Apr 16, 2024 |
CISA, DHS S&T and OpenSSF Announce Global Launch of Software Supply Chain Open Source Project
The Open Source Security Foundation (OpenSSF), in collaboration with the Cybersecurity and Infrastructure Security Agency (CISA), and the Department of Homeland Security (DHS) Science and Technology Directorate (S&T), today announced the launch and availability of Protobom, a new and innovative open source software supply chain tool. Read more.
Apr 15, 2024 |
OpenSSF Announces New Members & Initiatives at SOSS Community Day North America
The Open Source Security Foundation (OpenSSF), a global cross-industry initiative of the Linux Foundation that focuses on sustainably securing open source software (OSS), is excited to announce new members from leading technology, aerospace, and security firms at Secure Open Source Software (SOSS) Community Day North America. Read more.
Apr 15, 2024 |
In Blog
Open Source Security (OpenSSF) and OpenJS Foundations Issue Alert for Social Engineering Takeovers of Open Source Projects
The recent attempted XZ Utils backdoor (CVE-2024-3094) may not be an isolated incident as evidenced by a similar credible takeover attempt intercepted by the OpenJS Foundation, home to JavaScript projects used by billions of websites worldwide. The Open Source Security (OpenSSF) and OpenJS Foundations are calling all open source maintainers… Read more.
Apr 15, 2024 |
In Blog
Unveiling the Golden Egg Award Winners: Celebrating Excellence in Open Source Security
We’re excited to announce the winners of the Golden Egg Awards. These awards shine a light on those who go above and beyond in enriching our community. The Golden Egg Award symbolizes the community’s gratitude for selfless dedication to securing open source projects through community engagement, engineering, innovation, and thoughtful… Read more.
Apr 12, 2024 |
In Blog
Sessions You Won’t Want to Miss at SOSS Community Day NA and Open Source Summit North America 2024
Get ready for the Secure Open Source Software (SOSS) Community Day NA and Open Source Summit North America 2024, next week in Seattle, Washington! These events are where open source communities converge to collaborate, drive innovation, and foster a vibrant open source ecosystem. Read more.
Apr 11, 2024 |
In Blog
“What’s in the SOSS?” Podcast is Now Live
In our first podcast – Vincent Danen and the Art of Vulnerability Management, Omkhar Arasaratnam, General Manager of OpenSSF, talks to Vincent Danen, Vice President of Product Security at Red Hat, who is responsible for security and compliance activities across Red Hat's products and services. He’s also on the Governing Board… Read more.
Apr 10, 2024 |
In Blog
Join us for a TTX: Securing OSS & Empowering Maintainers
At SOSS Community Day NA on April 15, 2024 the OpenSSF Community will conduct a Tabletop Exercise (TTX). Periodically walking through various scenarios of a supply chain attack in a time of calm helps identify action items that are important to prepare in advance for when real attacks occur. A… Read more.
Apr 4, 2024 |
Static Binary Analysis: A Final Exam for Software Supply Chain Protection
The compromise of VoIP provider 3CX is just one of the latest incidents to highlight gaps in software supply chain security - and the need for a new approach to supply chain risk management, writes Charlie Jones of ReversingLabs. Read more.
Mar 30, 2024 |
In Blog
xz Backdoor CVE-2024-3094
CVE-2024-3094 documents a backdoor in the xz package. While the motivation behind this backdoor remains unknown, the intent was to compromise specific distributions, as the backdoors were only applied to DEB or RPM packages for the x86-64 architecture built with gcc and the gnu linker. Situations like this remind us… Read more.
Mar 29, 2024 |
In Blog
VulnCon 2024 Wrap-up: Securing the Ecosystem through Global Cooperation
The OpenSSF was pleased to be one of the sponsors that helped contribute to the inaugural 2024 VulnCon conference that brought together experts from across industry, government, security researchers, and community members throughout 3 days and nearly 40 sessions. Brought together by the FIRST PSIRT SIG and the CVE Board. Christopher… Read more.