home.social

#openssf — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #openssf, aggregated by home.social.

  1. OSSGuard — one CLI to scan your project and tell you exactly which OpenSSF security practices are missing: Scorecard, SLSA, SBOM, Sigstore, and more.

    Works with Python, Go, JS, Rust, Java, C/C++.

    pip install ossguard
    brew install kirankotari/tap/ossguard
    npx ossguard

    github.com/kirankotari/ossguard

    #OpenSSF #SupplyChainSecurity #DevSecOps #OpenSource #DevOps #Python #Node #Golang #Community

  2. @BrideOfLinux I enjoyed your article – thanks. Discovered three months after publication via <vermaden.wordpress.com/2026/05>.

    Just one thing:

    "… Isn’t this exactly what the Open Source Security Foundation was established to handle in the wake of OpenSSL’s difficulties?"

    I 'm not certain. The roadmap at <openssf.org/about/> begins:

    "The OpenSSF strategy is outlined across three key areas:

    We will be a Catalyst for Change, we will Educate and Empower the Modern Developer, and we will be an Ecosystem Leader. …"

    There's much more than a roadmap – and I didn't attempt to digest the charter (it's difficult to read, with the watermark) – it's difficult to tell why the OSSF was established, and so on. I don't doubt that the Foundation does great work, there's just a lot to take in. @openssf

    In the case of sudo: I imagine that the media was a catalyst for change. Some time between mid-February and 3rd March, the plea for sponsorship disappeared:

    ― <web.archive.org/web/2026021504>

    ― <web.archive.org/web/2026030514>.

    (I recall reading the article in The Register, which was discussed in Reddit <old.reddit.com/r/programming/d>, and so on.)

    Cc @millert @governa

    #sudo #OpenSSF

  3. @BrideOfLinux I enjoyed your article – thanks. Discovered three months after publication via <vermaden.wordpress.com/2026/05>.

    Just one thing:

    "… Isn’t this exactly what the Open Source Security Foundation was established to handle in the wake of OpenSSL’s difficulties?"

    I 'm not certain. The roadmap at <openssf.org/about/> begins:

    "The OpenSSF strategy is outlined across three key areas:

    We will be a Catalyst for Change, we will Educate and Empower the Modern Developer, and we will be an Ecosystem Leader. …"

    There's much more than a roadmap – and I didn't attempt to digest the charter (it's difficult to read, with the watermark) – it's difficult to tell why the OSSF was established, and so on. I don't doubt that the Foundation does great work, there's just a lot to take in. @openssf

    In the case of sudo: I imagine that the media was a catalyst for change. Some time between mid-February and 3rd March, the plea for sponsorship disappeared:

    ― <web.archive.org/web/2026021504>

    ― <web.archive.org/web/2026030514>.

    (I recall reading the article in The Register, which was discussed in Reddit <old.reddit.com/r/programming/d>, and so on.)

    Cc @millert @governa

    #sudo #OpenSSF

  4. @BrideOfLinux I enjoyed your article – thanks. Discovered three months after publication via <vermaden.wordpress.com/2026/05>.

    Just one thing:

    "… Isn’t this exactly what the Open Source Security Foundation was established to handle in the wake of OpenSSL’s difficulties?"

    I 'm not certain. The roadmap at <openssf.org/about/> begins:

    "The OpenSSF strategy is outlined across three key areas:

    We will be a Catalyst for Change, we will Educate and Empower the Modern Developer, and we will be an Ecosystem Leader. …"

    There's much more than a roadmap – and I didn't attempt to digest the charter (it's difficult to read, with the watermark) – it's difficult to tell why the OSSF was established, and so on. I don't doubt that the Foundation does great work, there's just a lot to take in. @openssf

    In the case of sudo: I imagine that the media was a catalyst for change. Some time between mid-February and 3rd March, the plea for sponsorship disappeared:

    ― <web.archive.org/web/2026021504>

    ― <web.archive.org/web/2026030514>.

    (I recall reading the article in The Register, which was discussed in Reddit <old.reddit.com/r/programming/d>, and so on.)

