Skip to main content
Stacklok Case Study

Jun 4, 2024 | OpenSSF

OpenSSF Case Study: Enhancing Open Source Security with Sigstore at Stacklok

Stacklok was founded in 2023 by Craig McLuckie (co-creator of Kubernetes) and Luke Hinds (creator of the OpenSSF project Sigstore), with the goal of helping developers produce and consume open source software more safely. Read more.
TIFunding

Jun 3, 2024 | OpenSSF

In Blog

Final Call: Submit your Technical Initiatives (TI) Funding Request by June 7th, 2024

We are excited to announce that another round of Technical Initiative (TI) funding is coming to a close with the mid-June window mentioned in the blog: How OpenSSF Technical Initiatives Can Receive Strategic Funding. Read more.
SecurityAdventure

May 31, 2024 | OpenSSF

In Blog

The OSS Security Adventure: Exploring the Frontlines of OSS Security through SOSS Policy Summit, RSA Conference, and Japan Meetup

OpenSSF is making waves globally, with our footprint evident in discussions and events across continents. Join us on an "OSS Security Adventure" as we delve into our impactful presence at the SOSS Policy Summit in Brussels, the RSA Conference in San Francisco, and our engaging meetup in Tokyo. Read more.

May 30, 2024 | OpenSSF

In Blog

Beyond the OpenSSF: An Introduction to Other Security Efforts Across the Linux Foundation

The Open Source Security Foundation (OpenSSF)’s mission is to strengthen the open source software ecosystem through a collaborative initiative across industry. But did you know about the other initiatives focusing on strengthening open source security, happening across the Linux Foundation? In fact, one of the top priorities at the Linux… Read more.

May 29, 2024 | OpenSSF

In Blog

The Opportunity for DEI Participation in the Security Industry (And OpenSSF)

At Secure Open Source Software (SOSS) Community Day North America 2024, we held a panel discussion on DEI (Diversity, Equity and Inclusion) at Open Source Security Foundation (OpenSSF). In preparing for this discussion we had a lot of conversations and realized we each had diverse perspectives on what the needs… Read more.
Introducing_Artifact_Attestations

May 24, 2024 | OpenSSF

Introducing Artifact Attestations—Now in Public Beta

There’s an increasing need across enterprises and the open source ecosystem to have a verifiable way to link software artifacts back to their source code and build instructions. And with more than 100 million developers building on GitHub, we want to ensure that developers have the tools needed to help… Read more.
Joins_OpenSource_Consortium_To_Define_EU_CRA_Security_Specifications

May 22, 2024 | OpenSSF

In Blog

OpenSSF Joins Open Source Consortium To Define E.U. CRA Security Specifications

The Open Source Security Foundation (OpenSSF), a project of the Linux Foundation focused on improving the security of open source software, is proud to announce its collaboration with the Eclipse Foundation and a leading open source consortium to work on the European Union’s (E.U.) Cyber Resilience Act (CRA). This alliance… Read more.

May 20, 2024 | OpenSSF

Enhancing Open Source Security: Introducing Siren by OpenSSF

By Christopher “CRob” Robinson, Director of Security Communications, Intel Product Assurance and Security, Intel Corporation; and Bennett Pursell, Ecosystem Strategist, OpenSSF In the ever-evolving landscape of cybersecurity threats, collaboration and information sharing are paramount. Now, more than ever, the open source community needs a centralized platform to exchange threat intelligence… Read more.

May 17, 2024 | OpenSSF

Where Does Your Software (Really) Come From?

Software is a funny, profound thing: Each piece of it is an invisible machine, seemingly made of magic words, designed to run on the ultimate, universal machine. It’s not alive, but it has a lifecycle. It starts out as source code—just text files sitting in a repository somewhere—and then later… Read more.

May 16, 2024 | OpenSSF

In Blog

Join Our Upcoming OpenSSF Tech Talk: Proactive Supply Chain Security with GUAC

Join our upcoming Tech Talk, "Proactive Supply Chain Security with GUAC," on June 6, 2024, at 10 AM PT/1 PM ET, as we discuss proactive vulnerability management and software supply chain security. Read more.