Sponsor of the Day:
Jerkmate
https://source.android.com/docs/security
Android Security | Android Open Source Project
security open sourceandroidproject
https://www.eclipse.org/security/
Eclipse Foundation Security | Open Source Safety & Trust
Explore how the Eclipse Foundation ensures open source project security: vulnerability reporting, trusted governance, and proactive risk management across 400+...
security open sourceeclipse foundationsafety trust
https://www.blackduck.com:443/
Application Security | Open Source Security | SAST/DAST/SCA Tools | Black Duck
Black Duck helps organizations secure their software supply chain by providing deep visibility into open source components, licenses, and vulnerabilities....
security open sourcesast dast scatools black duckapplication
https://sigma-star.at/
sigma star gmbh | The security & open source experts
Security, engineering, training: During the past decades sigma star has delivered various solutions for numerous companies. What can we do for you? Find out!
security open sourcesigma stargmbhexperts
https://www.blackduck.com/
Application Security | Open Source Security | SAST/DAST/SCA Tools | Black Duck
Black Duck helps organizations secure their software supply chain by providing deep visibility into open source components, licenses, and vulnerabilities....
security open sourcesast dast scatools black duckapplication
https://www.activestate.com/resources/webinars/outsourcing-open-source-pains/
Outsourcing Open Source Supply Chain Security
Nov 21, 2024 - Learn how outsourcing your open source maintenance can reclaim dev resources, keep you up-to-date and ensure software supply chain security.
open source supplychain securityoutsourcing
https://opensourcesecuritypodcast.libsyn.com/2020/05
Open Source Security
Open Source Security is a media project to help showcase and educate on open source security. Our goal is to give the community a platform educate both...
open source security
https://source.android.com/docs/whatsnew/latest-security-bulletins
Latest security bulletin | Android Open Source Project
android open sourcelatest securitybulletinproject
https://libraries.io/conda
conda - Libraries.io - security & maintenance data for open source software
A detailed listing of the most popular, recently updated and most watched conda packages online
libraries io securityopen source softwaremaintenance dataconda
https://www.helpnetsecurity.com/2025/11/26/deepteam-open-source-llm-red-teaming-framework/
DeepTeam: Open-source LLM red teaming framework - Help Net Security
DeepTeam is an open-source LLM red teaming framework that simulates attacks, detects vulnerabilities, adds guardrails to secure AI systems.
open source llmred teamingframeworkhelpsecurity
https://www.kusari.dev/learning-center/openssf
OpenSSF, the Open Source Security Foundation | Kusari®
What is OpenSSF, the Open Source Security Foundation? Everything you need to know, here at Kusari
open source securityopenssffoundation
https://evolveum.com/
Evolveum: Leading the Way in Open Source Identity Security
Explore Evolveum's open source identity management and governance platform. Secure your organization's digital identities with midPoint.
open source identityevolveumleadingwaysecurity
https://osseu2024.sched.com/event/1ivbc/keynote-improving-oss-security-through-collaboration-ryan-waite-open-source-strategy-and-incubations-microsoft
Open Source Summit Europe 2024: Keynote: Improving OSS Security Through...
View more about this event at Open Source Summit Europe 2024
open source summiteurope 2024oss securitykeynoteimproving
https://www.anaconda.com/press/ai-shortfalls-and-security-risks-demand-open-source-collaboration-anaconda-finds-in-state-of-data-science-report
AI Shortfalls and Security Risks Demand Open-Source Collaboration, Anaconda Finds in State of Data...
Jul 16, 2025 - Seventh annual survey of data science professionals shows 87% are using AI as much or more than last year, but 43% feel unprepared for its challenges Anaconda...
open source collaborationsecurity risksaishortfallsdemand
https://openssf.org/training/courses/
Free Course: Developing Secure Software (LFD121) – Open Source Security Foundation
developing secure softwareopen source securityfree courselfd121foundation
https://technitium.com/dns/
Technitium DNS Server | An Open Source DNS Server For Privacy & Security
technitium dnsopen sourceprivacy securityserver
https://openssf.org/event/openssf-community-day-europe-2026/
OpenSSF Community Day Europe 2026 – Open Source Security Foundation
openssf community daysource security foundationeurope 2026
https://libraries.io/
Libraries.io - security & maintenance data for open source software
Discover open source packages, modules and frameworks you can use in your code.
libraries io securityopen source softwaremaintenance data
https://openssf.org/resources/publications/
Reports – Open Source Security Foundation
open source securityreportsfoundation
https://opensourcesecuritypodcast.libsyn.com/2026-state-of-the-software-supply-chain-with-brian-fox
Open Source Security: 2026 State of the Software Supply Chain with Brian Fox
Josh chats with Brian Fox from Sonatype about their 2026 State of the Software Supply Chain report. Most of the number continue to grow at alarming rates, but...