    Cc @millert @governa

    #sudo #OpenSSF

  5. @BrideOfLinux I enjoyed your article – thanks. Discovered three months after publication via <vermaden.wordpress.com/2026/05>.

    Just one thing:

    "… Isn’t this exactly what the Open Source Security Foundation was established to handle in the wake of OpenSSL’s difficulties?"

    I 'm not certain. The roadmap at <openssf.org/about/> begins:

    "The OpenSSF strategy is outlined across three key areas:

    We will be a Catalyst for Change, we will Educate and Empower the Modern Developer, and we will be an Ecosystem Leader. …"

    There's much more than a roadmap – and I didn't attempt to digest the charter (it's difficult to read, with the watermark) – it's difficult to tell why the OSSF was established, and so on. I don't doubt that the Foundation does great work, there's just a lot to take in. @openssf

    In the case of sudo: I imagine that the media was a catalyst for change. Some time between mid-February and 3rd March, the plea for sponsorship disappeared:

    ― <web.archive.org/web/2026021504>

    ― <web.archive.org/web/2026030514>.

    (I recall reading the article in The Register, which was discussed in Reddit <old.reddit.com/r/programming/d>, and so on.)

    Cc @millert @governa

    #sudo #OpenSSF

  6. @BrideOfLinux I enjoyed your article – thanks. Discovered three months after publication via <vermaden.wordpress.com/2026/05>.

    Just one thing:

    "… Isn’t this exactly what the Open Source Security Foundation was established to handle in the wake of OpenSSL’s difficulties?"

    I 'm not certain. The roadmap at <openssf.org/about/> begins:

    "The OpenSSF strategy is outlined across three key areas:

    We will be a Catalyst for Change, we will Educate and Empower the Modern Developer, and we will be an Ecosystem Leader. …"

    There's much more than a roadmap – and I didn't attempt to digest the charter (it's difficult to read, with the watermark) – it's difficult to tell why the OSSF was established, and so on. I don't doubt that the Foundation does great work, there's just a lot to take in. @openssf

    In the case of sudo: I imagine that the media was a catalyst for change. Some time between mid-February and 3rd March, the plea for sponsorship disappeared:

    ― <web.archive.org/web/2026021504>

    ― <web.archive.org/web/2026030514>.

    (I recall reading the article in The Register, which was discussed in Reddit <old.reddit.com/r/programming/d>, and so on.)

    Cc @millert @governa

    #sudo #OpenSSF

  7. 🔖 The latest issue of my is out, issue 010.

    Stories from reviving & reimagining , secure publishing on , why doesn’t fail because of code, backlog updates &

    blog.ulisesgascon.com/newslett

  8. 🌟 New OpenSSF Project Spotlight 💃

    In this interview, SLSA Steering Committee member Tom Hennen (Google) breaks down how SLSA is helping organizations strengthen trust across the software supply chain.

    Watch the full Project Spotlight:
    🔗 youtube.com/watch?v=gdYlSuH5Srs

    #OpenSSF #SLSA #OSSSecurity

  9. Financial services run on open source, and #OpenSSF is helping make it more secure.

    At #OSFF, our community is leading sessions on:
    🔹 OSPS Baseline
    🔹 CVE & vulnerability data
    🔹 AI security

    📖Read the blog: openssf.org/blog/2025/10/09/bu

  10. 🗞️ Exciting news: now has a Security Working Group!

    We’ll:
    👉 Define triage & policies
    👉 Guide secure plugin development
    👉 Improve report processes
    👉 Promote best practices
    👉 Support & initiatives

    github.com/webpack/security-wg

  11. 📊 The OpenSSF Scorecard keeps improving! With 7.6K installs and 3.4K repositories displaying badges, it’s become an essential tool for open source security. 📥 Get the full details in the Annual Report: hubs.la/Q0318XDQ0
    #OSS #OpenSSF #Scorecard

