
The July 2026 OpenSSF Newsletter highlights the upcoming Community Day Europe agenda and new compliance resources for the EU Cyber Resilience Act (CRA). It also introduces a dedicated Policy & Regulatory section, technical updates on dependency firewalls and AI artifact signing, and global community outreach efforts.
TL;DR:
- 📅 OpenSSF Community Day Europe 2026 Program Schedule Is Live → The full lineup for October 6 in Prague is here – check out what’s in the agenda this year.
- 📘 New eBook, Built to Last: Understanding the European Cyber Resilience Act (CRA) → Learn about the CRA jargon so you know exactly what applies to you.
- 🔥 What Is a Dependency Firewall? → Stop malicious packages before they install, not after the damage is done.
- 🌍 Representing OpenSSF at AfricaCyberFest → One session in Lagos turned into 7+ new contributors and a growing community.
- 🎙️ Podcast: AI, Model Signing, and the Kernel → Alpha-Omega’s $20M milestone, securing AI/ML artifacts, and why upstream is the ultimate security strategy.
7 mins read
OpenSSF Community Day Europe 2026 Schedule Is Live
Register for the event | View the full schedule | Join as a sponsor
The full session schedule for OpenSSF Community Day Europe is now live ahead of the October 6 event in Prague, co-located with Open Source Summit Europe.
- What’s on the agenda? Read OpenSSF Community Day Europe 2026: Schedule Highlights & What to Expect

- Read OpenSSF Community Day North America (NA) First-time Experience and learn about a first-timer’s take on why these gatherings function as collaborative ecosystems, not just meetings.

- New track unlocked! Read Bridging the Gap Between Code and Research: Why SCORED ’26 Matters for Open Source Security, which explores how the Workshop on Software Supply Chain Offensive and Defensive Research at Community Day Europe fosters collaboration between academia and the open source ecosystem.

