OpenSSF

Tech Talk Recap | CRA-Ready: How Open Source Projects Can Prepare for the EU Cyber Resilience Act

The EU Cyber Resilience Act (CRA) is reshaping the landscape for open source software. Whether you're a maintainer, contributor, or vendor, the CRA introduces new expectations—and new responsibilities. To help the community navigate these changes, the Open Source Security Foundation (OpenSSF) recently hosted a Tech Talk: CRA-Ready: How to Prepare Your Open Source Project for…

Case Study: OSTIF Improves Security Posture of Critical Open Source Projects Through OpenSSF Membership

Organization: Open Source Technology Improvement Fund, Inc. (OSTIF) Contributor: Amir Montazery, Managing Director Website: ostif.org Problem Critical open source software (OSS) projects—especially those that are long-standing and widely adopted—often lack...

Maintainers’ Guide: Securing CI/CD Pipelines After the tj-actions and reviewdog Supply Chain Attacks

CI/CD pipelines are increasingly becoming high-value targets for attackers. With access to secrets, source code, and infrastructure, they offer a direct route to supply chain compromise. The recent breaches involving tj-actions/changed-files and reviewdog/action-setup are not just isolated events, they are harbingers of a new generation of CI/CD-targeted supply chain attacks. 

From Sandbox to Incubating: gittuf’s Next Step in Open Source Security

We’re pleased to share that gittuf, a platform-agnostic Git security framework, has officially progressed to the Incubating Project stage under the Open Source Security Foundation (OpenSSF). This marks a major milestone in gittuf’s development and recognizes the project’s technical progress, community growth, and alignment with the broader mission of strengthening the open source software supply…

OSS and the CRA: am I a Manufacturer or a Steward?

The European Union’s Cyber Resilience Act (CRA) is a piece of legislation that covers all countries within the EU and the EEA and entered into force on 10th December 2024. It covers many types of devices and applications that are either sold or otherwise made commercially available on the European market and the intention behind…