceptions for active contributors and thought leaders. Share your insights on open source security with our community.

Safeguarding Your Data

Oct 30, 2023 | OpenSSF

Safeguarding Your Data – How to Harden Your Systems

In our increasingly digitized world, data reigns supreme. Alongside traditional valuable information like customer records and bank details, data on interactions and activity has become more valuable to companies. As data has become critical, it is also more at risk from theft or attacks like ransomware. According to IBM, the… Read more.
Express Learning Courses Linux Foundation Training Certification

Oct 26, 2023 | OpenSSF

In Blog

3 New Express Learning Courses on Security for Cloud Pros

Security is the key theme throughout the three new free Express Learning courses launched by Linux Foundation Training & Certification for cloud professionals. The courses include: Security Self-Assessments for Open Source Projects (LFEL1005), Securing Projects with OpenSSF Scorecard (LFEL1006), Automating Supply Chain Security: SBOMs and Signatures (LFEL1007). Read more.
OpenSSF Security Job Board Launch

Oct 24, 2023 | OpenSSF

In Blog

OpenSSF Launches Security Job Board for the Community

We are excited to announce the launch of the OpenSSF Security Job Board. This job board is meant to serve the community in two ways: allowing developers to view top-notch jobs in the security space and helping companies hire great people. By making the best security jobs easily accessible in… Read more.
Secure by Design

Oct 23, 2023 | OpenSSF

In Blog

Secure by Design: Guidance from Governments

In April 2023 the US Cybersecurity and Infrastructure Agency (CISA), along with other government agencies inside and outside the US, released a paper emphasizing software secure-by-design principles and approaches. In October 2023 a significant update was released, now titled Shifting the Balance of Cybersecurity Risk: Principles and Approaches for Secure… Read more.
SLSA Tech Talk

Oct 20, 2023 | OpenSSF

In Blog

SLSA Tech Talk Highlights

Earlier this month we held a Tech Talk on Securing the Software Supply Chain: An In-Depth Exploration of SLSA. SLSA, or Supply-chain Levels for Software Artifacts, is an OpenSSF project that provides a security framework to improve the integrity and security of packages and infrastructure. You can watch the Tech… Read more.
OpenSSF Day Japan Agenda Live

Oct 18, 2023 | OpenSSF

In Blog

OpenSSF Day Japan Agenda Now Live

The OpenSSF Day Japan agenda is now live! We have a great day of session presentations, panels, and lightning talks lined up on December 4th, colocated with Open Source Summit Japan in Tokyo, Japan. Plan to join us to discuss the latest and greatest in ongoing efforts to secure the… Read more.
OpenSSF GB Chair Welcome Arun Gupta

Oct 17, 2023 | OpenSSF

In Blog

OpenSSF Welcomes New Governing Board Chair, Arun Gupta

The OpenSSF is pleased to welcome new Governing Board Chair, Arun Gupta who was elected by the OpenSSF Governing Board and will serve from October 2023 to October 2024. Join us for a conversation with new OpenSSF Board Chair, Arun Gupta. Read more.
2023 Milestones OpenSSF GB Chair

Oct 16, 2023 | OpenSSF

In Blog

Reflections on 2023 Milestones from Two-Term Board Chair, Jamie Thomas

Like the open source ecosystem itself, the OpenSSF has grown and evolved during a very busy 2023. It’s no longer debatable, everyone depends upon open source software today. Two-Term OpenSSF Board Chair, Jamie Thomas, reflects on 2023 milestones. Read more.
US Government Fact Sheet on Improving Security of Open Source Software in Operational Technology and Industrial Control Systems

Oct 13, 2023 | OpenSSF

In Blog

US Government Fact Sheet on Improving Security of Open Source Software in Operational Technology and Industrial Control Systems (OT / ICS)

This week, CISA, FBI, NSA, and the US Department of the Treasury released guidance on Improving Security of Open Source Software (OSS) in Operational Technology (OT) and Industrial Control Systems (ICS) to assist with better management of risk from OSS use in OT/ICS and increase resilience when using available resources.… Read more.
OpenSSF Malicious Packages Repository

Oct 12, 2023 | OpenSSF

In Blog

Introducing OpenSSF’s Malicious Packages Repository

Today, the OpenSSF Package Analysis team is excited to announce the launch of our Malicious Packages repository, the first open source system for collecting and publishing cross-ecosystem reports of malicious packages. This repository is a response to the rising incidence of attacks that include malicious open source packages. Read more.