OpenSSF Newsletter – May 2026

By May 28, 2026

What a month! May was packed with milestones for the OpenSSF community, and we’re still riding the high from an incredible OpenSSF Community Day North America in Minneapolis. The community showed up in full force to celebrate some major wins: five new members, the launch of our inaugural Ambassador Program, a brand new AI eBook, the Python Secure Coding Guide, and so much more. A full recap of Community Day is coming soon, so stay tuned. In the meantime, read on to catch up on everything new in May!

TL;DR:

  • 🚀 Q2 Foundational Wins → Five new members, OSS-CRS sandbox project, and v1.0.0 Python Secure Coding Guide celebrated at OpenSSF Community Day North America 2026.
  • 🤝 Ambassador Program Launches → First cohort of 13 OpenSSF Ambassadors announced to spread security best practices globally.
  • 📖 New eBook: Securing Open Source in the Age of AI → Crafted in partnership with CNCF, this eBook translates practical expertise into actionable guidance to help your project thrive in the age of AI. 
  • 🐍 Python Secure Coding Guide v1.0 → BEST WG publishes the first framework-independent resource for Python secure coding practices.
  • ⚖️ CRA Compliance Wake-Up Call → An urgent wake-up call: the EU Cyber Resilience Act September deadline is fast approaching, and the ecosystem must act.
  • 📦 Package Registry Sustainability → New pressure on open source package registries fuels Part II of the “Open Infrastructure Is Not Free” series.
  • 🤖 DARPA AIxCC Legacy → A look back at the impact and legacy of the AI Cyber Challenge, now powering OSS-CRS – the newest project of OpenSSF.

OpenSSF Notes Quarter of Growth with New Members, Added AI Security Resources, and Growing Community

Announced live at OpenSSF Community Day North America in Minneapolis, OpenSSF welcomed five new members: ActiveState, Aikido Security, Minimus, TuxCare (General Members), and the FreeBSD Foundation (Associate Member). We also released the v1.0.0 Python Secure Coding Guide, launched the first Ambassador cohort, and formally accepted OSS-CRS as a Sandbox project. Learn more about all the exciting news!

Introducing the First Cohort of the OpenSSF Ambassador Program

Securing the open source ecosystem requires passionate advocates. At OpenSSF Community Day, OpenSSF launched its inaugural Ambassador Program and announced 13 community leaders committed to spreading security best practices and growing the global OpenSSF community. Read the blog and get to know the ambassadors.

Securing Open Source in the Age of AI

Securing Open Source in the Age of AI eBookNew AI Security eBook: In collaboration with CNCF, OpenSSF released Securing Open Source in the Age of AI: A Practical Guide for Maintainers, Security Engineers, and Researchers, covering AI-generated contributions and AI-assisted security workflows. Download the eBook now.

Taking Stock of the State of European Cyber Resilience Act (CRA) Compliance: An Urgent Wake-up Call for the Open Source Ecosystem

Hear from CRob as he highlights that the EU Cyber Resilience Act (CRA) is no longer theoretical – it’s live and the September deadline is fast approaching. In this blog, CRob urges the open source ecosystem to move from mapping requirements to active compliance, outlining what foundations and maintainers need to do right now. Read the blog.

Secure Coding Guide for Python (pyscg) First Release

Python powers web apps, data pipelines, AI/ML, and cloud infrastructure, yet developers have lacked a single, framework-independent secure coding resource. The BEST Working Group’s v1.0.0 release fills that gap with high-confidence anti-patterns and compliant code examples to mitigate common vulnerabilities. Read this latest guide.

Hack to the Future: The Impact and Legacy of the DARPA AIxCC Challenge

Since DARPA’s 2023 announcement, the AI Cyber Challenge (AIxCC) has developed open source AI tooling to safeguard critical infrastructure. This post charts the competition’s results, the winning teams’ strategies, and how the challenge’s output now lives on inside OpenSSF through OSS-CRS. Read the blog by Helen Woeste for OSTIF and learn about the AIxCC challenge. 

The Road to Gold: How CPS Set a New Standard for Security and Quality in Open Source

The ONAP CPS project’s journey to achieving an OpenSSF Gold badge illustrates what it takes to meet rigorous security and quality baselines in a large-scale network automation framework. Read the guest blog by Toine Siebelink from Ericsson, detailing community-driven security uplift as a model for others.

Open Infrastructure Is Not Free, Part II: The Hidden Cost of Running Package Registries

Building on the 2025 open letter on open source sustainability, this post examines the growing economic pressures facing package registries as AI adoption accelerates. Rising bandwidth, security demands, and storage costs are making the status quo untenable – and the community must respond. Read the blog to learn more.

Detecting Malicious Packages Using the OSV API

The OpenSSF Malicious Packages repository is the first open source system for collecting and distributing malicious package data. This guest post by Nigel Douglas from Cloudsmith walks through how security teams can integrate the OSV API into day-to-day supply chain workflows to catch threats early. Read the blog.

What’s in the SOSS? An OpenSSF Podcast:

#60 – S3E12 Packaging, Transferring, and Deploying Software in Air-Gapped Environments with Zarf

Join Brandt Keller (Staff Software Engineer at Defense Unicorns and Maintainer of the OpenSSF Sandbox Project Zarf) as he discusses Zarf’s origins as a tool for deploying software in fully air-gapped environments. Listen to the podcast and learn about the growing need for defense and critical infrastructure operators in the ecosystem.

61 – S3E13 Beginner to Builder: Shaping the Conversation in Open Source Security

In this episode of the podcast, Yesenia Yser interviews cybersecurity analyst Ejiro Oghenekome about her journey from UI/UX design to becoming a key contributor to the OpenSSF. Ejiro shares the inspiration behind her public “100 Days of Cybersecurity” challenge, which has helped her maintain discipline and consistency while making the field less intimidating for beginners.

News from OpenSSF Community Meetings and Projects:

Upcoming community meetings

In the News:

Meet OpenSSF at These Upcoming Events!

Connect with the OpenSSF Community at these key events:

Ways to Participate:

There are a number of ways for individuals and organizations to participate in OpenSSF. Learn more here.

You’re invited to…

See You Next Month! 

We want to get you the information you most want to see in your inbox. Missed our previous newsletters? Read here!

Have ideas or suggestions for next month’s newsletter about the OpenSSF? Let us know at marketing@openssf.org, and see you next month! 

Regards,

The OpenSSF Team