#openssf
Heading to #KubeCon + #CloudNativeCon + Open Source #SecurityCon? Let’s connect at ZarfFest! 🎉

Join OpenSSF and Defense Unicorns for an evening of drinks, light bites, and great conversations with fellow builders, maintainers, and open source friends.

defenseunicorns.com/events/zarff...
ZarfFest: A Defense Unicorns x OpenSSF Happy Hour
ZarfFest: A KubeCon Happy Hour Presented by Defense Unicorns and OpenSSF Join Defense Unicorns and OpenSSF for ZarfFest, a happy hour bringing together the open source, cloud native, and software sec...
defenseunicorns.com
September 25, 2026 at 7:01 PM
Securing the open source supply chain is also about growing the community! 🌍✨

In this recap of the OpenSSF Summer Mentorship Lightning Showcase, discover how our talented mentees teamed up with seasoned mentors to tackle critical security challenges across projects.

🔗: openssf.org/blog/2026/09...
September 24, 2026 at 7:39 PM
「OSSレジストリのただ乗りは限界」 GoogleやMicrosoftなど12社が企業の費用負担を巡り共同声明:エンタープライズ向け「有償枠」などの資金調達モデルを模索へ(1/2 ページ) - @IT atmarkit.itmedia.co.jp/ait/spv/2609...
利用料を取る形になるのかな。それともこの 12 社が出し合って、他は無料で使える?ただ乗りと言えばそうだけど、ソフトウェア開発の根本的に参加を前提だから誰もただ乗りと認識してなかったよね
「OSSレジストリのただ乗りは限界」 GoogleやMicrosoftなど12社が企業の費用負担を巡り共同声明
生成AIの普及でソフトウェア開発が激変する中、セキュリティ脅威も深刻化し、OSSレジストリの運用負荷が高まっている。こうした背景を踏まえOpenSSFは「現在の無料モデルは維持不可能である」との認識を示し、持続可能な資金調達モデルへの移行を表明した。GoogleやMicrosoftなど主要12社・団体が声明に賛同している。 (1/2)
atmarkit.itmedia.co.jp
September 24, 2026 at 1:12 PM
Nice, my little Glazier project currently scores at an 8.1 for the OpenSSF report! My original “floor” goal was 8, so this is nice. I imagine I can easily boost that number with a bit of effort.

#golang
OpenSSF scorecard report
OpenSSF scorecard report
scorecard.dev
September 24, 2026 at 3:06 AM
Ready to level up your open source project’s security posture? 🛡️

OpenSSF & CNCF TAG Security launched Security Slam 2026 (Oct 5–Nov 6) for ALL OSS projects! Prepare for the EU CRA, access Slack advisors, and earn badges.

Read the blog: openssf.org/blog/2026/09...
September 23, 2026 at 8:01 PM
malicious-packages by @openssf (⭐️ 614)

A repository of reports of malicious packages identified in Open Source package repositories, consumable via the Open Source Vulnerability (OSV) fo...

#go
September 23, 2026 at 5:25 PM
bundleferry --advise recommends a bundler and reports its security posture from OpenSSF Scorecard and OSV. Deterministic rules with citations, never an invented score. Every claim is checked by an independent verifier. https://github.com/ryanda9910/bundleferry
September 22, 2026 at 1:00 AM
Firms pledge increased financial support for public package registries www.itpro.com/software/ope...
Firms pledge increased financial support for public package registries
OpenSSF said that current funding models are inadequate, thanks to rising infrastructure and security costs
www.itpro.com
September 17, 2026 at 12:58 PM
CIで `pip install --no-cache-dir` してると、ビルドは普通に通る。
でもそのたびPyPI側には配信コストが積まれてて、OpenSSFは前年比30〜50%増と言ってる。

「速く捨てる実験」の足元にある、取りに行く回数の話を書いた。
https://note.com/hiro_nakamura_ai/n/n0ed176f14122
September 17, 2026 at 10:34 AM
“PyPI、Maven Central、crates.io、RubyGems、npm、NuGet、OpenVSX、Packagistなど” のレジストリがAIの影響で維持困難になってるので資金調達に参加してくださいという。うーんたいへんだな……

Sustainable Package Registries: An Enterprise Commitment
Sustainable Package Registries: An Enterprise Commitment
Discover how OpenSSF and major tech enterprises are committing to sustainable funding for public package registries to secure the global software supply chain.
openssf.org
September 17, 2026 at 1:58 AM
AI moves fast. Critical infrastructure needs support.

The OpenSSF Governing Board backs sustainable funding for public package registries: stronger security, reliable services, and continued free access for developers.

We’re in. Join us: openssf.org/blog/2026/09...
September 16, 2026 at 1:02 PM
🌱 September 11 has passed. What’s next for CRA compliance?

Find your role and next steps with OpenSSF. Thanks to Roman Zhukov for inspiring our garden analogy and the Global Cyber Policy Working Group for helping it grow!

Find your path: openssf.org/blog/2026/09...
September 15, 2026 at 4:42 PM
Is a Security Baseline Enough For Open Source Software?

In February, The Linux Foundation’s Open Source Security Foundation (OpenSSF) initiated the Open Source Project Security Baseline (OSPS Baseline) to establish minimum security requirements for open-source software. However, not everyone is…
Is a Security Baseline Enough For Open Source Software?
In February, The Linux Foundation’s Open Source Security Foundation (OpenSSF) initiated the Open Source Project Security Baseline (OSPS Baseline) to establish minimum security requirements for open-source software. However, not everyone is supporting it. According to Christopher Robinson, chief security architect at OpenSSF, the baseline initiative provides a structured set of security requirements aligned with international cybersecurity frameworks, standards, and regulations……..
onlinemarketingscoops.com
September 15, 2026 at 9:13 AM
Watch the on-demand video: www.youtube.com/watch?si=atc...
Tech Talk: CRA Readiness: A Practitioner’s Guide to Compliance
YouTube video by OpenSSF
www.youtube.com
September 10, 2026 at 7:46 PM