Skip to main content
Category

Press Release

OpenSSF Welcomes New Members and Introduces New Initiatives at SOSS Community Day Japan

By Blog, Press Release

Growing Member Base and New Initiatives Continue to Advance Open Source Software Security

TOKYO, JAPAN – October 30, 2024 – The Open Source Security Foundation (OpenSSF), a global cross-industry initiative of the Linux Foundation that focuses on sustainably securing open source software (OSS), is excited to announce new members from leading technology, security, and research firms. The OpenSSF is also thrilled to host Secure Open Source Software (SOSS) Community Day at Open Source Summit Japan 2024, bringing together community members, maintainers, and contributors from across the globe.

New general member commitments from Arm, embraceable AI and Fujitsu along with new associate member commitments from Ruby Central and Trifecta Tech further strengthen the support for open source software security. With backing from these new organizations, the OpenSSF heads into the final quarter of 2024 with a robust member base dedicated to promoting a strong, vibrant, and secure open source software ecosystem.

“The addition of our newest members to the OpenSSF highlights the growing global commitment to strengthening open source software security,” said Arun Gupta, Vice President and General Manager, Developer Programs at Intel and OpenSSF Governing Board Chair. “By joining forces, we can address security challenges, foster innovative solutions, and build a safer digital future for everyone. With the support of these new members, we are further enabled to drive forward our shared mission.”

To celebrate its growing community, the OpenSSF is hosting SOSS Community Day Japan at Open Source Summit Japan 2024. SOSS Community Day Japan is an opportunity for community members from across the open source security ecosystem to come together and share ideas. With an agenda packed with sessions led by industry experts, the event will cover critical topics like education, innovation, tooling, vulnerabilities, and threats, showcasing the ongoing efforts of the OpenSSF community to enhance open source software security.

General Member Quotes

Arm

“At Arm, we recognize that collaboration is key to advancing the security of the global software ecosystem. By joining OpenSSF, we look forward to contributing to its mission of raising the bar on open source software security and underscoring our dedication to fostering standardization across the industry to give developers the confidence and tools they need to innovate.”

— Andrew Wafaa, Senior Director and Fellow, Software Communities, Arm

embraceable AI

“Security in the realm of AI is not just a feature; it’s the foundation of trust. As we empower enterprises with intelligent services, we prioritize safeguarding data and ensuring privacy, so our clients can innovate fearlessly.”  

— Dr.-Ing. Christian Gilcher, General Manager, embraceable AI 

Fujitsu

“Fujitsu is proud to have achieved conformance with OpenChain ISO/IEC 18974, demonstrating our commitment to open source compliance and excellence. Our next step is to join the OpenSSF. We take our dedication a step further to enhance the security and trustworthiness of the global software supply chain. Open source software is a key driver of innovation, and we look forward to collaborating with the OpenSSF community to ensure the resilience and transparency of the technologies shaping our future.”

— Teppei Asaba, Senior Director, Mission Critical System Business Unit, Fujitsu Limited

Associate Member Quotes

Ruby Central

“Joining OpenSSF aligns perfectly with Ruby Central’s commitment to advancing the security of open source ecosystems. By collaborating with OpenSSF and its community of forward-thinking organizations, we’re excited to bring our expertise from the Ruby ecosystem and work together on solutions that enhance the security and sustainability of open source software for all developers.”

— Marty Haught, Interim Open Source Lead, Ruby Central

Trifecta Tech

“We are excited to join the OpenSSF as an associate member as we continue to actively contribute to the security of the open source software we all rely on. Trifecta Tech Foundation is a non-profit working on safer software for the underlying infrastructure of the Internet and vital systems for water, energy, and communication. We develop and maintain open source software and contribute to open standards for these essential systems. Our projects include memory-safe alternatives to critical pieces of software like sudo, the Network Time Protocol, and zlib.”

— Erik Jonkers, Chair, Trifecta Tech Foundation

New Initiatives 

In addition to welcoming new members, OpenSSF is excited to announce several new initiatives aimed at bolstering open source software security.

Minder: contributed by Stacklok, is now a sandbox project within OpenSSF. Minder simplifies the integration and use of powerful security tools like OSV, OpenSSF Scorecard, and Sigstore, allowing developers and security teams to establish policies on code repositories and dependencies, reducing risk before and after code is merged.

bomctl: A format-agnostic Software Bill of Materials (SBOM) tooling project introduced in September 2024, aimed at enhancing SBOM generation and management across various formats.

