Hello, Linux Foundation members and readers! Here’s what we at the Open Source Security Foundation (OpenSSF) worked on during the past quarter:
On September 18, 2023, we hosted OpenSSF Day Europe at the Open Source Summit Europe in Bilbao, Spain. Throughout the day, we hosted several sessions around the state of open source software security, discussing current initiatives and what’s next.
The OpenSSF brought together US Government (USG) officials from the National Security Council (NSC), Office of the National Cyber Director (ONCD), and the Cybersecurity and Infrastructure Security Agency (CISA), among others with industry leaders at the Secure Open Source Software (SOSS) Summit 2023. Participants at the Summit discussed the security challenges for the consumption of OSS in critical infrastructure sectors and beyond and highlighted the shared responsibility needed to ensure the resilience of OSS in critical infrastructure.
We welcomed six new members from leading technology firms to the OpenSSF. New general members include Mend.io, RTX, Shopify, SlimAI, and Stacklok. A new associate member, the Rust Foundation, also joined. Technical communities continue to prioritize investment in open source security and recognize the role of supporting and sustaining open source communities in maintaining a healthy, vibrant, and secure open source ecosystem.
The Open Source Security Foundation (OpenSSF) announced at Black Hat 2023 its collaboration with the Defense Advanced Research Projects Agency (DARPA) on the AI Cyber Challenge (AIxCC) – a two-year competition aimed at driving innovation at the nexus of AI and cybersecurity to create a new generation of cybersecurity tools.
We’ve been busy at the OpenSSF, and often share updates with the community on our blog. Here are a few recent posts from our blog that you won’t want to miss. Check them out!
We remain committed to ensuring the open source software ecosystem is secure for all. Explore getting involved in the OpenSSF. This could range from participating in our working groups to joining our Slack or mailing list.
We look forward to working with you to help secure the entire OSS ecosystem!