Guest blog opportunities are open to members, with limited exceptions for active contributors and thought leaders. Share your insights on open source security with our community.
OpenSSF Blog
Jun 25, 2025 |
An Introduction to the OpenSSF Model Signing (OMS) Specification: Model Signing for Secure and Trusted AI Supply Chains
By Mihai Maruseac (Google), Eoin Wickens (HiddenLayer), Daniel Major (NVIDIA), Martin Sablotny (NVIDIA) As AI adoption continues to accelerate, so does the need to secure the AI supply chain. Organizations want to be able to verify that the models they build, deploy, or consume are authentic, untampered, and compliant with… Read more.
Jun 18, 2025 |
In Blog
Member Spotlight: Datadog â Powering Open Source Security with Tools, Standards, and Community Leadership
Datadog, a leading cloud-scale observability and security platform, joined the Open Source Security Foundation (OpenSSF) as a Premier Member in July, 2024. With both executive leadership and deep technical involvement, Datadog has rapidly become a force in advancing secure open source practices across the industry. Key Contributions GuardDog: Open Source… Read more.
Jun 17, 2025 |
In Blog
OpenBao Joins the OpenSSF to Advance Secure Secrets Management in Open Source
Weâre excited to welcome OpenBao to the Open Source Security Foundation (OpenSSF) as a newly accepted sandbox project! Read more.
Jun 16, 2025 |
In Blog
Tech Talk Recap | CRA-Ready: How Open Source Projects Can Prepare for the EU Cyber Resilience Act
The EU Cyber Resilience Act (CRA) is reshaping the landscape for open source software. Whether you're a maintainer, contributor, or vendor, the CRA introduces new expectationsâand new responsibilities. To help the community navigate these changes, the Open Source Security Foundation (OpenSSF) recently hosted a Tech Talk: CRA-Ready: How to Prepare… Read more.
Jun 13, 2025 |
Case Study: OSTIF Improves Security Posture of Critical Open Source Projects Through OpenSSF Membership
Organization: Open Source Technology Improvement Fund, Inc. (OSTIF) Contributor: Amir Montazery, Managing Director Website: ostif.org Problem Critical open source software (OSS) projectsâespecially those that are long-standing and widely adoptedâoften lack the resources and systematic support needed to regularly review and improve their security posture. Many of these projects are maintained… Read more.
Jun 12, 2025 |
GUAC 1.0 is Now Available
The GUAC project is proud to announce the release of GUAC 1.0. GUAC â which stands for âGraph for Understanding Artifact Compositionâ is an OpenSSF incubating project that brings understanding and insights to the software supply chain. Started by Kusari, Google, and Purdue University, GUAC has contributions from over 400… Read more.
Jun 11, 2025 |
Maintainersâ Guide: Securing CI/CD Pipelines After the tj-actions and reviewdog Supply Chain Attacks
CI/CD pipelines are increasingly becoming high-value targets for attackers. With access to secrets, source code, and infrastructure, they offer a direct route to supply chain compromise. The recent breaches involving tj-actions/changed-files and reviewdog/action-setup are not just isolated events, they are harbingers of a new generation of CI/CD-targeted supply chain attacks. Read more.
Jun 6, 2025 |
From Sandbox to Incubating: gittufâs Next Step in Open Source Security
Weâre pleased to share that gittuf, a platform-agnostic Git security framework, has officially progressed to the Incubating Project stage under the Open Source Security Foundation (OpenSSF). This marks a major milestone in gittufâs development and recognizes the projectâs technical progress, community growth, and alignment with the broader mission of strengthening… Read more.
Jun 5, 2025 |
Choosing an SBOM Generation Tool
Software Bills of Materials (SBOMs) are the foundational piece of understanding your software supply chain. By listing the components that go into your application, SBOMs give you a starting point for understanding risks â including vulnerabilities, license issues, and other supply chain risks. But how do you create those SBOMs? Read more.
Jun 2, 2025 |
OSS and the CRA: am I a Manufacturer or a Steward?
The European Unionâs Cyber Resilience Act (CRA) is a piece of legislation that covers all countries within the EU and the EEA and entered into force on 10th December 2024. It covers many types of devices and applications that are either sold or otherwise made commercially available on the European… Read more.









