#OpenSSF

Pierre-Yves Lapersonnepylapp@framapiaf.org
2025-05-30

"The Open Source Security FoundationBest Practices badge is a way for Free/Libre and Open Source Software projects to show that they follow best practices.
Projects can voluntarily self-certify, at no cost […] to explain how they follow each best practice."

#FLOSS #opensource #security #OpenSSF #NIS2 #CyberResilienceAct

bestpractices.dev/en

2025-05-22

✨Exciting news in May across the #OpenSSF community—don’t miss the momentum!
📬 Read the May newsletter: openssf.org/newsletter/2025/05

2025-05-15

What does collaboration on secure builds look like?

Ericsson contributed its C/C++ Compiler Options Hardening Guide to the #OpenSSF Best Practices WG—earning insights that strengthened the guide for everyone.

Learn More ➝ openssf.org/blog/2025/05/15/ca

2025-05-14

📢 CFP is open for #OpenSSFCommunity Day Korea — Nov 4 in Seoul, colocated with the Linux Foundation's Open Source Summit Korea!

🗓 Submit by Aug 3 (23:59 KST | 06:59 PST)
🔗 events.linuxfoundation.org/ope

#OpenSSF #OSSummit #OpenSourceSecurity

2025-05-06

New podcast episode! 🎙️
Meet Stacey Potter, the new Community Manager at #OpenSSF. From startup ops to open source advocacy, Stacey shares her journey and hopes for a more inclusive security future.
Listen → openssf.org/podcast/2025/05/06

2025-05-01

#OpenSSF Community Day India 2025 is happening on 4 Aug, Hyderabad.

The CFP deadline is 4 May 23:59 IST, and they're open to talks about Security Education, Research, Tooling, Public Policy and the AI/Security space as well.

2025-04-29

📢 #OpenSSF just launched a free course to help developers get ready for the EU #CRA — and nearly 2,000 people enrolled in the first week!

✅ Understand the CRA’s key requirements
✅ Learn how to start preparing for 2026 enforcement

➡️ Full announcement: openssf.org/press-release/2025

2025-04-28

The #OpenSSF Memory Safety SIG just released the #MemorySafety Continuum!
Practical steps to tackle memory safety risks and strengthen #OSSSecurity — no matter where you are today.
👉 Read more: https://openssf.org/blog/2025/04/28/an

2025-04-25

🔒 #RSTUF has successfully completed an independent security audit, supported by #OpenSSF and coordinated by OSTIF!

Security audits like this strengthen trust, transparency, and resilience across our ecosystem. Read more & get involved: openssf.org/blog/2025/04/25/re

2025-04-22

🎧 In this episode of What’s in the SOSS? #OpenSSF Podcast, host CRob sits down with the “Council of Daves” – Dr. David A. Wheeler (OpenSSF) and Dave Russo (Red Hat) – to talk secure development and why training both devs and managers is mission-critical.

openssf.org/podcast/2025/04/22

2025-04-15

🎙️ New Podcast Episode – What’s in the SOSS?

Meet Steve Fernandez, the new GM of #OpenSSF.

Don’t miss this powerful conversation about leadership, security, and the future of open source.
🎧 Listen now → openssf.org/podcast/2025/04/15

2025-04-04

📣 Announcing v1.0 of the model-signing project, developed by the #OpenSSF AI/ML WG! This project enables signing + verifying ML models of any size/format using #sigstore, self-signed certs, or key pairs. Read the blog to learn more & get involved: openssf.org/blog/2025/04/04/la

2025-04-03

🔐 #OpenSSF is sponsoring #VulnCon 2025, happening April 7-10 at the McKimmon Center in Raleigh, NC!

Join the community! Virtual admission through April 4: first.org/conference/vulncon20

OpenSSF's Open Source Project Security Baseline is a game-changer for securing open-source projects. jpmellojr.blogspot.com/2025/04 #OpenSSF #SecurityBaseline #OpenSource #SecureCoding #SoftwareDevelopment

2025-03-28

🔍 How can we better protect open source ecosystems from supply chain attacks?
Datadog, an #OpenSSF member, advances security with #GuardDog, an open source tool detecting malicious packages in PyPI & npm while contributing to a public threat dataset.
Read the blog: openssf.org/blog/2025/03/28/gu

2025-03-25

📬 The March 2025 #OpenSSF Newsletter is here!

🔹 Community Days
🔹 Policy Summit Washington, D.C.
🔹 Season 2 of What’s in the SOSS? Podcast
🔹 New, free course for software development managers
🔹 Project and working group updates

openssf.org/newsletter/2025/03

2025-03-20

"#OpenSSF Defines Baseline for Securing #OpenSource #Software"

ICYMI, a new #OSS project aims to standardize a #cybersecurity framework for OSS maintainers.

Love it! Coz my research has shown breaking down org boundaries has a very strong correlation with #DevOps success!

devops.com/openssf-defines-bas

2025-03-20

🌟 Community Day India is back! 🌟
Co-located with #KubeCon India, this is your chance to engage with the brightest minds in software security.
🎤 Submit your proposal by Sunday, April 27.
events.linuxfoundation.org/ope
#OpenSSF #OpenSSFCommunity #OSSSecurity

The Linux Foundationlinuxfoundation@social.lfx.dev
2025-03-19

📢 Is the open source ecosystem ready for the Cyber Resilience Act?
62% of respondents remain unfamiliar with CRA, and compliance challenges are emerging. This new Linux Foundation Research report, in partnership with OpenSSF and LF Europe, explores key findings.

Read more ⬇️
🔗 linuxfoundation.org/research/c

#CyberResilience #OpenSource #Security #OpenSSF #LFEurope

Client Info

Server: https://mastodon.social
Version: 2025.04
Repository: https://github.com/cyevgeniy/lmst