  12. #Sigstore creator, #Chainguard CEO, #OpenSSF TAC member and Season 1 guest Dan Lorenc returns to the #ITOps Query podcast to discuss the year in #opensource and #cybersecurity. Topics range from #softwaresupplychain management, hardening #containerimages and #SBOMs in limbo to #openproduct companies and business models, including his own company's shift in focus this year. Plus: a look ahead to #SecOps and #AI in 2025. #yearinreview #2024yearinreview

    podbean.com/ew/pb-ivy26-1778bf

  13. 📅 Happening today at Open Source Summit Japan: Hitachi presents on the OpenSSF Scorecard, exploring supply chain attacks and xz utilities. Learn more about OpenSSF Scorecard: openssf.org/projects/scorecard
    #OSSummit #OpenSSF #Scorecard

  14. Open sourcerers say suspected #xz-style attacks continue to target #maintainers
    #SocialEngineering patterns spotted across range of popular projects
    Higher-ups at the #OpenJS Foundation and #OpenSource Security Foundation (#OpenSSF) believe the attempt to plant a #backdoor into #Linux's xz data compression library "may not be an isolated incident" given their recent observations.
    theregister.com/2024/04/16/xz_

  15. Excellent summary by Solar Designer on oss-security of what's happened in the last two weeks in response to the #xz #backdoor:

    openwall.com/lists/oss-securit

    Noteworthy:
    - #OpenSSH implemented systemd notification
    - #systemd moves to dlopen(3) for some dependencies
    - another detailed timeline at research.swtch.com/xz-timeline
    - similar social engineering takeover attempts suspected in #OpenJS and #OpenSSF

  16. This exemplifies the unique network of human beings in and around Open Source that makes it so _resilient_.

    With OSS, people are curious. They are empowered to take a peek under the hood. To share what they find with others. To ignore organizational and architectural boundaries.

    #OpenSource #FreeSoftware #FOSS #OSS #InfoSec #XZ #OpenJS #OpenSSF #Linux #SOSSCommunity

    twitter.com/postgresperf/statu

  17. Free and Open Source software communities are anything *but* “fragile” in light of recent failed attacks.

    They are smart. They are vigilant. They are resilient.

    But they also need support from institutions given the resources attackers may have.

    #OpenSource #FreeSoftware #FOSS #OSS #InfoSec #XZ #OpenJS #OpenSSF #Linux #SOSSCommunity

  18. Open Source Security (OpenSSF) and OpenJS Foundations Issue Alert for Social Engineering Takeovers of Open Source Projects

    XZ Utils cyberattack likely not an isolated incident

    #OpenSource #FreeSoftware #FOSS #OSS #InfoSec #XZ #OpenJS #OpenSSF #Linux

    openjsf.org/blog/openssf-openj

  19. Today and tomorrow I'll join the third #OSPOlogyLive Europe in #Apeldoorn (part presentations, part roundtable sessions) to help organizations navigate Open Source Program Offices operations and management in European regions. OSPOlogy Live is hosted by the #OSPO at the Dutch Tax and Customs Administration (#Belastingdienst) and co-organized with #LFEurope, #InnerSource Commons Foundation, Foundation for Public Code, #LFEnergy, #OpenChain, #SPDX, #CHAOSS, #TODOGroup and #OpenSSF projects.

  20. 🎉 OpenSSF Scorecard Monitor version 2.0.0-beta7 is out!.

    Simplify tracking in your organization with automated and reports, plus optional issue .

    Check it out:
    github.com/marketplace/actions

  21. "TACOS, in addition to being delicious, are now getting a new meaning as a framework for evaluating and attesting to the secure #software #development practices of open source packages....TACOS is grounded in the #NIST #SSDF, and draws from the #OpenSSF Scorecard project and the Center for Internet Security Software Supply Chain Security Guide as well"

    Interesting,, and certainly named with the typical #FOSS adherence to decorum.

    blog.tidelift.com/introducting

  22. Ein neues Tool der Open Source Security Foundation prüft in Open-Source-Projekten auf GitHub kontinuierlich die Einhaltung der Security Best Practices.
    Allstar: Sicherheitsregeln in GitHub-Projekten automatisiert durchsetzen