Zarf: created by Defense Unicorns, launched in July 2024, Zarf is a free, open source tool enabling continuous software delivery on systems disconnected from the internet, facilitating secure software distribution in air-gapped environments.

These new initiatives demonstrate the OpenSSF’s continued dedication to fostering innovation and providing tools to enhance open source software security across diverse use cases.

Additional Resources

  • View the complete list of OpenSSF members.
  • To learn more about the OpenSSF community, including information about membership, contribution, project participation, and more, contact us.

###

About the OpenSSF

The Open Source Security Foundation (OpenSSF) is a cross-industry initiative by the Linux Foundation that brings together the industry’s most important open source security initiatives and the individuals and companies that support them. The OpenSSF is committed to collaboration and working both upstream and with existing communities to advance open source security for all. For more information, please visit openssf.org.

About the Linux Foundation

The Linux Foundation is the world’s leading home for collaboration on open source software, hardware, standards, and data. Linux Foundation projects are critical to the world’s infrastructure, including Linux, Kubernetes, Node.js, ONAP, OpenChain, OpenSSF, PyTorch, RISC-V, SPDX, Zephyr, and more. The Linux Foundation focuses on leveraging best practices and addressing the needs of contributors, users, and solution providers to create sustainable models for open collaboration. For more information, please visit linuxfoundation.org.

The Linux Foundation has registered trademarks and uses trademarks. For a list of trademarks of The Linux Foundation, please see its trademark usage page. Linux is a registered trademark of Linus Torvalds.

Media Contact
Jennifer Tanner
Look Left Marketing
openssf@lookleftmarketing.com

SOSS-Fusion-2024-OpenSSF-SOSS-Fusion-Conference-Kicks-off-with-Talks-from-Google-and-Cisco-Executives-

OpenSSF SOSS Fusion Conference Kicks off with Talks from Google and Cisco Executives

By Blog, Press Release

Event aims to create a more secure open source future by covering high-priority topics and offering workshops and industry expert insights

WASHINGTON — October 22, 2024 — The Open Source Security Foundation (OpenSSF) announced the opening of the Secure Open Source Software (SOSS) Fusion Conference in North America in Atlanta, GA, today. This event unites a diverse community of professionals, including public sector leaders, software developers, security engineers, students, cybersecurity experts, CISOs, CIOs, founders, and tech pioneers. With a robust agenda covering AI security, critical open source security projects, public policy, and today’s most pressing security topics, SOSS Fusion offers a comprehensive look at OpenSSF’s initiatives that’s aimed at simplifying security for developers, and will help them prepare to shape a safer digital world in 2025 and beyond. 

The OpenSSF supports a vibrant, active community developing tools and best practices to aid developers on their security journey. With 7,500-plus projects in the OpenSSF Best Practices Badge program, the foundation remains committed to educating and influencing the broader community through thought leadership in open source security. This year, OpenSSF staff and community members have presented at over 30 meaningful events, such as VulnCon, OSPOs for Good, OECD Global Forum on Digital Security for Prosperity, and Grace Hopper Celebration, among others.

This event aims to strengthen the community by bringing together industry leaders, developers, project maintainers, students, and security researchers. Together, they will exchange actionable insights and introduce state-of-the-art tools to improve the security of open source software for everyone. Participants will stay informed about the latest advancements in open source security.

“When I look at the lineup of topics at SOSS Fusion and speakers I am reminded of our amazing community. I see an excellent mixture of our seasoned members and projects alongside new and exciting voices joining us for the first time,” said CRob, chief security architect at OpenSSF. “The sessions cover important key topics ranging from AI and machine learning security, to some of our newest projects, like Zarf. This event will be valuable to attendees and will showcase the most innovative ideas and initiatives the open source community has to offer.”

Along with notable keynote sessions and workshops, the agenda will highlight key themes from Cisco, Google, Kusari, and Linux Foundation executives including:

Recorded sessions will be available on demand approximately two weeks after the event. Sign up for the OpenSSF newsletter to receive notifications about the recorded sessions, and visit the website to learn more about becoming an OpenSSF member.

