Blog

“What’s in the SOSS?” Podcast is Now Live

In our first podcast – Vincent Danen and the Art of Vulnerability Management, Omkhar Arasaratnam, General Manager of OpenSSF, talks to Vincent Danen, Vice President of Product Security at Red Hat, who is responsible for security and compliance activities across Red Hat's products and services. He’s also on the Governing Board of the OpenSSF. Vincent has…

Join us for a TTX: Securing OSS & Empowering Maintainers

At SOSS Community Day NA on April 15, 2024 the OpenSSF Community will conduct a Tabletop Exercise (TTX). Periodically walking through various scenarios of a supply chain attack in a time of calm helps identify action items that are important to prepare in advance for when real attacks occur. A TTX is an important planning…

xz Backdoor CVE-2024-3094

CVE-2024-3094 documents a backdoor in the xz package. While the motivation behind this backdoor remains unknown, the intent was to compromise specific distributions, as the backdoors were only applied to DEB or RPM packages for the x86-64 architecture built with gcc and the gnu linker. Situations like this remind us all that we need to…

VulnCon 2024 Wrap-up: Securing the Ecosystem through Global Cooperation

The OpenSSF was pleased to be one of the sponsors that helped contribute to the inaugural 2024 VulnCon conference that brought together experts from across industry, government, security researchers, and community members throughout 3 days and nearly 40 sessions.  Brought together by the FIRST PSIRT SIG and the CVE Board. Christopher “CRob” Robinson, OpenSSF TAC Chair…

OpenSSF Scorecard Tech Talk Highlights

Last week the community convened for the first OpenSSF Tech Talk of the year, shining a spotlight on OpenSSF Scorecard. OpenSSF Scorecard aids developers and open source consumers in assessing how well an open source project adheres to best practices. It evaluates projects for security risks using a series of automated checks. The Tech Talk…