OpenSSF Newsletter – July 2026

By July 30, 2026

The July 2026 OpenSSF Newsletter highlights the upcoming Community Day Europe agenda and new compliance resources for the EU Cyber Resilience Act (CRA). It also introduces a dedicated Policy & Regulatory section, technical updates on dependency firewalls and AI artifact signing, and global community outreach efforts.

TL;DR:

7 mins read

OpenSSF Community Day Europe 2026 Schedule Is Live

Register for the event | View the full schedule | Join as a sponsor

The full session schedule for OpenSSF Community Day Europe is now live ahead of the October 6 event in Prague, co-located with Open Source Summit Europe. 

New eBook: Built to Last: Understanding the European Cyber Resilience Act (CRA)

With awareness still lagging and the first compliance deadline weeks out, OpenSSF has a new resource to help close the gap. Written by Sal Kimmich of OpenUK, the eBook walks through what the CRA actually requires, who it applies to, and how manufacturers and open source stewards can start building toward compliance. Download the eBook.

What Is a Dependency Firewall?

Most security scanning happens after a package is already installed, by which point a malicious install script may already have grabbed credentials, tokens, or source code. A dependency firewall moves that decision earlier, evaluating packages before they’re allowed onto a workstation, into a CI/CD pipeline, or into an AI coding agent’s workspace. Aikido Security’s Nicholas Thomson walks through what these tools should check for, from typosquatting and dependency confusion to the slopsquatting risk created by AI agents recommending packages that don’t actually exist. Read the full post.

Navigating The OpenSSF is as Easy as Floating Down A Lazy River

This new framework provides role-specific User Journeys, offering a curated path to essential resources for everyone from OSPO leads and security engineers to developers and executives. The “Lazy River” significantly reduces the cognitive load for newcomers. It ensures that critical security best practices are not just accessible, but actionable, regardless of your organizational role or technical expertise. Read the blog

The CRA Readiness Reality: What Changed (and What Didn’t) Between 2025 and 2026?

Last year’s survey found that 62% of the open source community had little to no familiarity with the EU Cyber Resilience Act. A year later, with the first compliance deadline just weeks away, the number has climbed to 66%, and to 72% in the US and Canada. Read the full analysis for what’s changed, what hasn’t, and where the community goes from here.

Representing OpenSSF at AfricaCyberFest

OpenSSF’s BEAR Working Group took the stage in Lagos to introduce the OpenSSF Africa Special Interest Group, walking the audience through OpenSSF’s tools, standards, and community programs. A booth conversation after the session led to a connection with the University of Lagos Cybersecurity Group; a follow-up visit brought about seven new contributors into the community. Read the recap.

What’s in the SOSS? An OpenSSF Podcast:

#64 – S3E16 The Heartbeat of the Kernel: Why Upstream is the Ultimate Security Strategy with Greg Kroah-Hartman

What does it feel like to wake up and realize your weekend passion project is now the critical infrastructure powering the planet? In this episode of What’s in the SOSS?, CRob sits down with Linux Kernel Maintainer Greg Kroah-Hartman to explore why sending fixes upstream is the ultimate security strategy for long-term code stability. Listen now.

#65 – S3E17 Signing the Future: Securing AI and ML Artifacts with Mihai Maruseac

In this episode, host Yesenia Yser sits down with Mihai Maruseac to discuss the OpenSSF Model Signing (OMS) specification, securing the AI/ML supply chain, and bringing transparency and trust to modern machine learning artifacts. Listen now.

#66 – S3E18 Turning AI into the Ultimate Open Source Maintainer Power Tool with Michael Winser

CRob welcomes back Michael Winser to celebrate Alpha-Omega surpassing $20 million in security grants. They discuss the economics of package registries and how AI can be transformed into the ultimate power tool for open source maintainers. Listen now.

News from OpenSSF Community Meetings and Projects:

Upcoming community meetings

  • The TAC approved Privateer’s sandbox project application. Privateer is a plugin-based framework for security and compliance validation of deployed systems.
  • The Supply Chain Integrity WG proposed an updated Charter v2.0 to pivot focus directly toward maintainer enablement.
  • The Securing Software Repositories WG reviewed recent security measures across major ecosystems, including preventive account protections for high-impact npm accounts, GitHub Actions improvements (safer pull_request_target defaults, trigger controls, read-only caches), and PyPI’s policy prohibiting new file uploads two weeks post-release.
  • OpenBao released v2.6.0 introducing namespace sealing, external Auto Unseal KMS plugins, and API workflows, followed by v2.6.1 with fixes for policy persistence and container image compliance.
  • Minder published v0.2.2, featuring terminal client UI improvements, interactive live profile editing, generic entity management commands, and a new Starlark-based rule testing command (mindev test).
  • Zarf released v0.82.0, introducing CLI type inference for values, namespace-scoped watches for health checks, and multi-version API schema support.
  • OSV Schema released v1.8.0, expanding coverage to include the Azure Linux, TuxCare, and vcpkg package ecosystems along with CVSS severity source attribution.
  • AMPEL released v1.3.3, extending official binary release support across all GitHub Actions runner platforms.
  • The Global Cyber Policy WG has submitted feedback to ENISA’s public consultation on the Technical Advisory on Secure Update Mechanisms. The working group is also seeking community input for the public consultation on the Cloud and AI Development Act, part of the Tech Sovereignty Package. The group is also looking for community feedback to help shape the next in-person CRA Workshop in Prague. Share your thoughts by answering five short questions.
  • The ORBIT Launchpad SIG has completed CRABFOSC v1 (CRA Baseline for Open Source Consumption), establishing standardized due-diligence criteria for software consumers under the EU Cyber Resilience Act.
  • A newly proposed SBOM-VEX Working Group is seeking community feedback on its charter.
  • Alpha-Omega has recently introduced a predictable four-quarter seasonal grant framework, expanded hands-on support through Security Engineers in Residence, completed security enhancements for Rust and PyTorch ExecuTorch, and rolled out the AI-powered vulnerability scanner Scrutineer.

Cybersecurity Policy & Regulatory Updates 

Member Spotlights

CleanStart – Why Vulnerability Scanning Alone Is Not Enough

Standard scanning reveals exposure but fails to establish trust, flagging known defects only after an image is constructed. This approach overlooks provenance, build integrity, and runtime permissions, leaving root-access vulnerabilities unchecked even in “clean” images. OpenSSF General Member CleanStart cites the xz/liblzma backdoor as a definitive proof of this gap, where malicious code bypassed conventional scanners because no matching signatures existed yet. Read the full article.

Cloudsmith – Webinar: Inside the Open Source Malware Attack Landscape

Malicious activity is surfacing across fresh vectors, including VS Code extensions and GitHub repositories. Join Nigel Douglas from OpenSSF’s General Member Cloudsmith on August 13 at 4pm BST to dissect these emerging threats and explore strategies for defending against sophisticated adversaries. Register here.

Balena – CRA Research: Relevance to the Edge/IoT Community

As a key contributor to the 2026 CRA Awareness and Readiness Report, OpenSSF’s General Member Balena examines the specific implications of these regulatory findings for the IoT and edge ecosystems. Read their insight.

Meet OpenSSF at These Upcoming Events!

Ways to Participate:

There are a number of ways for individuals and organizations to participate in OpenSSF. Learn more here.

You’re invited to…

See You Next Month! 

We want to get you the information you most want to see in your inbox. Missed our previous newsletters? Read here!

Have ideas or suggestions for next month’s newsletter about the OpenSSF? Let us know at marketing@openssf.org, and see you next month! 

Regards,

The OpenSSF Team