Blog

Introducing RSTUF, Repository Service for TUF

We’re thrilled to announce that RSTUF, Repository Service for TUF, has joined the OpenSSF as an OpenSSF Sandbox Project. This is a major step forward in ensuring we can improve secure content distribution. RSTUF helps address a major challenge: securing software repositories, particularly ensuring the integrity of software updates, is crucial to protect against supply…

OpenSSF Securing Software Repositories Working Group: Repositories, Registries, and Tools

The OpenSSF Securing Software Repositories Working Group focuses on the maintainers of software repositories, software registries, and the tools that rely on them. By repositories, we include all platforms where software is developed, including GitHub and other platforms. By registries, we include platforms such as package registries and other ways to distribute software artifacts. We…

Submit to Speak at OpenSSF Day Japan

We are pleased to announce that OpenSSF Day Japan will be taking place on December 4, 2023 at the Ariake Central Tower Hall & Conference, colocated with Open Source Summit Japan in Tokyo, Japan. Registration is now open, and you are invited to submit your talk to the call for proposals (CFP) for OpenSSF Day…

OpenSSF Scorecard Launches v4.12 with Support for GitLab

Today, we are excited to announce OpenSSF Scorecard v4.12. This release adds support for GitLab and brings the project closer to its longer-term goal of supporting all types of hosted repositories. Previously, Scorecard has been limited to GitHub-based repositories along with some support for local Git repositories. 

Join Us in Adopting the Open Source Consumption Manifesto

By adopting a few common principles, software organizations can achieve real, measurable change in the security and health of their software supply chains. You are invited to adopt the new Open Source Consumption Manifesto (OSCM) developed by the OpenSSF’s End Users Working Group and to sign the Manifesto by adding your name and submitting a…