Sign in

OpenSSF

@openssf.org
2.1K followers 1 following 376 posts

Open Source Security Foundation (OpenSSF) Together, we're securing the open source ecosystem openssf.org #OSSSecurity #OpenSSFCommunity

PostsRepliesMedia
OpenSSF @openssf.org · 10h
September Newsletter is here! 📰 September brings a commitment to sustainable package registries, practical CRA guidance, new community security work, and more. Catch up on the latest OpenSSF updates: openssf.org/newsletter/2026/09/30/o…
011
OpenSSF @openssf.org · 29/09/2026
Angie Jones, VP at the Agentic AI Foundation, joins What's in the SOSS talking about what it actually takes to run AI agents in production. 🎧 openssf.org/podcast/2026...
112
OpenSSF @openssf.org · 25/09/2026
Heading to #KubeCon + #CloudNativeCon + Open Source #SecurityCon? Let’s connect at ZarfFest! 🎉 Join OpenSSF and Defense Unicorns for an evening of drinks, light bites, and great conversations with fellow builders, maintainers, and open source friends. defenseunicorns.com/events/zarff...
defenseunicorns.com
ZarfFest: A Defense Unicorns x OpenSSF Happy Hour
ZarfFest: A KubeCon Happy Hour Presented by Defense Unicorns and OpenSSF Join Defense Unicorns and OpenSSF for ZarfFest, a happy hour bringing together the open source, cloud native, and software sec...
030
OpenSSF @openssf.org · 25/09/2026
Open source participation creates business and career value. Explore IBM’s journey with RedHat and #ProjectLightwell, plus Jamie Thomas’s insights in conversation with CRob. What’s your strategy to give back? openssf.org/blog/2026/09...
010
OpenSSF @openssf.org · 24/09/2026
Securing the open source supply chain is also about growing the community! 🌍✨ In this recap of the OpenSSF Summer Mentorship Lightning Showcase, discover how our talented mentees teamed up with seasoned mentors to tackle critical security challenges across projects. 🔗: openssf.org/blog/2026/09...
010
OpenSSF @openssf.org · 23/09/2026
Ready to level up your open source project’s security posture? 🛡️ OpenSSF & CNCF TAG Security launched Security Slam 2026 (Oct 5–Nov 6) for ALL OSS projects! Prepare for the EU CRA, access Slack advisors, and earn badges. Read the blog: openssf.org/blog/2026/09...
021
OpenSSF @openssf.org · 22/09/2026
AI speeds up development. Can your security keep pace? ActiveState CEO Abby Kearns joins What’s in the SOSS? to tackle AI velocity, CRA compliance and dependency debt. Know your dependencies. Hear her perspective. 🎧 Listen: openssf.org/podcast/2026...
000
OpenSSF @openssf.org · 16/09/2026
AI moves fast. Critical infrastructure needs support. The OpenSSF Governing Board backs sustainable funding for public package registries: stronger security, reliable services, and continued free access for developers. We’re in. Join us: openssf.org/blog/2026/09...
Graphic titled "We’re In: Enterprise Commitment to Sustainable Package Registries" featuring the OpenSSF (Open Source Security Foundation) logo on a dark background. A grid on the right displays logos for supporting organizations: Arm, Datadog, Dell Technologies, Ericsson, GitHub, Google, IBM, Kusari, Microsoft, Red Hat, Rust Foundation, and Sonatype.
0104
OpenSSF @openssf.org · 15/09/2026
🌱 September 11 has passed. What’s next for CRA compliance? Find your role and next steps with OpenSSF. Thanks to Roman Zhukov for inspiring our garden analogy and the Global Cyber Policy Working Group for helping it grow! Find your path: openssf.org/blog/2026/09...
A promotional graphic by OpenSSF titled "CRA Readiness for Open Source." Below the main heading, large text asks "What Is Your Role?" followed by "Find the CRA guidance and resources created for:". The graphic features a cartoon illustration of a community garden with three distinct areas labeled on wooden signs: "Open Source Maintainers," "Open Source Software Stewards" (depicted as a greenhouse), and "Product Manufacturers" (depicted as harvested crates). To the right, a cartoon goose mascot wearing a sun hat, blue shirt, and holding a watering can has a speech bubble asking, "Where do I fit? What do I need to do?" The bottom left includes a banner reading "Explore the Grow CRA Readiness Journey," and the bottom right features a headshot and author credit for "Sally Cooper, Senior Marketing and Communications Manager, The Linux Foundation."
