Enhancing open source security: Insights from the OpenSSF on addressing key challenges

In this Help Net Security interview, we meet a prominent industry leader. Brian Behlendorf, CTO at the Open Source Security Foundation (OpenSSF), shares insights on the influence of his experiences with the White House CTO office, World Economic Forum,… Continue reading Enhancing open source security: Insights from the OpenSSF on addressing key challenges

Research reveals where 95% of open source vulnerabilities lie

New research from Endor Labs offers a view into the rampant but often unmonitored use of existing open-source software in application development and the dangers arising from this common practice. Open source vulnerabilities As just one example, the re… Continue reading Research reveals where 95% of open source vulnerabilities lie

A 10-point plan to improve the security of open source software

The Linux Foundation and the Open Source Software Security Foundation, with input provided by executives from 37 companies and many U.S. government leaders, delivered a 10-point plan to broadly address open source and software supply chain security, by… Continue reading A 10-point plan to improve the security of open source software

OpenSSF announces 15 new members to tackle supply chain security challenges

The Open Source Security Foundation (OpenSSF) announced 15 new members from leading software development, cybersecurity, financial services, communications, and academic sectors. This round of commitments is led by two new premier members, Atlassian an… Continue reading OpenSSF announces 15 new members to tackle supply chain security challenges

OpenSSF announces Alpha-Omega Project to improve global OSS supply chain security

Following a meeting with government and industry leaders at the White House, OpenSSF announced the Alpha-Omega Project to improve the security posture of open source software (OSS) through direct engagement of software security experts and automated se… Continue reading OpenSSF announces Alpha-Omega Project to improve global OSS supply chain security

Allstar app helps enforce security best practices for GitHub projects

Google and the Open Source Security Foundation (OpenSSF) have released Allstar, an app that allows organizations / owners of GitHub repositories to set up security policy expectations for GitHub projects and to make sure that these policies are adhered… Continue reading Allstar app helps enforce security best practices for GitHub projects

OpenSSF adds new members from around the globe to improve OSS security

OpenSSF announced new membership commitments to advance open source security education and best practices. New members include Accurics, Anchore, Bloomberg Finance, Cisco Systems, Codethink, Cybertrust Japan, OpenUK, ShiftLeft, Sonatype and Tidelift. O… Continue reading OpenSSF adds new members from around the globe to improve OSS security

Open Source Security Foundation Announces Education Courses and Participation Initiatives to Advance its Commitment to Securing the World’s Software Infrastructure

Free training opportunities, new members investments, consolidation with Core Infrastructure Initiative and new opportunities for anyone to contribute accelerate work on open source security SAN FRANCISCO, Calif., Oct 29, 2020 – OpenSSF, a cross-indust… Continue reading Open Source Security Foundation Announces Education Courses and Participation Initiatives to Advance its Commitment to Securing the World’s Software Infrastructure