OpenSSF stories
Software supply chain attacks are becoming the biggest concern in cyber security, with organisations globally at risk.
Backed by Amazon, Google and Microsoft, the scheme aims to speed fixes for flaws that could ripple through banks, hospitals and power grids.
Members are backing tougher open source security as OpenSSF expands guidance on regulation, Python coding and AI-driven vulnerability tools.
Sonatype joins Linux Foundation registry working group to tackle funding, governance and security pressures as package downloads near 10 trillion.
Cloudsmith adds automated controls to quarantine and block risky dependencies, tightening enforcement on software supply chain security.
OpenSSF adds new members and launches AI security, supply chain and training initiatives after securing USD $12.5 million in funding.
Linux Foundation wins USD $12.5m from tech giants to bolster AI-era open source security and ease pressure on overstretched maintainers.
Adfinis launches six OpenBao-based services to help regulated organisations modernise open source secrets and encryption management.
OpenSSF has welcomed Target, Thread AI, and OSTIF as general members, enhancing efforts to improve security across the open source software ecosystem.
LF Energy introduces five open-source projects for digital energy technologies, bolstering efforts towards energy transition.
OpenSSF introduces new members including Patchstack and SparkFabrik, and outlines secure software development principles.
Technology is critical in business, government, social development, and so much more—and open source is all too often at the forefront of what's next.
Venafi has released its predictions for the cybersecurity landscape in 2023, indicating that this will be one the most challenging years yet for the industry.
Endor Labs exposes the dangers of unchecked open source software reuse in application development, with 95% of vulnerabilities found in indirect dependencies.
Widespread use of open source software in app development poses significant security risks, says Snyk and The Linux Foundation.
A free training course on developing secure software from the Open source Security Foundation is now available.
The Open Source Security Foundation partners with the Eclipse Foundation and others to shape the EU's Cyber Resilience Act, aiming to enhance software supply chain security.