For 20+ years, @Google has been dedicated to OSS and the developers who secure it. To combat the current threat landscape, we’re joining our industry peers to make new commitments.
https://t.co/nP7n3kJxtb
I am proud to share the announcement about our CodeMender project at @GoogleDeepMind, an agent that can automatically fix a range of code security vulnerabilities. From only a modest-compute run, our agent submitted 72 high-quality fixes to vulnerable code in popular codebases, and maintainers accepted and upstreamed them.
https://t.co/TApULhUSzB
🥳 #OpenSSF is turning 5! From sigstore to SLSA, OpenSSF Scorecard to GUAC—we’ve grown into a global force for open source security.
Read the full journey & join the celebration 🎉
👉 https://t.co/mRMsONEbLt
Tell us how OpenSSF has impacted your work ⬇️
I am really excited that NVIDIA model hub is the first model hub that has adopted the model signing project. NVIDIA has collaborated significantly on the project and is a major reason for the standardization of the signature format (OMS).
Tom Hennen from @Google shares how the new #SLSA Source Track helps reduce the risk of source tampering—bringing stronger guarantees to code integrity and auditability. Learn how to protect your repo from attacks like PHP and xz. #OSSummit#OpenSSF#SupplyChainSecurity
I was pleasantly surprised to see model signing presented in the first 5 slides of the conference. And then the A2A talk raised the stakes: we need to sign the agent cards.
My thesis: we can do the same with the same model signing solution
Yesterday we launch v1.0 of model signing library, taming the wild west of model formats and deserialization vulnerabilities. You can read more about why this is needed and why we picked Sigstore as main signing method at https://t.co/SFdmRLgAH3
📣 Announcing v1.0 of the model-signing project, developed by the #OpenSSF AI/ML WG! This project enables signing + verifying ML models of any size/format using #sigstore, self-signed certs, or key pairs. Read the blog to learn more & get involved: https://t.co/TRfwJI3lc7
🚀 The Alpha-Omega project has published its 2024 annual report!
With $6M in grants, Alpha-Omega helped staff security teams, fund audits, and strengthen critical #opensource projects—shaping a more secure and sustainable ecosystem.
📖 https://t.co/C7VjlvrzFA
OSV-Scanner has just released the first beta for V2, a major update that includes significant new features, including layer-aware container scanning, remediation for pom.xml, new HTML output and more.
https://t.co/kkPK2KHBTk
Please try it out and give us feedback!
Happy new year! OSV had a lot of great progress in 2024, from new ecosystem adoption, API improvements, and scanner feature development! We just published a blog about these and our 2025 plans here: https://t.co/7vRkoPHZfO !
On the heels of @Google’s ‘Big Sleep’ AI discovery of a real-world vulnerability, our OSS-Fuzz team identified and reported 26 vulnerabilities to open-source project maintainers by using AI-generated and enhanced fuzz targets. Read more here: https://t.co/6SfPt38ZmE
New blog post about OSS-Fuzz AI-powered fuzzing is live!
We talk about what went into making LLMs work well enough for this use case to find 26 new vulnerabilities (including a CVE in OpenSSL), as well as what else we have planned to make this better.
https://t.co/ewCUmtRs6P
ToB's @arturcygan found code execution and DoS bugs after just a few hours of fuzzing ZBar, an open-source library for reading barcodes.
tl;dr basic fuzz testing can reveal serious bugs - even in widely used software. https://t.co/fbwBhAJSLT
Join us at SigstoreCon: Supply Chain Day on Nov 12, co-located with KubeCon NA in SLC! Registration includes a day of engaging talks, lunch, and swag! https://t.co/9KOMMkiaoa