Recap: OpenSSF Community Day Korea 2025
OpenSSF Community Day Korea took place on November 4, 2025, in Seoul, bringing developers and security engineers together for a day of practical discussions on software security.
OpenSSF Community Day Korea took place on November 4, 2025, in Seoul, bringing developers and security engineers together for a day of practical discussions on software security.
At KubeCon+CloudNativeCon North America, Stacey Potter (OpenSSF) and Adolfo GarcĆa Veytia delivered one of the most memorable and entertaining keynotes of the week: āSupply Chain Reaction: A Cautionary Tale in Kubernetes Security.ā
In the latest OpenSSF Tech Talk, we focused on a significant hurdle in software supply chain security: managing software delivery and upkeep within air-gapped and restricted network environments. You can now view the recording on the OpenSSF YouTube channel, and the presentation slides are accessible here.
At the end of October 2025, the Linux Foundation Europe, OpenSSF, and CEPS brought together developers, maintainers, policymakers, and industry leaders for conversations on open source, security, and Europeās digital future. Through keynotes, workshops, and policy-focused sessions, the week created much-needed clarity around the Cyber Resilience Act (CRA) and, more broadly, the EU cybersecurity policy,…
At Open Source SecurityCon in Atlanta, the Open Source Security Foundation (OpenSSF) announced Target Corporation and Thread AI as new general members, OSTIFās upgrade to general membership, and recognized Golden Egg Award winners for their contributions to open source security. The Foundation continues to advance education, collaboration, and tooling to secure the global software supply…
OpenSSF sponsored the Open Source Finance Forum in New York, highlighting how collaboration between open source maintainers and the financial sector drives stronger cybersecurity. Talks covered AI security, the OSPS Baseline, and stabilizing vulnerability data, helping financial institutions build trust and resilience through open source.
By Madalin Neag, Kate Stewart, and David A. Wheeler In our previous blog post, we explored how the Software Bill of Materials (SBOM) should not be a static artifact created...
The Open Source Security Foundation (OpenSSF) has launched a new free course, Secure AI/ML-Driven Software Development (LFEL1012), authored by David A. Wheeler. As AI and machine learning become core to modern software development, this course helps developers understand and mitigate the security risks associated with AI code assistants. In just one hour, learners will gain…
Weāre pleased to announce the creation of a new BigQuery public dataset, rekor. The rekor dataset is an easily-queryable mirror of the public good instance of Sigstoreās transparency log, Rekor.
This blog was originally published on the OSTIF website on October 9, 2025 by Helen Wooste TheĀ Open Source Technology Improvement FundĀ is proud to share the results of our security audit...