Guest Blog

How I Got Involved with the OpenSSF

Let’s get it out of the way early: it’s not always clear how you can best plug into organizations like OpenSSF. That’s why I’m writing this guest blog post as an ā€œoutsider.ā€ I’m just your average tech employee who has become progressively more involved since my company, Sonatype, became members of OpenSSF. If you’re connecting…

SBOMs, So Far, So Good, So What?

We’ve been discussing the creation of SBOMs for over ten years, but has it gotten us any closer to hardening our software development practices? SBOMs provide critical supply chain data, but we are simply not using the data to drive our supply chain decisions. Requiring SBOM generation alone is not the answer. What is the…

The Role of Foundations in Securing OSS

Security used to be something of an afterthought in software development. Security was clunky or inconvenient, often because it was a ā€˜bolt-on’. That has rapidly changed over the last two years. Now, the world has finally realised that security needs to be ā€˜baked-in’, not ā€˜bolted-on’.Ā Meaningful and impactful improvements can be achieved in OSS security engineering…

Improving Supply Chain Security: IBM as a user and a contributor to Open Source Security Foundation Scorecard

Scorecard is becoming a key part of IBM’s review and curation of the open-source software in our products and services. IBM is committed to helping address the systemic security issues in modern SW supply chains and believes an important part of this effort is to help the open-source ecosystem improve the overall security of OS…

New SLSA++ Survey Reveals Real-World Developer Approaches to Software Supply Chain Security

Answering even basic questions about software supply chain security has been surprisingly hard. For instance, how widespread are the different practices associated with software supply chain security? And do software professionals view these practices as useful or not? Easy or hard? To help answer these and related questions, Chainguard, the Eclipse Foundation, the Rust Foundation,…

How to Make High-Quality SBOMs

The widespread use of software bill of materials (SBOMs) arguably depends on SBOM quality—that SBOMs contain sufficient and accurate information for the intended user to achieve their goals. But, until recently, it has been difficult to measure SBOM quality. New SBOM quality tools, a new SBOM dataset, and new SBOM quality research changes this state…