π The 2025 OpenSSF Annual Report has officially arrived!!!
We invite you to celebrate another year of progress, creativity, and collaboration shaping a safer, more resilient open source community.
Download the report: https://t.co/mUa1KqoPxw
#AnnualReport#OSSSecurity
Abandoned projects introduce hidden risks into your software supply chain.
On the latest episode of the Whatβs in the SOSS? podcast, host CRob sits down with Isaac Wuest from HeroDevs to examine End-of-Life (EOL) open source software.
https://t.co/JVAsPPlv4x
Learn why machine-readable security signals provide the practical foundation for automated due diligence. These signals function as voluntary mechanisms for upstream transparency, not formal assurances or a transfer of legal liability.
Link in the comments.
π Software risk is becoming a board-level issue.
Mike Vizard talks with Christopher Robinson of OpenSSF about the EU Cyber Resilience Act, vulnerability reporting, software dependencies and using business-focused risk language.
Watch: https://t.co/bHPijhEPmd
Live from #OpenSSFCommunity Day North America! π We're celebrating an incredible quarter of growth and officially welcoming our newest members to the Foundation: ActiveState, Aikido Security, Minimus, TuxCare, and the FreeBSD Foundation!
https://t.co/pqukYY2ayS
We've seen a concerning rise in targeted attacks on upstream registries like npm and PyPI through malicious packages. But how do you actually defend against them day-to-day?
Learn how to strengthen your supply chain security: https://t.co/QgAgPyzk6v
AI is flooding open source projects with vulnerability reports faster than maintainers can handle. @OpenSSF and @CNCF just dropped the free playbook.
"This is math, not magic. And with the right practices, it is manageable."
Download your copy: https://t.co/rkWNyHTnqm
From UI/UX to OpenSSF Contributor: Ejiro Oghenekome on Whatβs in the SOSS?
Ejiro shares insights from her "100 Days of Cybersecurity" challenge and her leadership in authoring the "Beginner to Builder" series.
https://t.co/tkKyEFDzkI
Is your organization ready for the European Cyber Resilience Act (CRA)? New EU rules mandate "security by design" for digital products.
The second Linux Foundation Research survey launches this June, learn why the ecosystem is falling behind.
https://t.co/RpBQumouLK
The OpenSSF released the Secure Coding Guide for #Python (PySCG). This practical resource offers 50+ rules and code examples to help developers mitigate vulnerabilities in open source software. π
Read the blog: https://t.co/HI8ZZ9QJwK
Access the guide: https://t.co/GbzPFglHxL
The AI Cyber Challenge (AIxCC) results are in and the work continues through new #OpenSSF projects like OSS-CRS and FuzzingBrain.
Read the blog by Helen Woeste (OSTIF):
https://t.co/WBx8MUVLNR
The CPS project has just officially secured the #OpenSSF Gold Badge.
CPS is the first project within the LFN community to hit this milestone. This badge proves that security and quality are baked into the DNA of the project.
Read the full story: https://t.co/GhecMwKshJ
Open Infrastructure Is Not Free Part II
10 trillion open source package downloads in 2026. Still running on donations and volunteers.
AI is accelerating attacks. The Sustaining Package Registries WG is here to help.
https://t.co/wcm4zEcBAh
#PreserveOpenSource
In the latest What's in the SOSS?, Sally Cooper sits down with Brandt Keller from Defense Unicorns to talk about Zarf, @CloudNativeFdn-ecosystem #OpenSSF Sandbox Project built to package, transfer, and deploy software in air-gapped environments.
https://t.co/yNZV998xpx
Join us for #OpenSSFCommunity Day North America on May 21! π
We are grateful for the support of @HondaJP, our Gold Sponsor, in our mission to secure the open source software ecosystem.
Register & join the conversation on software supply chain security: https://t.co/0fjOKhQ9lP
The April OpenSSF Newsletter is here! π°
Big things are happening in the world of open source security. Topping the list: #OpenSSFCommunity Day North America is happening May 21st in Minneapolis!
Read the Newsletter: https://t.co/CEwKi9f9Su
The #OpenSSFCommunity Day agenda is live! Mark your calendar for May 21 in Minneapolis and start planning your schedule by bookmarking your favorite sessions.
Read the agenda highlight: https://t.co/OaBOTcbOYk
Register for OpenSSF Community Day NA: https://t.co/0fjOKhQHbn
Third-Party Notices (TPNs) are often the only verifiable record when source code or #SBOMs are inaccessible, yet theyβre usually trapped in unstructured PDFs.
A new guest blog by Devashri Datta discusses transforming TPNs into "Security Intelligence."
https://t.co/3Ia2kyx8P9
130 new #CVEs are disclosed every day.
Learn how to filter out the 95% of "noise" and focus on vulnerabilities that are actually exploitable in production.
Check out the latest guest blog from Jonas Rosland (Sysdig)
https://t.co/zZEizIr2n0
The 2026 #SecuritySlam has officially concluded! π π‘οΈ
Huge congrats to our champions and special thanks to our partners at @sonatype and the CNCF TAG Security team!
See the full list of winners and find out whatβs next: https://t.co/3BL4g3lTZU