Open Source Security Foundation (OpenSSF) Together, we're securing the #opensource ecosystem #OSSSecurity openssf.org social.lfx.dev/@openssf

🎉 The 2025 OpenSSF Annual Report has officially arrived!!! We invite you to celebrate another year of progress, creativity, and collaboration shaping a safer, more resilient open source community. Download the report: openssf.org/download-the-202… #AnnualReport #OSSSecurity
1
4
19
2,130
Heading to #KubeCon + #CloudNativeCon + Open Source #SecurityCon? Let’s connect at ZarfFest! 🎉 Join OpenSSF and Defense Unicorns for an evening of drinks, light bites, and great conversations with fellow builders, maintainers, and open source friends. hubs.la/Q04yl-zj0
1
236
Open source participation creates business and career value. Explore @IBM’s journey with @RedHat and #ProjectLightwell, plus Jamie Thomas’s insights in conversation with CRob. What’s your strategy to give back? hubs.la/Q04ykxGZ0
1
2
229
Securing the open source supply chain is also about growing the community! 🌍✨ Discover how our talented mentees teamed up with seasoned mentors to tackle critical security challenges across projects in the OpenSSF Summer Mentorship Showcase. bit.ly/46JEsiY
2
6
369
Ready to level up your open source project’s security posture? 🛡️ OpenSSF & @CloudNativeFdn TAG Security launched Security Slam 2026 (Oct 5–Nov 6) for ALL OSS projects! Prepare for the EU CRA, access Slack advisors, and earn badges. Read the blog: openssf.org/blog/2026/09/23/…
3
236
AI speeds up development. Can your security keep pace? ActiveState CEO Abby Kearns joins What’s in the SOSS? to tackle AI velocity, CRA compliance, and dependency debt. Know your dependencies. Hear her perspective. 🎧️ hubs.la/Q04y2NQh0
1
3
314
AI moves fast. Critical infrastructure needs support. The OpenSSF Governing Board backs sustainable funding for public package registries: stronger security, reliable services, and continued free access for developers. We’re in. Join us: hubs.la/Q04xDS7r0
1
1
6
471
🌱 September 11 has passed. What’s next for CRA compliance? Find your role and next steps with OpenSSF. Thanks to Roman Zhukov for inspiring our garden analogy and the Global Cyber Policy Working Group for helping it grow! Find your path: hubs.la/Q04xz3N90
2
3
239
Mila from @awscloud breaks down how OS projects can maintain secure infrastructure without financial strain. Discover how Gradle and Compiler Explorer leverage the AWS Open Source Promotional Credit Program to harden the global software supply chain. openssf.org/blog/2026/09/14/…
1
3
257
The September 11 CRA reporting milestone is here. Our new community guide explains manufacturers’ reporting obligations and how open source maintainers and stewards can prepare for collaboration when vulnerabilities affect downstream products. hubs.la/Q04xggDY0
1
4
451
Sept 11 is here. Are you ready? In our latest Tech Talk, experts walked us through practical steps for EU Cyber Resilience Act readiness, covering maintainer exemptions, manufacturer obligations, and new supply chain security baselines. Read the recap: openssf.org/blog/2026/09/10/…
1
1
3
224
AI changes the speed of vulnerability discovery, not the fundamentals of software security. Sal Kimmich and Simon John examine the UK GDS guidance, the case for “open by default,” and why durable enforcement must focus on real security practices. hubs.la/Q04x6sPW0
2
8
520
AI is reshaping software engineering and security, but its impact cuts both ways. OpenSSF Board Chair Mark Russinovich, CTO, Deputy CISO and Technical Fellow at Microsoft Azure, joined us June 26 to discuss. hubs.la/Q04wYtKD0
1
7
380
From our Happy Hour Reception at The Cosmopolitan to deep dives into software supply chain security, AI findings, and the hallway track, OpenSSF was proud to advance open source security at Hacker Summer Camp 2026! Read the full recap: openssf.org/blog/2026/09/04/…
1
3
354
The EU Cyber Resilience Act is reshaping responsibility across the software supply chain. Madalin Neag breaks down what the CRA means for open source, software stewards, maintainers, and organizations preparing for compliance. hubs.la/Q04w3M9j0
1
1
4
362
📰 The August Newsletter is here! It is packed with exciting updates within the OpenSSF community, including how Ericsson solved CRA obligations with over 1,400 upstream fixes, and key strategies for securing agentic AI ahead of AGNTCon NA. Read: openssf.org/newsletter/2026/…
3
396
We are excited to announce that #BOMHort (formerly SeeBOM) has officially joined the OpenSSF family as a Sandbox Project!!! Read the full announcement on our blog to learn more about BOMHort: openssf.org/blog/2026/08/28/… Get involved on this project: openssf.org/projects/bomhort…
2
5
13
862
How did one team improve security across the open source ecosystem? Ericsson took on the EU Cyber Resilience Act (CRA) by eliminating private forks and going straight to the source. hubs.la/Q04vJ_TZ0
2
2
14
2,500
We're heading to #AGNTCon + #MCPCon North America this October! 🚀 Come see us at the OpenSSF booth to grab some swag and chat! 👋 Read more on our blog: hubs.la/Q04vBrY-0
3
325
How does a major telecom leader solve EU Cyber Resilience Act (CRA) compliance? By going 100% upstream. Learn how Ericsson lowered long-term lifecycle costs while strengthening the global supply chain. hubs.la/Q04vpFtc0
2
273