New eBook: Built to Last: Understanding the European Cyber Resilience Act (CRA)
With awareness still lagging and the first compliance deadline weeks out, OpenSSF has a new resource to help close the gap. Written by Sal Kimmich of OpenUK, the eBook walks through what the CRA actually requires, who it applies to, and how manufacturers and open source stewards can start building toward compliance. Download the eBook.
What Is a Dependency Firewall?
Most security scanning happens after a package is already installed, by which point a malicious install script may already have grabbed credentials, tokens, or source code. A dependency firewall moves that decision earlier, evaluating packages before they’re allowed onto a workstation, into a CI/CD pipeline, or into an AI coding agent’s workspace. Aikido Security’s Nicholas Thomson walks through what these tools should check for, from typosquatting and dependency confusion to the slopsquatting risk created by AI agents recommending packages that don’t actually exist. Read the full post.
Navigating The OpenSSF is as Easy as Floating Down A Lazy River
This new framework provides role-specific User Journeys, offering a curated path to essential resources for everyone from OSPO leads and security engineers to developers and executives. The “Lazy River” significantly reduces the cognitive load for newcomers. It ensures that critical security best practices are not just accessible, but actionable, regardless of your organizational role or technical expertise. Read the blog.
The CRA Readiness Reality: What Changed (and What Didn’t) Between 2025 and 2026?
Last year’s survey found that 62% of the open source community had little to no familiarity with the EU Cyber Resilience Act. A year later, with the first compliance deadline just weeks away, the number has climbed to 66%, and to 72% in the US and Canada. Read the full analysis for what’s changed, what hasn’t, and where the community goes from here.
Representing OpenSSF at AfricaCyberFest
OpenSSF’s BEAR Working Group took the stage in Lagos to introduce the OpenSSF Africa Special Interest Group, walking the audience through OpenSSF’s tools, standards, and community programs. A booth conversation after the session led to a connection with the University of Lagos Cybersecurity Group; a follow-up visit brought about seven new contributors into the community. Read the recap.
What’s in the SOSS? An OpenSSF Podcast:
What does it feel like to wake up and realize your weekend passion project is now the critical infrastructure powering the planet? In this episode of What’s in the SOSS?, CRob sits down with Linux Kernel Maintainer Greg Kroah-Hartman to explore why sending fixes upstream is the ultimate security strategy for long-term code stability. Listen now.
#65 – S3E17 Signing the Future: Securing AI and ML Artifacts with Mihai Maruseac
In this episode, host Yesenia Yser sits down with Mihai Maruseac to discuss the OpenSSF Model Signing (OMS) specification, securing the AI/ML supply chain, and bringing transparency and trust to modern machine learning artifacts. Listen now.
#66 – S3E18 Turning AI into the Ultimate Open Source Maintainer Power Tool with Michael Winser
CRob welcomes back Michael Winser to celebrate Alpha-Omega surpassing $20 million in security grants. They discuss the economics of package registries and how AI can be transformed into the ultimate power tool for open source maintainers. Listen now.
News from OpenSSF Community Meetings and Projects:
- The TAC approved Privateer’s sandbox project application. Privateer is a plugin-based framework for security and compliance validation of deployed systems.
- The Supply Chain Integrity WG proposed an updated Charter v2.0 to pivot focus directly toward maintainer enablement.
- The Securing Software Repositories WG reviewed recent security measures across major ecosystems, including preventive account protections for high-impact npm accounts, GitHub Actions improvements (safer pull_request_target defaults, trigger controls, read-only caches), and PyPI’s policy prohibiting new file uploads two weeks post-release.
- OpenBao released v2.6.0 introducing namespace sealing, external Auto Unseal KMS plugins, and API workflows, followed by v2.6.1 with fixes for policy persistence and container image compliance.
- Minder published v0.2.2, featuring terminal client UI improvements, interactive live profile editing, generic entity management commands, and a new Starlark-based rule testing command (mindev test).
- Zarf released v0.82.0, introducing CLI type inference for values, namespace-scoped watches for health checks, and multi-version API schema support.
- OSV Schema released v1.8.0, expanding coverage to include the Azure Linux, TuxCare, and vcpkg package ecosystems along with CVSS severity source attribution.
- AMPEL released v1.3.3, extending official binary release support across all GitHub Actions runner platforms.
- The Global Cyber Policy WG has submitted feedback to ENISA’s public consultation on the Technical Advisory on Secure Update Mechanisms. The working group is also seeking community input for the public consultation on the Cloud and AI Development Act, part of the Tech Sovereignty Package. The group is also looking for community feedback to help shape the next in-person CRA Workshop in Prague. Share your thoughts by answering five short questions.
- The ORBIT Launchpad SIG has completed CRABFOSC v1 (CRA Baseline for Open Source Consumption), establishing standardized due-diligence criteria for software consumers under the EU Cyber Resilience Act.
- A newly proposed SBOM-VEX Working Group is seeking community feedback on its charter.
- Alpha-Omega has recently introduced a predictable four-quarter seasonal grant framework, expanded hands-on support through Security Engineers in Residence, completed security enhancements for Rust and PyTorch ExecuTorch, and rolled out the AI-powered vulnerability scanner Scrutineer.
Cybersecurity Policy & Regulatory Updates
- Following the public consultation held in March-April 2026, the European Commission has published new guidance on CRA implementation, offering fresh clarifications that complement the existing CRA implementation FAQ.
- The Commission has also released the minutes from the June 10 CRA Expert Group meeting.
- ENISA has refreshed the FAQ section on the Single Reporting Platform, giving reporting entities clearer guidance on that process.
- The agency has also published its SME CRA Survey Report, drawing on a survey run in February and March. Alongside it, ENISA released the SME Cyber Resilience Maturity Assessment Model and a companion assessment tool – useful if you’re / helping smaller organizations gauge their CRA readiness.
- ENISA also issued the final version of the ENISA Secure by Design and Default Playbook
- If your organization falls under NIS2, take note: ENISA has launched a survey for national authorities and high-critical entities to inform the next NIS360 report. (Catch up on the previous edition here.)
- BSI Germany has put out a Community Draft of its AI Audit and Assurance Assessment Architecture (A5), open for feedback.
- CyberStand.eu is running a survey to assess how ready existing standards are for the CRA
- The EU-funded StandICT project has opened a new call for experts who want to get involved in standardisation work tied to the CRA.
Member Spotlights
CleanStart – Why Vulnerability Scanning Alone Is Not Enough
Standard scanning reveals exposure but fails to establish trust, flagging known defects only after an image is constructed. This approach overlooks provenance, build integrity, and runtime permissions, leaving root-access vulnerabilities unchecked even in “clean” images. OpenSSF General Member CleanStart cites the xz/liblzma backdoor as a definitive proof of this gap, where malicious code bypassed conventional scanners because no matching signatures existed yet. Read the full article.
Cloudsmith – Webinar: Inside the Open Source Malware Attack Landscape
Malicious activity is surfacing across fresh vectors, including VS Code extensions and GitHub repositories. Join Nigel Douglas from OpenSSF’s General Member Cloudsmith on August 13 at 4pm BST to dissect these emerging threats and explore strategies for defending against sophisticated adversaries. Register here.
Balena – CRA Research: Relevance to the Edge/IoT Community
As a key contributor to the 2026 CRA Awareness and Readiness Report, OpenSSF’s General Member Balena examines the specific implications of these regulatory findings for the IoT and edge ecosystems. Read their insight.
Meet OpenSSF at These Upcoming Events!
- Black Hat 2026 – August 1–4, Las Vegas, NV
- OpenSSF Community Day Europe 2026 – October 6, Prague, Czechia
- Open Source Summit Europe 2026 – October 7–9, Prague, Czechia
- All Things Open 2026 – October 19–20, Raleigh, NC
- ETSI Security Conference 2026 – October 19-22, Sophia Antipolis, France
- AGNTCon + MCPCon North America – October 20–23, San Jose, CA
- Open Source SecurityCon North America 2026 – November 9, Salt Lake City, UT
- KubeCon + CloudNativeCon North America 2026 – November 9–12, Salt Lake City, UT
Ways to Participate:
There are a number of ways for individuals and organizations to participate in OpenSSF. Learn more here.
You’re invited to…
- Join a Working Group or Project
- Chat with us on Slack
- Follow us on X, Mastodon, Bluesky, and LinkedIn
- Join OpenSSF
See You Next Month!
We want to get you the information you most want to see in your inbox. Missed our previous newsletters? Read here!
Have ideas or suggestions for next month’s newsletter about the OpenSSF? Let us know at marketing@openssf.org, and see you next month!
Regards,
The OpenSSF Team