000
OpenSSF @openssf.org · 14/09/2026
Mila from AWS breaks down how OS projects can maintain secure infrastructure without financial strain. Discover how Gradle and Compiler Explorer leverage the AWS Open Source Promotional Credit Program to harden the global software supply chain. Read: openssf.org/blog/2026/09...
011
OpenSSF @openssf.org · 11/09/2026
The September 11 CRA reporting milestone is here. Our new community guide explains manufacturers’ reporting obligations and how open source maintainers and stewards can prepare for collaboration when vulnerabilities affect downstream products. openssf.org/blog/2026/09...
A Community Guide to the EU CRA September 11 Deadline for Manufacturers
011
OpenSSF @openssf.org · 10/09/2026
Sept 11 is here. Are you ready? In our latest Tech Talk, experts walked us through practical steps for EU Cyber Resilience Act readiness, covering maintainer exemptions, manufacturer obligations, and new supply chain security baselines. Read the recap: openssf.org/blog/2026/09...
100
OpenSSF @openssf.org · 10/09/2026
AI changes the speed of vulnerability discovery, not the fundamentals of software security. Sal Kimmich and Simon John examine the UK GDS guidance, the case for “open by default,” and why durable enforcement must focus on real security practices. openssf.org/blog/2026/09...
Open by Default After AI: The GDS Guidance and the Enforcement Question

September 2026

By Sal Kimmich and Simon John
021
OpenSSF @openssf.org · 08/09/2026
AI is reshaping software engineering and security, but its impact cuts both ways. OpenSSF Board Chair Mark Russinovich, CTO, Deputy CISO and Technical Fellow at Microsoft Azure, joined us June 26 to discuss AI, supply chain security and vulnerability management. 🎧 openssf.org/podcast/2026...
010
OpenSSF @openssf.org · 04/09/2026
From our Happy Hour Reception at The Cosmopolitan to deep dives into software supply chain security, AI findings, and the hallway track, OpenSSF was proud to advance open source security at Hacker Summer Camp 2026! Read the full recap: openssf.org/blog/2026/09...
030
OpenSSF @openssf.org · 01/09/2026
The EU Cyber Resilience Act is reshaping responsibility across the software supply chain. In the latest What’s in the SOSS?, Madalin Neag breaks down what the CRA means for open source, software stewards, maintainers, and organizations preparing for compliance. openssf.org/podcast/2026...
001
OpenSSF @openssf.org · 31/08/2026
📰 The August Newsletter is here! It is packed with exciting updates within the OpenSSF community, including how Ericsson solved CRA obligations with over 1,400 upstream fixes, and key strategies for securing agentic AI ahead of AGNTCon NA. Read: openssf.org/newsletter/2...
012
OpenSSF @openssf.org · 31/08/2026
📰 The August Newsletter is here! It is packed with exciting updates within the OpenSSF community, including how Ericsson solved CRA obligations with over 1,400 upstream fixes, and key strategies for securing agentic AI ahead of AGNTCon NA. Read: openssf.org/newsletter/2...
010
OpenSSF @openssf.org · 28/08/2026
We are excited to announce that #BOMHort (formerly SeeBOM) has officially joined the OpenSSF family as a Sandbox Project!!! Read the full announcement on our blog to learn more about BOMHort: openssf.org/blog/2026/08... Get involved on this project: openssf.org/projects/bom...
051
OpenSSF @openssf.org · 28/08/2026
How did one team improve security across the entire open source ecosystem? Ericsson took on the EU Cyber Resilience Act (CRA) by eliminating private forks and going straight to the source. Read the full case study: openssf.org/blog/2026/08...
020
OpenSSF @openssf.org · 27/08/2026
We're heading to #AGNTCon + #MCPCon North America this October! 🚀 If you're working on agent infrastructure, tooling, or production AI systems, come see us at the OpenSSF booth to grab some swag and chat! 👋 Read more on our blog: openssf.org/blog/2026/08...
010
OpenSSF @openssf.org · 26/08/2026
How does a major telecom leader solve EU Cyber Resilience Act (CRA) compliance? By going 100% upstream. By eliminating custom patches and fixing vulnerabilities at the source, Ericsson lowered long-term lifecycle costs while strengthening the global supply chain. openssf.org/blog/2026/08...