About the OpenSSF

The Open Source Security Foundation (OpenSSF) is a cross-industry initiative by the Linux Foundation that brings together the industry’s most important open source security initiatives and the individuals and companies that support them. The OpenSSF is committed to collaborating and working upstream and with existing communities to advance open source security. For more information, please visit us at openssf.org.

Media Contact:

Jennifer Tanner
Look Left Marketing
openssf@lookleftmarketing.com

OpenSSF Announces Key Themes of AI Security, Diversity and Open Source Public Policy at SOSS Fusion Conference

By Blog, Press Release

Engaging Sessions Led by Industry Experts Will Empower Attendees With the Knowledge, Tools, and Connections to Drive Innovation and Enhance Security in the Open Source Ecosystem

WASHINGTON — September 26, 2024 — The Open Source Security Foundation (OpenSSF) is pleased to announce the agenda for its inaugural Secure Open Source Software (SOSS) Fusion Conference, which will take place October 22-23, 2024, in Atlanta, Ga. Featuring presentations covering a variety of high-priority topics, including AI security, diversity, OSS consumption and public policy, the conference will bring together a diverse group of professionals from both the public and private sectors — software developers, security engineers, cybersecurity experts and leaders, founders, tech pioneers and policymakers — to collaborate on creating a more secure open source future. 

In the wake of recent high-profile incidents including XZ Utils, there has been an industry-wide pivot to focus on creating and implementing programs and best practices to bolster open source security. SOSS Fusion will unite key stakeholders for discussions, training and community-building opportunities to advance a more secure digital future. The program will feature keynotes from industry leaders, including:

  • Decoding the AI Revolution; Implications for Security and Society: AI Security Matters: Bruce Schneier, renowned security technologist and best-selling author
  • Window Snyder, founder and CEO at Thistle Technologies (session details forthcoming)
  • Enshittification Was a Choice: Cory Doctorow, science fiction author, activist and journalist
  • Government’s Continuing Path Contributing Towards a Secure Open Source Ecosystem: Timothy Pepper, senior technical advisor, open source software security, U.S. Cybersecurity and Infrastructure Security Agency (CISA)
  • Setting the Standard — Safely Operationalizing OSS Contributions: Brenton Stevens, open source compliance manager, Fannie Mae
  • There Is Just One Way to Do Open Source Security: Together: Marten Mickos, CEO, HackerOne

“Security in the open source world is not just about technology; it’s about building a culture of collaboration and trust,” said Arun Gupta, vice president and general manager of Open Ecosystem Initiatives at Intel and OpenSSF governing board chair. “At SOSS Fusion, we’re bringing together the best minds in the industry to address the pressing challenges of our time, from AI security to diversity and public policy. This conference is an essential step towards creating a safer, more inclusive digital future.”

It will also showcase workshops on the latest security technologies, panel discussions on emerging cyber threats, and networking opportunities with peers and industry leaders. Agenda highlights include:

  • Building Developer Confidence in Software Security With the DevRel Community [Panel]: Katherine Druckman, Intel Corporation; Tabatha DiDomenico, G-Research; Lori Lorusso, Percona
  • Assessing Open Source Software Projects in the Software Supply Chain: Scott Hissam, Carnegie Mellon Software Engineering Institute, and Joshua “CoCo” Crisp, Unified Platform (USCYBERCOM)
  • Trojan Model Hubs: Hacking the ML Supply Chain and Defending Yourself from Threats: Sam Washko and William Armiros, Protect AI
  • Navigating the Quantum Readiness Journey: Hands-on Guidance for Starting Your Migration: Eric Mizell, Keyfactor
  • Is Diversity the Top Ingredient in Your SBOM?: Rao Lakkakula and Tunji Taiwo, JPMorgan Chase

Registration for SOSS Fusion 2024 is now open. To learn more about the event, including sponsorship opportunities, please visit the event website.

About the OpenSSF

The Open Source Security Foundation (OpenSSF) is a cross-industry initiative by the Linux Foundation that brings together the industry’s most important open source security initiatives and the individuals and companies that support them. The OpenSSF is committed to collaborating and working upstream and with existing communities to advance open source security. For more information, please visit us at openssf.org.

Media Contact:

Jennifer Tanner
Look Left Marketing
openssf@lookleftmarketing.com