OpenSSF

@openssf.org

Open Source Security Foundation (OpenSSF) Together, we're securing the open source ecosystem http://openssf.org #OSSSecurity #OpenSSFCommunity

📰 The July 2026 OpenSSF Newsletter is out, featuring the newly published schedule for OpenSSF Community Day Europe in Prague! Check out the full issue to catch up on the latest project releases and regulatory updates across the community: openssf.org/newsletter/2...

Bild

The CRA is shifting legal responsibility for software security back to manufacturers. With mandatory vulnerability reporting starting September 2026. Get ahead of compliance with the free eBook, "Built to Last" by Sal Kimmich (OpenUK). openssf.org/resources/bu...

Understanding the CRA

Whether you're a Developer, Security Engineer, OSPO, Executive, Marketing or Community leader, there's an OpenSSF journey designed for you. Explore practical resources, discover what's next, and find the guidance that fits your role. 🌊 Ready to dive in? 🔗 openssf.org/blog/2026/07...

Getting Started with OpenSSF

In the latest episode of What's in the SOSS?, Yesenia Yser talks with Mihai (MM) Maruseac, lead of the OpenSSF AI/ML Security Working Group and Security & Privacy expert at OpenAI, about securing AI models with the OpenSSF Model Signing (OMS) specification. openssf.org/podcast/2026...

What happens when your weekend project becomes global infrastructure? On the latest "What’s in the SOSS?" podcast, Linux kernel icon Greg Kroah-Hartman talks kernel security, the EU CRA, and why your team needs to update today. 🎧 openssf.org/podcast/2026...

Despite widespread education campaigns over the last year, macro-level unfamiliarity with the EU CRA has actually widened to 66% globally. Read the new blog by Angelah Liu to see what changed (and what didn't) across 2 years of data. openssf.org/blog/2026/06...

Bild

For too long, security academia and open source maintainers have lived on different planets. SCORED '26 is bringing academics and open source practitioners into the same room to tackle security challenges. Read the blog from Justin Cappos to learn more: openssf.org/blog/2026/06...

Bild

The most underestimated career accelerator in technology may be open source. The skill that carries you furthest is not always the code. It is the art of influence. Listen to "Big Thoughts, Open Sources", where host CRob talks with Jamie Thomas from IBM. openssf.org/podcast/2026...

How did the "Mini Shai-Hulud" attack compromise 170+ packages while maintaining valid SLSA Build L3 attestations? Read the full blog to see where SLSA’s boundaries fall and how to secure your pipeline with defense in depth. 🔗: openssf.org/blog/2026/06...

Bild

The 2026 CRA Awareness & Readiness Report by The Linux Foundation Research and OpenSSF is officially out, and the data reveals a sobering reality for the global software ecosystem as the European CRA deadlines approach. Download the report: openssf.org/resources/pu...

Bild

Abandoned projects introduce hidden risks into your software supply chain. On the latest episode of the What’s in the SOSS? podcast, host CRob sits down with Isaac Wuest from HeroDevs to examine End-of-Life (EOL) open source software. openssf.org/podcast/2026...

Learn why machine-readable security signals provide the practical foundation for automated due diligence. These signals function as voluntary mechanisms for upstream transparency, not formal assurances or a transfer of legal liability. Link in the comments.

Bild

We've seen a concerning rise in targeted attacks on upstream registries like npm and PyPI through malicious packages. But how do you actually defend against them day-to-day? Learn how to strengthen your supply chain security: openssf.org/blog/2026/05...

Bild

AI is flooding open source projects with vulnerability reports faster than maintainers can handle. @OpenSSF and @CNCF just dropped the free playbook. "This is math, not magic. And with the right practices, it is manageable." Download your copy: openssf.org/resources/se...

Bild

Is your organization ready for the European Cyber Resilience Act (CRA)? New EU rules mandate "security by design" for digital products. The second Linux Foundation Research survey launches this June, learn why the ecosystem is falling behind. openssf.org/blog/2026/05...

Bild