000
OpenSSF @openssf.org · 25/08/2026
Hiding behind a private code fork to avoid EU CRA compliance is a $250,000 mistake per release. Check out the latest podcast with Dave Russo from Red Hat to learn more: openssf.org/podcast/2026...
032
OpenSSF @openssf.org · 18/08/2026
In Episode #69 of What’s in the SOSS?, we've invited Roman to break down what the CRA means for open source maintainers, stewards, and manufacturers. 🎧 Listen & learn how to prepare your team & bake "compliance as code" into your development lifecycle: openssf.org/podcast/2026...
011
OpenSSF @openssf.org · 14/08/2026
With CRA enforcement kicking off in Sept, manufacturers face new obligations to demonstrate security due diligence for the open source components they consume. Learn how the ORBIT Launchpad is helping organizations shift from reactive patching to proactive compliance. 📺 youtu.be/gAv60r9ZRVs?...
youtu.be
Global Cyber Policy Working Group OpenSSF Tech Talk ORBIT Launchpad
YouTube video by OpenSSF
032
OpenSSF @openssf.org · 11/08/2026
Join us for the upcoming OpenSSF Tech Talk to learn how industry leaders are navigating regulatory milestones and strengthening software supply chain security. 📅 August 20, 1 PM ET / 7 PM CET Read & register: openssf.org/blog/2026/08...
001
OpenSSF @openssf.org · 11/08/2026
This month, What’s in the SOSS? is going all in on CRA readiness, starting with Megan Knight, PMP, Chair of the OpenSSF Awareness SIG. Learn what you can do today, and why the open source community doesn’t have to figure this out alone. openssf.org/podcast/2026...
030
OpenSSF @openssf.org · 07/08/2026
Meet Katherine Druckman, one of our incredible ambassadors at OpenSSF! 🌟 As a longtime friend of the OpenSSF community, Katherine brings a deep understanding of open source and security to her ambassador mission. www.youtube.com/shorts/d6ih_...
youtube.com
Meet Katherine Druckman, one of our incredible ambassadors at OpenSSF!
YouTube video by OpenSSF
040
OpenSSF @openssf.org · 06/08/2026
OpenBao v2.6 is here! 🥟 This is our most collaborative release to date, featuring contributions from 42 first-time contributors, 27 individuals contributing multiple changes, and 8 users with double-digit change counts. Learn about this new release: openssf.org/blog/2026/08...
142
OpenSSF @openssf.org · 04/08/2026
Mila Zhou recently sat down with Yesenia Yser on the What's in the SOSS podcast to share her path from accounting to her role as a Senior Open Source & Security Program Manager at Amazon Web Services (AWS). openssf.org/podcast/2026...
011
OpenSSF @openssf.org · 30/07/2026
📰 The July 2026 OpenSSF Newsletter is out, featuring the newly published schedule for OpenSSF Community Day Europe in Prague! Check out the full issue to catch up on the latest project releases and regulatory updates across the community: openssf.org/newsletter/2...
010
OpenSSF @openssf.org · 29/07/2026
The schedule for #OpenSSFCommunity Day Europe 2026 (Oct 6 in Prague) just dropped! Get a sneak peek at the single-day event co-located with #OSSummit Europe. Learn what sessions are happening, who's speaking, and why you should attend. Read: openssf.org/blog/2026/07...
042
OpenSSF @openssf.org · 28/07/2026
What is a Dependency Firewall? 🧱 A dependency firewall is an install-time security checkpoint that evaluates open source software packages before they execute. Read the analysis from OpenSSF's member Aikido Security: openssf.org/blog/2026/07/28/what-is…
000
OpenSSF @openssf.org · 28/07/2026
New What's in the SOSS? 🎧 CRob talks with Michael Winser, co-founder of Alpha-Omega on turning AI into the maintainer's power tool: AI assists on maintainers' terms, not more vulnerability slop. openssf.org/podcast/2026...
000
OpenSSF @openssf.org · 23/07/2026
The CRA is shifting legal responsibility for software security back to manufacturers. With mandatory vulnerability reporting starting September 2026. Get ahead of compliance with the free eBook, "Built to Last" by Sal Kimmich (OpenUK). openssf.org/resources/bu...
Understanding the CRA
021
OpenSSF @openssf.org · 22/07/2026
What happens at OpenSSF Community Day? Hannah shares her key takeaways from her first time attending Community Day in Minneapolis. #OpenSSFCommunity Day Europe is coming this fall, read the blog and see why Hannah enjoyed her first Community Day: openssf.org/blog/2026/07...
