OpenSSF
Open Source Security Foundation (OpenSSF)
Advancing open source security for all
The OpenSSF released the Secure Coding Guide for #Python (PySCG). This practical resource offers 50+ rules and code examples to help developers mitigate vulnerabilities in open source software. 🐍
Read the blog: https://openssf.org/blog/2026/05/12/secure-coding-guide-for-python-pyscg-first-release/
Access the guide: https://best.openssf.org/Secure-Coding-Guide-for-Python/
AI is flooding open source projects with vulnerability reports faster than maintainers can handle. OpenSSF and CNCF just dropped the free playbook.
"This is math, not magic. And with the right practices, it is manageable."
Download your copy: https://openssf.org/resources/securing-open-source-in-the-age-of-ai-a-practical-guide/
Today, The Linux Foundation announced a $12.5 million investment from a powerhouse coalition including Anthropic, Amazon Web Services (AWS), Google, Google DeepMind, GitHub, Microsoft, and OpenAI. Managed by OpenSSF and the Alpha-Omega project.
The @linuxfoundation@social.lfx.dev, today announced $12.5 million in total grants from Anthropic, AWS, GitHub, Google, Google DeepMind, Microsoft, and OpenAI to strengthen the security of the open source software ecosystem.
The funding will be managed by Alpha-Omega and the Open Source Security Foundation (OpenSSF), to develop long-term, sustainable security solutions that support open source communities worldwide.
We've seen a concerning rise in targeted attacks on upstream registries like npm and PyPI through malicious packages. But how do you actually defend against them day-to-day?
Learn how to strengthen your supply chain security: https://openssf.org/blog/2026/05/20/detecting-malicious-packages-using-the-osv-api/
📣 We're launching the OpenSSF Ambassador Program!
Applications are now open on a rolling basis. Help us create a future where software is universally trusted and secure.
Learn more: https://openssf.org/blog/2026/03/23/introducing-the-openssf-ambassador-program/
Learn why machine-readable security signals provide the practical foundation for automated due diligence. These signals function as voluntary mechanisms for upstream transparency, not formal assurances or a transfer of legal liability.
Read the blog: https://openssf.org/blog/2026/05/29/aligning-on-machine-readable-signals-as-the-foundation-for-due-diligence/
Huge updates in the world of Open Source Security! 🔐
The #OpenSSF February Newsletter is out, and it is packed with resources for developers and security teams.
Stay ahead of the curve and check out the full breakdown here: https://openssf.org/newsletter/2026/02/26/openssf-newsletter-february-2026/
Package repository security impacts every OSS ecosystem. 🔐
OpenSSF convened npm, PyPI, Maven Central, RubyGems, crates.io & more to tackle shared challenges -- from identity to governance and sustainability.
Read: https://openssf.org/blog/2026/02/19/advancing-package-repository-security-through-collaboration/
Vulnerability "slop" is real, and it's burning out our maintainers. 📉
On the latest #WhatsInTheSOSS podcast, Michael Lieberman from Kusari explains how we can use codified expertise to filter the noise and meet developers where they are.
The April OpenSSF Newsletter is here! 📰
Big things are happening in the world of open source security. Topping the list: #OpenSSFCommunity Day North America is happening May 21st in Minneapolis!
Read the Newsletter: https://openssf.org/newsletter/2026/04/21/openssf-newsletter-april-2026/
Introducing the #Gemara Model -- a new framework for GRC engineering.
It outlines a 7-layer architecture designed to help teams standardize how security policies are defined, enforced, and measured.
📖 Blog:
https://openssf.org/blog/2026/03/09/introducing-the-gemara-model/
📄 Publication:
https://openssf.org/resources/gemara-a-governance-risk-and-compliance-engineering-model-for-automated-risk-assessment/
While many organizations have mastered pre-deployment scanning, a massive blind spot remains: post-deployment vulnerability detection. As Tracy Ragan explains in her latest blog, software that is secure at release can become vulnerable as new #CVEs are disclosed.
https://openssf.org/blog/2026/04/03/rethinking-post-deployment-vulnerability-detection/
Abandoned projects introduce hidden risks into your software supply chain.
On the latest episode of the What’s in the SOSS? podcast, host CRob sits down with Isaac Wuest from HeroDevs to examine End-of-Life (EOL) open source software.
Isaac explains how to differentiate between inherent hazards and actual risk within your dependency tree.
Kusari is providing its Inspector tool at no cost to OpenSSF projects to move security from reactive firefighting to proactive prevention.
At Open Source #SecurityCon Europe, we welcome Helvethink, Spectro Cloud, and Quantrexion as General Members, introduce Kusari Inspector, and launch the OpenSSF Ambassador Program.
Read the Announcement: https://openssf.org/press-release/2026/03/23/openssf-celebrates-new-members-no-cost-tooling-and-project-milestones/
The #OpenSSF Mentorship Program 2026 cycle is here! Whether you're a student looking to learn or a pro ready to lead, join us.
🎧 Inside Scoop: Check out the latest What’s in the SOSS? Podcast to hear how mentees become project maintainers. https://openssf.org/podcast/2026/03/17/whats-in-the-soss-podcast-56-s3e8-empowering-new-maintainers-inside-the-openssf-mentorship-program/
Live from #OpenSSFCommunity Day North America! 🎉 We're celebrating an incredible quarter of growth and officially welcoming our newest members to the Foundation: ActiveState, Aikido Security, Minimus, TuxCare, and the FreeBSD Foundation!
