Skip to main content

đŸ“© Stay Updated! Follow us on LinkedIn and join our mailing list for the latest news!

SigstoreCon North America

Sep 27, 2022 | OpenSSF

First-Ever SigstoreCon at KubeCon + CloudNativeCon North America 2022

This year SigstoreCon will be hosted for the first time! The one-day event will take place on October 25, in Detroit Michigan, in co-location with KubeCon + CloudNativeCon North America. SigstoreCon aims to help accelerate how you secure your software supply chain. The great news is that this is a… Read more.
SPDX OpenSSF SBOM Everywhere

Sep 13, 2022 | OpenSSF

In Blog

Funding Python SPDX Development with the OpenSSF and SBOM Everywhere

SBOM Everywhere, as the name suggests, is working towards bringing SBOMs to all of open source in a way that is non disruptive. The first effort of the SBOM Everywhere project was to create a plan that enabled the OpenSSF to fund work on the SDPX Python library. We are… Read more.
OpenSSF CVD Guide for Finders

Sep 13, 2022 | OpenSSF

In Blog

Coordination is Key! The OpenSSF’s CVD Guide for Finders

The Vulnerability Disclosures Working Group is proud to unveil the next evolution in improving open source coordination of vulnerability disclosures by crafting a new guide focused on the Security researcher or Finder persona. The newly published Guidance for Security Researchers to Coordinate Vulnerability Disclosures with Open Source Software Projects provides… Read more.
Concise Guides OpenSSF - Developing More Secure Software Evaluating Open Source Software

Sep 13, 2022 | OpenSSF

In Blog

Introducing New Concise Guides for Developing More Secure Software and Evaluating Open Source Software

In response to the growing concern around open source software development, OpenSSF’s Best Practices for Open Source Developers Working Group (WG) has been diligently working with concerned members and community groups on a couple of new guides for developers and consumers of open source. Read more.
Alpha-Omega Project

Sep 13, 2022 | OpenSSF

Alpha-Omega Project Announces Over $1.5M in Grants to Critical Open Source Projects and New Omega Analysis Toolchain

As part of the OpenSSF’s continued investment in critical open-source projects, we are happy to announce new partnerships and tooling from the Alpha-Omega Project. Alpha-Omega will sponsor critical security work with a $460K grant to the Rust Foundation. This work expands on funding previously announced earlier this year, bringing our… Read more.
New End Users WG OpenSSF

Sep 13, 2022 | OpenSSF

In Blog

Introducing the New OpenSSF End Users Working Group

OpenSSF is excited to announce its newest WG (Working Group), the End Users WG. This WG will focus on representing and addressing the challenges enterprises face when adopting (and using) different open-source technologies and products. Read more.
Show Off Your Score OpenSSF Security Scorecards

Sep 8, 2022 | OpenSSF

In Blog

Show Off Your Security Score: Announcing Scorecards Badges

We are excited to release new features from the Scorecards project, the OpenSSF tool that helps maintainers follow best security practices. The Scorecards GitHub Action now supports a REST API for quickly viewing project scores, and we’ve added one of our favorite new features: badges! We hope these additions will… Read more.
openssf npm best practices guide

Sep 1, 2022 | OpenSSF

In Blog

npm Best Practices for the Supply-Chain

We are excited to announce the v1 release of the “npm Best Practices,” a new guide focused on dependency management and supply chain security for npm. This release is the result of the OpenSSF Best Practice Working Group. It is a critical step to help JavaScript and TypeScript developers reduce… Read more.
Open Source Software Security Summit Japan

Aug 24, 2022 | amartin

In Blog

Outcomes from Open Source Software Security Summit in Japan

On August 23rd, we at the OpenSSF and Linux Foundation Japan hosted the Open Source Security Summit Japan. We were joined by senior cybersecurity representatives from more than 20 leading Japanese firms. We convened to discuss open source software (OSS) security challenges, modern challenges to the global software supply chain,… Read more.
OpenSSF Welcomes Capital One

Aug 24, 2022 | OpenSSF

Capital One Joins Open Source Security Foundation

Capital One joins the Open Source Security Foundation (OpenSSF) as a premier member affirming its commitment to strengthening the open source software supply chain. OpenSSF is a cross-industry organization hosted at the Linux Foundation, designed to inspire and enable the community to secure the open source software we all depend… Read more.