🦜 Open Source Security Foundation
@openssf.org@rss-parrot.net
I'm an automated parrot! I relay a website's RSS feed to the Fediverse. Every time a new post appears in the feed, I toot about it. Follow me to get all new posts in your Mastodon timeline!
Brought to you by the RSS Parrot.
---
Linux Foundation Projects
Your feed and you don't want it here? Just
e-mail the birb.
We’re In: Enterprise Commitment to Sustainable Package Registries
https://openssf.org/blog/2026/09/16/were-in-enterprise-commitment-to-sustainable-package-registries/
Published: September 16, 2026 08:17
The OpenSSF Governing Board and major tech enterprises are partnering to support sustainable funding models for public package registries. This commitment aims to secure and scale the global software supply chain while ensuring open source stays free and…
Grow CRA Readiness: Find Your Path Through the European Union Cyber Resilience Act
https://openssf.org/blog/2026/09/15/grow-cra-readiness-find-your-path-through-the-european-union-cyber-resilience-act/
Published: September 15, 2026 16:11
Discover how the EU Cyber Resilience Act (CRA) impacts your open source work. OpenSSF’s new community garden user journey helps maintainers, software stewards, and manufacturers navigate legal requirements and find essential tools for CRA readiness.
Empowering Open Source Security with Scalable Infrastructure
https://openssf.org/blog/2026/09/14/empowering-open-source-security-with-scalable-infrastructure/
Published: September 14, 2026 19:15
How can open source projects maintain secure infrastructure without financial strain? OpenSSF Premier Member, Amazon Web Services (AWS) addresses this by providing critical funding and scalable compute resources.
A Community Guide to the EU CRA September 11 Deadline for Manufacturers
https://openssf.org/blog/2026/09/11/a-community-guide-to-the-eu-cra-september-11-deadline-for-manufacturers/
Published: September 11, 2026 16:04
The EU Cyber Resilience Act (CRA) introduces new cybersecurity requirements for products with digital elements. Discover what the September 11, 2026 reporting deadline for manufacturers means for the open source community, maintainers, and stewards, and…
Tech Talk Recap: A Practitioner’s Guide to CRA Readiness
https://openssf.org/blog/2026/09/10/tech-talk-recap-a-practitioners-guide-to-cra-readiness/
Published: September 10, 2026 19:39
The EU Cyber Resilience Act is no longer a distant regulatory concept. With vulnerability reporting obligations to ENISA arriving on September 11 and the full weight of the law landing in December 2027, open source maintainers, foundations, and the…
Open by Default After AI: The GDS Guidance and the Enforcement Question
https://openssf.org/blog/2026/09/10/open-by-default-after-ai-the-gds-guidance-and-the-enforcement-question/
Published: September 10, 2026 08:20
What’s in the SOSS? Podcast #72 – S3E24 Balancing AI’s Double-Edged Sword: Software Engineering, Unlearning, and Ecosystem Sustainability with Mark Russinovich
https://openssf.org/podcast/2026/09/08/whats-in-the-soss-podcast-72-s3e24-balancing-ais-double-edged-sword-software-engineering-unlearning-and-ecosystem-sustainability-with-mark-russinovich/
Published: September 8, 2026 13:51
Join Azure CTO and OpenSSF Chair Mark Russinovich as he discusses AI's impact on software engineering, supply chain security, and vulnerability management.
OpenSSF at Hacker Summer Camp 2026: Black Hat & DEF CON Highlights and Recap
https://openssf.org/blog/2026/09/04/openssf-at-hacker-summer-camp-2026-black-hat-def-con-highlights-and-recap/
Published: September 4, 2026 20:23
Las Vegas was once again the center of the cybersecurity universe from August 1–9 for Black Hat and DEF CON 2026. The Open Source Security Foundation (OpenSSF) had a major presence throughout the week, engaging with security leaders, project maintainers,…
What’s in the SOSS? Podcast #71 – S3E23 Navigating the New Era: The EU Cyber Resilience Act Explained with Madalin Neag
https://openssf.org/podcast/2026/09/01/whats-in-the-soss-podcast-71-s3e23-navigating-the-new-era-the-eu-cyber-resilience-act-explained-with-madalin-neag/
Published: September 1, 2026 13:16
In this episode of What’s in the SOSS, host Sally Cooper and OpenSSF EU Policy Advisor Madalin Neag demystify the EU Cyber Resilience Act (CRA). Learn how the CRA establishes a new cybersecurity baseline and what it means for open source maintainers,…
OpenSSF Newsletter – August 2026
https://openssf.org/newsletter/2026/08/31/openssf-newsletter-august-2026/
Published: August 31, 2026 18:22
The August 2026 OpenSSF Newsletter spotlights a wave of CRA readiness content, from a new Ericsson case study to a four-part podcast run on compliance.