The agentic AI Tech Talk is happening next week -- have you registered yet?
Read the blog to see why this conversation matters: from agent autonomy & trusted tool interaction to context integrity, it outlines what you’ll learn in the session.
#AgenticAI is moving fast -- but is it secure? 🤖🔐
📅 Join us for an OpenSSF Tech Talk on the practical realities of securing agentic systems on March 17, 1PM ET!
Hear from experts from Microsoft, Canonical, TestifySec, and Thread AI!
Think you need special permission to contribute to OpenSSF? Think again. ❌
#OSSSecurity thrives on diverse perspectives. Whether you’re into AI/ML security, policy, or dev best practices, there’s a seat at the table for you. 🪑
In the latest What's in the SOSS?, Sally Cooper sits down with Brandt Keller from Defense Unicorns to talk about Zarf, @CloudNativeFdn-ecosystem #OpenSSF Sandbox Project built to package, transfer, and deploy software in air-gapped environments.
Join us for #OpenSSFCommunity Day North America on May 21! 📅
We are grateful for the support of Honda, our Gold Sponsor, in our mission to secure the open source software ecosystem.
Register & join the conversation on software supply chain security: https://events.linuxfoundation.org/openssf-community-day-north-america/register/
The #OpenSSF March newsletter is live! Featuring:
- New funding from AWS, Google, Microsoft, and others to secure AI 💰
- Launch of the OpenSSF Ambassador Program
- The new Gemara Model for GRC engineering
Read more: https://openssf.org/newsletter/2026/03/26/openssf-newsletter-march-2026/
Subscribe: https://openssf.org/newsletter/#newsletter
Join us for a Welcome Call to meet the BEAR Working Group!
We’re on a mission to ensure everyone has a fair chance to help protect our digital world.
Come see how you can get involved!
March 26, 2026 at 9am PT / 12pm ET / 16:00 UTC
View our calendar at openssf.org/getinvolved
🔍 What to expect at Open Source #SecurityCon Europe 2026?
From eBPF-based algorithms to the latest on the EU Cyber Resilience Act, we’re covering the tech and policy that keeps our ecosystem safe.
The EU #CRA is a major milestone for open source, but it can feel overwhelming. At FOSDEM 2026, Harald Fischer from balena broke down the first steps toward conformity using a simple metaphor.
🔗 Read the full guest blog and watch the FOSDEM session here: https://openssf.org/blog/2026/03/11/first-steps-towards-cyber-resilience-act-conformity-biking-the-cra-with-balena-at-fosdem-2026/
Now live: ROI for Open Source Software Contribution
The data is clear:
• 2 to 5x ROI
• Faster security response
• Less technical debt
Read the report: https://openssf.org/resources/roi-for-open-source-software-contribution/
In our latest OpenSSF Tech Talk, OpenSSF members dismantled the AI "black box."
Read the recap to learn about the SAFE-#MCP threat catalog, how to secure the 3,000+ open source dependencies in the typical AI stack, and more!
https://openssf.org/blog/2026/04/08/openssf-tech-talk-recap-securing-agentic-ai/
From UI/UX to OpenSSF Contributor: Ejiro Oghenekome on What’s in the SOSS?
Ejiro shares insights from her "100 Days of Cybersecurity" challenge and her leadership in authoring the "Beginner to Builder" series.
How do we move from isolated security patches to a systemic, resilient software supply chain?
Read the #OpenSSFCommunity Day NA recap and see how the community has been unifying tools, navigating AI, and securing the OSS.
Is your organization ready for the European Cyber Resilience Act (CRA)? New EU rules mandate "security by design" for digital products.
The second Linux Foundation Research survey launches this June, learn why the ecosystem is falling behind.
The 2026 #SecuritySlam has officially concluded! 🏁 🛡️
Huge congrats to our champions and special thanks to our partners at Sonatype and the CNCF TAG Security team!
See the full list of winners and find out what’s next: https://openssf.org/blog/2026/04/10/security-slam-2026-celebrating-our-security-champions-and-project-milestones/
🔍 The #OSPSBaseline provides practical guidance for open source maintainers and organizations to strengthen project security.
It defines clear baseline expectations across areas like repository management, access control, and vulnerability handling.
Welcoming OSS-CRS to the #OpenSSFCommunity
Following the success of DARPA’s AI Cyber Challenge (AIxCC), we are thrilled to announce that OSS-CRS is joining the OpenSSF under the AI / ML Security Working Group.
The #OpenSSFCommunity Day agenda is live! Mark your calendar for May 21 in Minneapolis and start planning your schedule by bookmarking your favorite sessions.
Read the agenda highlight: https://openssf.org/blog/2026/04/20/secure-your-spot-the-openssf-community-day-north-america-2026-agenda-is-live/
Register for OpenSSF Community Day NA: https://events.linuxfoundation.org/openssf-community-day-north-america/register/
AI is playing an increasing role in open source security.
Part of our #AIxCC series, @trailofbits shares lessons from DARPA’s challenge and how AI + fuzzing can deliver real results.
🎙️ What's in the SOSS? Ep. 59 with Yesenia and Prince Asiedu, the origin story of #OSSAfrica and why structural barriers can spark community breakthroughs.
The CPS project has just officially secured the #OpenSSF Gold Badge.
CPS is the first project within the LFN community to hit this milestone. This badge proves that security and quality are baked into the DNA of the project.
Read the full story: https://openssf.org/blog/2026/05/07/the-road-to-gold-how-cps-set-a-new-standard-for-security-and-quality-in-open-source/
