Open Source Security Foundation
Structured security requirements aligned with international frameworks, standards, and regulations.
Sigstore is a standard for signing, verifying, and protecting software.
Safeguarding artifact integrity across any software supply chain.
Using AI securely ("security for AI") and using AI to improve security of other products ("AI for security").
Multi-discipline approach to international regulation and legislation and application of cybersecurity frameworks.
Helping people understand and make decisions on the provenance of the code they maintain, produce and use.
Improving the overall security of the OSS ecosystem by helping advance vulnerability reporting and communication.
OpenSSF events are a great opportunity to get involved with the OpenSSF community across the security and open source ecosystem. and ideas, progress, and collaborate on securing open source software.
Improving Risk Management Decisions with SBOM Data
Practical Guide for Building Robust AI/ML Pipeline Security
Join the growing list of organizations supporting the advancement of securing open source technology and funding the development and adoption of OpenSSF initiatives.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
