Mila Zhou recently sat down with Yesenia Yser on the What's in the SOSS podcast to share her path from accounting to her role as a Senior Open Source & Security Program Manager at Amazon Web Services (AWS). openssf.org/podcast/2026...
OpenSSF
@openssf.org
Open Source Security Foundation (OpenSSF) Together, we're securing the open source ecosystem http://openssf.org #OSSSecurity #OpenSSFCommunity
📰 The July 2026 OpenSSF Newsletter is out, featuring the newly published schedule for OpenSSF Community Day Europe in Prague! Check out the full issue to catch up on the latest project releases and regulatory updates across the community: openssf.org/newsletter/2...
The schedule for #OpenSSFCommunity Day Europe 2026 (Oct 6 in Prague) just dropped! Get a sneak peek at the single-day event co-located with #OSSummit Europe. Learn what sessions are happening, who's speaking, and why you should attend. Read: openssf.org/blog/2026/07...
What is a Dependency Firewall? 🧱 A dependency firewall is an install-time security checkpoint that evaluates open source software packages before they execute. Read the analysis from OpenSSF's member Aikido Security: https://openssf.org/blog/2026/07/28/what-is-a-dependency-firewall/
New What's in the SOSS? 🎧 CRob talks with Michael Winser, co-founder of Alpha-Omega on turning AI into the maintainer's power tool: AI assists on maintainers' terms, not more vulnerability slop. openssf.org/podcast/2026...
The CRA is shifting legal responsibility for software security back to manufacturers. With mandatory vulnerability reporting starting September 2026. Get ahead of compliance with the free eBook, "Built to Last" by Sal Kimmich (OpenUK). openssf.org/resources/bu...
What happens at OpenSSF Community Day? Hannah shares her key takeaways from her first time attending Community Day in Minneapolis. #OpenSSFCommunity Day Europe is coming this fall, read the blog and see why Hannah enjoyed her first Community Day: openssf.org/blog/2026/07...
Open source adoption across Africa is growing at an incredible rate. OpenSSF ambassador Ejiro Oghenekome shares key takeaways from representing OpenSSF and the BEAR Working Group at #AfricaCyberFest. Read the blog: openssf.org/blog/2026/07...
Whether you're a Developer, Security Engineer, OSPO, Executive, Marketing or Community leader, there's an OpenSSF journey designed for you. Explore practical resources, discover what's next, and find the guidance that fits your role. 🌊 Ready to dive in? 🔗 openssf.org/blog/2026/07...
In the latest episode of What's in the SOSS?, Yesenia Yser talks with Mihai (MM) Maruseac, lead of the OpenSSF AI/ML Security Working Group and Security & Privacy expert at OpenAI, about securing AI models with the OpenSSF Model Signing (OMS) specification. openssf.org/podcast/2026...
What happens when your weekend project becomes global infrastructure? On the latest "What’s in the SOSS?" podcast, Linux kernel icon Greg Kroah-Hartman talks kernel security, the EU CRA, and why your team needs to update today. 🎧 openssf.org/podcast/2026...
Despite widespread education campaigns over the last year, macro-level unfamiliarity with the EU CRA has actually widened to 66% globally. Read the new blog by Angelah Liu to see what changed (and what didn't) across 2 years of data. openssf.org/blog/2026/06...
The June 2026 OpenSSF Newsletter is here! The open source security landscape is moving faster than ever, and this month’s edition covers the critical shifts you need to know about. Read the full newsletter: openssf.org/newsletter/2...
For too long, security academia and open source maintainers have lived on different planets. SCORED '26 is bringing academics and open source practitioners into the same room to tackle security challenges. Read the blog from Justin Cappos to learn more: openssf.org/blog/2026/06...
Sponsorship is open for OpenSSF Community Day Europe 2026 — October 6, Prague. Keynote slots, exhibit space, social and email recognition, post-event data report. Platinum/Gold/Silver. Deadline Sept 4: openssfevents@linuxfoundation.org events.linuxfoundation.org/openssf-comm...
The most underestimated career accelerator in technology may be open source. The skill that carries you furthest is not always the code. It is the art of influence. Listen to "Big Thoughts, Open Sources", where host CRob talks with Jamie Thomas from IBM. openssf.org/podcast/2026...
How did the "Mini Shai-Hulud" attack compromise 170+ packages while maintaining valid SLSA Build L3 attestations? Read the full blog to see where SLSA’s boundaries fall and how to secure your pipeline with defense in depth. 🔗: openssf.org/blog/2026/06...
The 2026 CRA Awareness & Readiness Report by The Linux Foundation Research and OpenSSF is officially out, and the data reveals a sobering reality for the global software ecosystem as the European CRA deadlines approach. Download the report: openssf.org/resources/pu...
How do we move from isolated security patches to a systemic, resilient software supply chain? Read the #OpenSSFCommunity Day NA recap and see how the community has been unifying tools, navigating AI, and securing the OSS. openssf.org/blog/2026/06...
Abandoned projects introduce hidden risks into your software supply chain. On the latest episode of the What’s in the SOSS? podcast, host CRob sits down with Isaac Wuest from HeroDevs to examine End-of-Life (EOL) open source software. openssf.org/podcast/2026...
Learn why machine-readable security signals provide the practical foundation for automated due diligence. These signals function as voluntary mechanisms for upstream transparency, not formal assurances or a transfer of legal liability. Link in the comments.
Meet Christopher "CRob" Robinson, Chief Security Architect at OpenSSF, speaking at the Open Source Policy Ecosystem Forum on June 8 in Brussels. He will explore "Open Technology Cybersecurity as a Global Collaboration Challenge." Secure your spot: https://bit.ly/4uAwAuj
Live from #OpenSSFCommunity Day North America! 🎉 We're celebrating an incredible quarter of growth and officially welcoming our newest members to the Foundation: ActiveState, Aikido Security, Minimus, TuxCare, and the FreeBSD Foundation! openssf.org/press-releas...
We've seen a concerning rise in targeted attacks on upstream registries like npm and PyPI through malicious packages. But how do you actually defend against them day-to-day? Learn how to strengthen your supply chain security: openssf.org/blog/2026/05...
AI is flooding open source projects with vulnerability reports faster than maintainers can handle. @OpenSSF and @CNCF just dropped the free playbook. "This is math, not magic. And with the right practices, it is manageable." Download your copy: openssf.org/resources/se...
From UI/UX to OpenSSF Contributor: Ejiro Oghenekome on What’s in the SOSS? Ejiro shares insights from her "100 Days of Cybersecurity" challenge and her leadership in authoring the "Beginner to Builder" series. openssf.org/podcast/2026...
Is your organization ready for the European Cyber Resilience Act (CRA)? New EU rules mandate "security by design" for digital products. The second Linux Foundation Research survey launches this June, learn why the ecosystem is falling behind. openssf.org/blog/2026/05...
The OpenSSF released the Secure Coding Guide for #Python (PySCG). This practical resource offers 50+ rules and code examples to help developers mitigate vulnerabilities in open source software. 🐍 Read the blog: openssf.org/blog/2026/05... Access the guide: best.openssf.org/Secure-Codin...
The AI Cyber Challenge (AIxCC) results are in and the work continues through new #OpenSSF projects like OSS-CRS and FuzzingBrain. Read the blog by Helen Woeste (OSTIF): openssf.org/blog/2026/05...
The CPS project has just officially secured the #OpenSSF Gold Badge. CPS is the first project within the LFN community to hit this milestone. This badge proves that security and quality are baked into the DNA of the project. Read the full story: openssf.org/blog/2026/05...