Blog

Sigstore Announces General Availability at SigstoreCon

Today at SigstoreCon, the Sigstore community announced the general availability of its free software signing service giving open source communities access to production-grade stable services for artifact signing and verification. Sigstore provides a set of tools designed to improve supply chain security by making it easy to sign, verify and check the software developers are…

Report Finds OpenSSF Scorecards Are Highly Effective Measures to Assess Project Security

Projects adopting the practices set out by the OpenSSF in its Security Score, including adopting a dependency update tool that ensures rapid updating of vulnerable dependencies, will improve their project's security and the security of the open source projects that depend on them. Dependency management is critical, because Sonatype’s research revealed that about 6 out…

Securing Open Source Software is Securing Critical Infrastructure

Securing critical OSS components and infrastructure is an important part of securing critical infrastructure. When we consider open source critical infrastructure we must keep in mind that not all OSS is equally important, but some OSS (& its supporting infrastructure) are very critical. Several initiatives are underway at the OpenSSF to identify and fill gaps…

New Meet a Maintainer Series: Q&A with Azeem Shaikh, Senior Software Engineer, Google

Meet Azeem Shaikh, Senior Software Engineer, Google. Maintainers play a vital role in the OpenSSF and the Linux Foundation and we think you should get a chance to meet some of the amazing individuals powering open source software (OSS) security initiatives. Over the next few weeks we’ll be featuring maintainers and contributors and hearing how…