Blog

OpenSSF Releases Top 10 Secure Software Development Guiding Principles

Today, we are excited to announce version 1.0 of the Secure Software Development Guiding Principles. These 10 principles describe a series of foundational practices that, if followed, can help provide better assurance and security for organizations leveraging them. Though aspirational, they provide a set of core practices that producers and suppliers of software can pledge…

Strengthening the Fort šŸ°: OpenSSF Releases Compiler Options Hardening Guide for C and C++

In the fast-changing landscape of cybersecurity, OpenSSF has taken a significant step towards enhancing the security of C and C++ software. This effort addresses a persistent class of software defects that have affected software, including open source software (OSS), since the dawn of the Internet. By releasing a comprehensive "Compiler Options Hardening Guide for C…

Sigstore: Simplifying Code Signing for Open Source Ecosystems

This month’s spotlight focuses on the Sigstore project. Digital signatures play a critical role in the software supply chain, by providing verifiable attributes of authentication, integrity, and non-repudiation of artifacts as they are distributed between consumers and producers. By ensuring that the origin of the software can be reliably traced back to its source, digital…

OpenSSF publishes Mission, Vision, Values, and Strategy

The open source software (OSS) community is ever-changing, and the security of OSS rapidly evolves in parallel. This requires OpenSSF to regularly re-evaluate our focus and approach to intentionally improve OSS security.Ā  Today the Open Source Security Foundation (OpenSSF) releases an updated Mission, Vision, Values and Strategy (MVS) for the foundation as approved by the…

Securing the Software Supply Chain Report Recommends SBOM Consumption Practices for Critical Infrastructure Providers

In an era where cyber threats continue to evolve, securing the software supply chain has become paramount for organizations globally. Recognizing the critical need for a robust framework, the US National Security Agency (NSA), Office of the Director of National Intelligence (ODNI), the Cybersecurity and Infrastructure Security Agency (CISA), and industry partners have collaborated to…

OpenSSF Supports oss-security and (linux-)distros Mailing Lists

As a part of the OpenSSF's mission to sustainably secure the development, maintenance and consumption of open source software, the OpenSSF earlier this year started to sponsor the operation of a critical piece of the community's infrastructure for communication.Ā  The oss-security and (linux)-distros mailing lists, which are operated by Openwall, have been a key part…