Open Source Security Foundation
The Open Source Security Foundation (OpenSSF) is a cross-industry organization at the Linux Foundation that brings together the industry’s most important open source security initiatives and the individuals and companies that support them. The OpenSSF is committed to collaboration and working both upstream and with existing communities to advance open source security for all.www.openssf.org
4
MENTIONS
3
EPISODES
3
PODCASTS
Search complete. 4 mentions across 3 episodes found for "Open Source Security Foundation".
Sep 9, 2026
Log4Shell Is Almost Five Years Old. Most Teams Still Can't Answer "What's In Our Software?"
A
7:57Artificial IntelligenceNARRATOR
This is where artifact signing and SLSA, Supply Chain Levels for Software Artifacts, come in.
A
8:03Artificial IntelligenceNARRATOR
SLSA, originally developed at Google and now maintained by the OpenSSF, reached its one zero specification in April 2023, defining a tiered ladder of build integrity requirements from, "The build has some provenance," up to, "The signing happens inside an isolated tamper-resistant build platform that even a malicious insider can't forge." Sigstore is the toolchain most current SLSA adoption leans on, and its keyless signing model is worth understanding because it directly answers the failure mode SolarWinds exposed.
A
8:36Artificial IntelligenceNARRATOR
Instead of a long-lived private key that becomes a single point of catastrophic failure if stolen, a C job authenticates via OIDC, gets a short-lived certificate from Sigstore's Fulcio, signs the artifact with, and the signing event is recorded permanently in Sigstore's public record transparency log.
A
8:53Artificial IntelligenceNARRATOR
A real signing command looks like no key management, no rotation schedule.
Agent Sandbox, with Tim Hockin and Brandon Royal
K
1:04Kaslin FieldsHOST
Platform teams still running 1.34 are encouraged to review their upgrade paths and begin planning transitions.
K
1:11Kaslin FieldsHOST
BombHort has joined the Open Source Security Foundation, or OpenSSF.
K
1:16Kaslin FieldsHOST
BombHort is a Kubernetes-native platform built to ingest, normalize, and visualize SBOMs at scale, giving security, compliance, and engineering teams centralized visibility into their software supply chain.
K
1:29Kaslin FieldsHOST
In a retrospective published on Google's open source blog, Google shared that approximately 10% of Alphabet's developer workforce is actively contributing to open source software, supporting foundational industry standards like Kubernetes, Envoy, and VLLM.
Inside the Mind of an Open Source Innovator with Tracy Ragan | Agents of Dev Episode 36
T
5:09Tracy RaganGUEST
And I've been in governance now around that for quite some time.
T
5:12Tracy RaganGUEST
I've sat on the boards of the Continuous Delivery Foundation, both the governing and technical oversight committees, as well as the Open Source Security Foundation.
T
5:21Tracy RaganGUEST
So yeah, I've been doing this for a while.
T
5:23Tracy RaganGUEST
I love the space.
15 MINS LATER
M
20:11Mitch AshleyHOST
It's interesting.
T
20:13Tracy RaganGUEST
And maybe the solution sometime is to go back go back a package version or two, right? As opposed to going forward because you go forward and you introduce new problems.
T
20:24Tracy RaganGUEST
So we haven't figured out how to make open source safe yet, even though we have open, you know, I'm on the tack of the Open Source Security Foundation.
T
20:34Tracy RaganGUEST
It requires more than a $12 million investment to Alpha Omega, right? To fix this problem.