022
OpenSSF @openssf.org · 21/07/2026
Open source adoption across Africa is growing at an incredible rate. OpenSSF ambassador Ejiro Oghenekome shares key takeaways from representing OpenSSF and the BEAR Working Group at #AfricaCyberFest. Read the blog: openssf.org/blog/2026/07...
010
OpenSSF @openssf.org · 16/07/2026
Whether you're a Developer, Security Engineer, OSPO, Executive, Marketing or Community leader, there's an OpenSSF journey designed for you. Explore practical resources, discover what's next, and find the guidance that fits your role. 🌊 Ready to dive in? 🔗 openssf.org/blog/2026/07...
Getting Started with OpenSSF
000
OpenSSF @openssf.org · 14/07/2026
In the latest episode of What's in the SOSS?, Yesenia Yser talks with Mihai (MM) Maruseac, lead of the OpenSSF AI/ML Security Working Group and Security & Privacy expert at OpenAI, about securing AI models with the OpenSSF Model Signing (OMS) specification. openssf.org/podcast/2026...
010
OpenSSF @openssf.org · 30/06/2026
What happens when your weekend project becomes global infrastructure? On the latest "What’s in the SOSS?" podcast, Linux kernel icon Greg Kroah-Hartman talks kernel security, the EU CRA, and why your team needs to update today. 🎧 openssf.org/podcast/2026...
040
OpenSSF @openssf.org · 25/06/2026
Despite widespread education campaigns over the last year, macro-level unfamiliarity with the EU CRA has actually widened to 66% globally. Read the new blog by Angelah Liu to see what changed (and what didn't) across 2 years of data. openssf.org/blog/2026/06...
010
OpenSSF @openssf.org · 24/06/2026
The June 2026 OpenSSF Newsletter is here! The open source security landscape is moving faster than ever, and this month’s edition covers the critical shifts you need to know about. Read the full newsletter: openssf.org/newsletter/2...
010
OpenSSF @openssf.org · 23/06/2026
For too long, security academia and open source maintainers have lived on different planets. SCORED '26 is bringing academics and open source practitioners into the same room to tackle security challenges. Read the blog from Justin Cappos to learn more: openssf.org/blog/2026/06...
030
OpenSSF @openssf.org · 23/06/2026
Sponsorship is open for OpenSSF Community Day Europe 2026 — October 6, Prague. Keynote slots, exhibit space, social and email recognition, post-event data report. Platinum/Gold/Silver. Deadline Sept 4: openssfevents@linuxfoundation.org events.linuxfoundation.org/openssf-comm...
010
OpenSSF @openssf.org · 16/06/2026
The most underestimated career accelerator in technology may be open source. The skill that carries you furthest is not always the code. It is the art of influence. Listen to "Big Thoughts, Open Sources", where host CRob talks with Jamie Thomas from IBM. openssf.org/podcast/2026...
000
OpenSSF @openssf.org · 10/06/2026
How did the "Mini Shai-Hulud" attack compromise 170+ packages while maintaining valid SLSA Build L3 attestations? Read the full blog to see where SLSA’s boundaries fall and how to secure your pipeline with defense in depth. 🔗: openssf.org/blog/2026/06...
011
OpenSSF @openssf.org · 09/06/2026
The 2026 CRA Awareness & Readiness Report by The Linux Foundation Research and OpenSSF is officially out, and the data reveals a sobering reality for the global software ecosystem as the European CRA deadlines approach. Download the report: openssf.org/resources/pu...
011
OpenSSF @openssf.org · 05/06/2026
How do we move from isolated security patches to a systemic, resilient software supply chain? Read the #OpenSSFCommunity Day NA recap and see how the community has been unifying tools, navigating AI, and securing the OSS. openssf.org/blog/2026/06...
030
OpenSSF @openssf.org · 02/06/2026
Abandoned projects introduce hidden risks into your software supply chain. On the latest episode of the What’s in the SOSS? podcast, host CRob sits down with Isaac Wuest from HeroDevs to examine End-of-Life (EOL) open source software. openssf.org/podcast/2026...
000
OpenSSF @openssf.org · 29/05/2026
Learn why machine-readable security signals provide the practical foundation for automated due diligence. These signals function as voluntary mechanisms for upstream transparency, not formal assurances or a transfer of legal liability. Link in the comments.
100