Skip to main content
Open Source Security Foundation

Open Source Security Foundation

The Open Source Security Foundation (OpenSSF) is a cross-industry organization at the Linux Foundation that brings together the industry’s most important open source security initiatives and the individuals and companies that support them. The OpenSSF is committed to collaboration and working both upstream and with existing communities to advance open source security for all.www.openssf.org

Search complete. 4 mentions across 3 episodes found for "Open Source Security Foundation".

Sep 9, 2026

Artificial IntelligenceNARRATOR
7:57
This is where artifact signing and SLSA, Supply Chain Levels for Software Artifacts, come in.
Artificial IntelligenceNARRATOR
8:03
SLSA, originally developed at Google and now maintained by the OpenSSF, reached its one zero specification in April 2023, defining a tiered ladder of build integrity requirements from, "The build has some provenance," up to, "The signing happens inside an isolated tamper-resistant build platform that even a malicious insider can't forge." Sigstore is the toolchain most current SLSA adoption leans on, and its keyless signing model is worth understanding because it directly answers the failure mode SolarWinds exposed.
Artificial IntelligenceNARRATOR
8:36
Instead of a long-lived private key that becomes a single point of catastrophic failure if stolen, a C job authenticates via OIDC, gets a short-lived certificate from Sigstore's Fulcio, signs the artifact with, and the signing event is recorded permanently in Sigstore's public record transparency log.
Artificial IntelligenceNARRATOR
8:53
A real signing command looks like no key management, no rotation schedule.
Kaslin FieldsHOST
1:04
Platform teams still running 1.34 are encouraged to review their upgrade paths and begin planning transitions.
Kaslin FieldsHOST
1:11
BombHort has joined the Open Source Security Foundation, or OpenSSF.
Kaslin FieldsHOST
1:16
BombHort is a Kubernetes-native platform built to ingest, normalize, and visualize SBOMs at scale, giving security, compliance, and engineering teams centralized visibility into their software supply chain.
Kaslin FieldsHOST
1:29
In a retrospective published on Google's open source blog, Google shared that approximately 10% of Alphabet's developer workforce is actively contributing to open source software, supporting foundational industry standards like Kubernetes, Envoy, and VLLM.
Tracy RaganGUEST
5:09
And I've been in governance now around that for quite some time.
Tracy RaganGUEST
5:12
I've sat on the boards of the Continuous Delivery Foundation, both the governing and technical oversight committees, as well as the Open Source Security Foundation.
Tracy RaganGUEST
5:21
So yeah, I've been doing this for a while.
Tracy RaganGUEST
5:23
I love the space.

15 MINS LATER

Mitch AshleyHOST
20:11
It's interesting.
Tracy RaganGUEST
20:13
And maybe the solution sometime is to go back go back a package version or two, right? As opposed to going forward because you go forward and you introduce new problems.
Tracy RaganGUEST
20:24
So we haven't figured out how to make open source safe yet, even though we have open, you know, I'm on the tack of the Open Source Security Foundation.
Tracy RaganGUEST
20:34
It requires more than a $12 million investment to Alpha Omega, right? To fix this problem.

We value your privacy

We use cookies to understand how you use our platform and to improve your experience. Click “Accept All” to consent, or “Decline non-essential” to opt out of non-essential cookies. Read our Privacy Policy.