Open Source Security Foundation – Linux Foundation Projects [Un…

🌉 bridged from 🌐 https://openssf.org/: https://fed.brid.gy/web/openssf.org

4 followers0 following50 stories

Longform Stories

The “Skyway” to OSS Security: OpenSSF Community Day North America 2026 Recap

1d ago·1 min read·70 words

Updates from Europe: Single Reporting Platform, Public Consultations, New Publications

3d ago·1 min read·40 words

What’s in the SOSS? Podcast #62 – S3E14 The Ghost in the Dependency Tree: Navigating Open Source End-of-Life with HeroDevs

4d ago·24 min read·4761 words

Aligning on Machine-Readable Signals as the Foundation for Due Diligence

May 29·1 min read·40 words

OpenSSF Newsletter – May 2026

May 28·1 min read·37 words

OpenSSF Notes Quarter of Growth with New Members, Added AI Security Resources, and Growing Community

May 21·7 min read·1211 words

Introducing the First Cohort of the OpenSSF Ambassador Program

May 21·7 min read·1361 words

Detecting Malicious Packages using the OSV API

May 20·7 min read·1333 words

What’s in the SOSS? Podcast #61 – S3E13 Beginner to Builder: Shaping the Conversation in Open Source Security

May 19·24 min read·4694 words

Taking Stock of the State of European Cyber Resilience Act (CRA) Compliance: An Urgent Wake-up Call for the Open Source Ecosystem

May 18·8 min read·1404 words

Secure Coding Guide for Python (pyscg) First Release

May 12·1 min read·8 words

Hack to the Future: The Impact and Legacy of the DARPA AIxCC Challenge

May 12·1 min read·13 words

The Road to Gold: How CPS Set a New Standard for Security and Quality in Open Source

May 7·1 min read·17 words

Open Infrastructure Is Not Free, Part II: The Hidden Cost of Running Package Registries

May 6·1 min read·14 words

What’s in the SOSS? Podcast #60 – S3E12 Packaging, Transferring, and Deploying Software in Air-Gapped Environments with Zarf

May 5·1 min read·18 words

OpenSSF Newsletter – April 2026

Apr 21·1 min read·5 words

What’s in the SOSS? Podcast #59 – S3E11 Building a Connected Africa: The Origin Story of OSSAfrica with Prince Asiedu

Apr 21·1 min read·20 words

Secure Your Spot: The OpenSSF Community Day North America 2026 Agenda is Live!

Apr 20·1 min read·13 words

Why Third-Party Notices Are Breaking at Scale: What the Ecosystem Needs Next

Apr 17·1 min read·12 words

From Noise to Signal: Using Runtime Context to Win the Vulnerability Management Battle

Apr 15·1 min read·13 words

Security Slam 2026: Celebrating Our Security Champions and Project Milestones

Apr 10·1 min read·10 words

OpenSSF Tech Talk Recap: Securing Agentic AI

Apr 8·1 min read·7 words

What’s in the SOSS? Podcast #58 – S3E10 Big Thoughts, Open Sources: Beyond the Hype: Brian Fox on Securing the Agentic Future of Open Source

Apr 6·1 min read·25 words

Rethinking Post-Deployment Vulnerability Detection

Apr 3·1 min read·4 words

From AIxCC to OpenSSF: Welcoming OSS-CRS to Advance AI Driven Open Source Security

Apr 2·1 min read·13 words

OpenSSF Newsletter – March 2026

Mar 26·1 min read·5 words

What’s in the SOSS? Podcast #57 – S3E9 From Noise to Signal: Security Expertise and Kusari Inspector with Mike Lieberman

Mar 24·1 min read·20 words

Introducing the OpenSSF Ambassador Program

Mar 23·1 min read·5 words

Kusari Partners with OpenSSF to Strengthen Open Source Software Supply Chain Security

Mar 23·1 min read·12 words

OpenSSF Celebrates New Members, No-Cost Tooling, and Project Milestones

Mar 23·1 min read·9 words

Leading Tech Coalition Invests $12.5 Million Through OpenSSF and Alpha-Omega to Strengthen Open Source Security

Mar 17·1 min read·15 words

What’s in the SOSS? Podcast #56 – S3E8 Empowering New Maintainers: Inside the OpenSSF Mentorship Program

Mar 17·1 min read·16 words

Linux Foundation Announces $12.5 Million in Grant Funding from Leading Organizations to Advance Open Source Security

Mar 17·1 min read·16 words

KubeCon + CloudNativeCon Europe 2026 Co-located Event Deep Dive: Open Source SecurityCon

Mar 16·1 min read·12 words

Securing Agentic AI in Practice: From OpenSSF Guidance to Real-World Implementation

Mar 13·1 min read·11 words

First Steps Towards Cyber Resilience Act Conformity: Biking the CRA with Balena at FOSDEM 2026

Mar 11·1 min read·15 words

What’s in the SOSS? Podcast #55 – S3E7 The Gemara Project: GRC Engineering Model for Automated Risk Assessment

Mar 10·1 min read·18 words

Introducing the Gemara Model

Mar 9·1 min read·4 words

Your Voice Belongs Here: How to Get Involved in the OpenSSF Community

Mar 5·1 min read·12 words

Case Study: Defending the Open Source Supply Chain in a New Regulatory Era

Mar 2·1 min read·13 words

OpenSSF Newsletter – February 2026

Feb 26·1 min read·5 words

Getting an OpenSSF Baseline Badge with the Best Practices Badge System

Feb 25·1 min read·11 words

Advancing Package Repository Security Through Collaboration

Feb 19·1 min read·6 words

EU Cyber Resilience Act (CRA) in Practice @ FOSDEM 2026: From Awareness to Action

Feb 17·1 min read·14 words

Fill Out All The Margins 📖: OpenSSF Releases Compiler Annotations Guide for C and C++

Feb 12·1 min read·15 words

Have a Security Lesson Worth Sharing? Submit a Talk at OpenSSF Community Day North America

Feb 10·1 min read·15 words

What’s in the SOSS? Podcast #54 – S3E6 AIxCC Part 4 – Cyber Reasoning Systems: The Real-World Journey After AIxCC

Feb 9·1 min read·20 words

What’s in the SOSS? Podcast #53 – S3E5 AIxCC Part 3 – Buttercup’s Hybrid Approach: Trail of Bits’ Journey to Second Place in AIxCC

Feb 9·1 min read·24 words

What’s in the SOSS? Podcast #52 – S3E4 AIxCC Part 2 – From Skeptics to Believers: How Team Atlanta Won AIxCC by Combining Traditional Security with LLMs

Feb 9·1 min read·27 words

What’s in the SOSS? Podcast #51 – S3E3 AIxCC Part 1 – From Skepticism to Success: The AI Cyber Challenge (AIxCC) with Andrew Carney

Feb 9·1 min read·24 words