open source securitysoftware supply chain2026 statebrianfox
https://openssf.org/blog/
Blog – Open Source Security Foundation
open source securityblogfoundation
https://openssf.org/townhalls/
Town Hall Meetings – Open Source Security Foundation
town hall meetingsopen source securityfoundation
https://openssf.org/projects/guac/
GUAC – Open Source Security Foundation
open source securityguacfoundation
https://libraries.io/platforms
Platforms - Libraries.io - security & maintenance data for open source software
All the open source platforms that packages have been published to
libraries io securityopen source softwaremaintenance dataplatforms
https://assured.co.uk/2025/why-irresponsible-users-put-open-source-security-on-shaky-ground/
Why Irresponsible Users Put Open Source Security on Shaky Ground • Assured
Oct 28, 2025 - Why Irresponsible Users Put Open Source Security on Shaky Ground - Danny Bradbury explains why more money must be diverted to maintainers and infrastructure
open source securityshaky groundirresponsibleusersput
https://openssf.org/newsletter/2026/03/26/openssf-newsletter-march-2026/
OpenSSF Newsletter – March 2026 – Open Source Security Foundation
march 2026 opensource security foundationopenssf newsletter
https://openssf.org/projects/security-insights/
Security Insights – Open Source Security Foundation
open source foundationsecurity insights
https://openssf.org/projects/best-practices-badge/
Best Practices Badge – Open Source Security Foundation
open source securitybest practicesbadgefoundation
https://www.harness.io:443/resources/software-supply-chain-security-more-than-open-source
Software Supply Chain Security: More Than Open Source
In this OnDemand session, you'll discover why addressing open source vulnerabilities is just the first step in securing your software supply chain. We'll...
software supply chainopen sourcesecurity
https://opensrcsec.com/careers
Open Source Security, Inc.
Open Source Security, Inc is the industry leader in compiler and OS-based security defenses. It develops and maintains grsecurity, a higher-assurance drop-in...
open source securityinc
https://openssf.org/blog/2025/06/13/case-study-ostif-improves-security-posture-of-critical-open-source-projects-through-openssf-membership/
Case Study: OSTIF Improves Security Posture of Critical Open Source Projects Through OpenSSF...
critical open sourcecase studyimproves securityostifposture
https://www.anaconda.com/guides/open-source-security
Open-Source Security: Risks, Benefits, and Best Practices | Anaconda
Jul 14, 2025 - Explore the complexities of open-source security, including risks, benefits, and strategies to safeguard your software supply chain against vulnerabilities.
open source securityrisks benefitsbest practicesanaconda
https://source.android.com/docs/security/bulletin/2024-12-01
Android Security Bulletin December 2024 | Android Open Source Project
2024 open sourceandroid securitybulletindecemberproject
https://libraries.io/languages
Languages - Libraries.io - security & maintenance data for open source software
All the programming languages that packages have been written in.
libraries io securityopen source softwaremaintenance datalanguages
https://openssf.org/groups/bear/
Belonging, Empowerment, Allyship, and Representation – Open Source Security Foundation
open source securitybelongingempowermentallyshiprepresentation
https://www.linuxfoundation.org/press/open-source-usage-trends-and-security-challenges-revealed-in-new-study
Open Source Usage Trends and Security Challenges Revealed in New Study
Dec 4, 2024 - Open Source Usage Trends and Security Challenges Revealed in New Census III Report by Linux Foundation and Laboratory for Innovation Science at Harvard
open sourceusage trendssecurity challengesnew studyrevealed
https://openssf.org/category/guest-blog/
Guest Blog – Open Source Security Foundation
open source securityguest blogfoundation
https://blog.google/innovation-and-ai/technology/safety-security/ai-powered-open-source-security/
New investments in AI-powered open source security
Mar 17, 2026 - Google is making new investments, building new tools and developing code security to improve open source security.
open source securitynew investmentsai powered
https://alpha-omega.dev/blog/case-study-from-phishing-to-fast-response-how-alpha-omega-enabled-a-cross-ecosystem-security-super-team/
Open Source Security Case Study: Phishing & Fast Response | Alpha-Omega
Learn how Alpha-Omega helped the Rust Foundation mitigate coordinated phishing attacks through cross-ecosystem collaboration and shared threat intelligence.
open source securitycase studyfast responsealpha omegaphishing
https://openssf.org/about/tac/technical-initiative-funding/
Technical Initiative Funding – Open Source Security Foundation
open source securityinitiative fundingtechnicalfoundation
https://opensource.org/blog/improving-open-source-security-with-the-new-github-secure-open-source-fund
Improving Open Source security with the new GitHub Secure Open Source Fund - Open Source Initiative
Dec 13, 2024 - Launched with a $1.25 million commitment from partners, the GitHub Secure Open Source Fund is designed to address a critical issue: the often-overlooked...
open source securitynew githubfund initiativeimprovingsecure
https://openssf.org/blog/2025/09/16/new-openssf-guidance-on-ai-code-assistant-instructions/
New OpenSSF Guidance on AI Code Assistant Instructions – Open Source Security Foundation
ai code assistantopen source securitynewopenssfguidance
https://opensourcesecuritypodcast.libsyn.com/2017/10
Open Source Security
Open Source Security is a media project to help showcase and educate on open source security. Our goal is to give the community a platform educate both...
open source security
https://openssf.org/groups/supply-chain-integrity/
Supply Chain Integrity – Open Source Security Foundation
supply chain integrityopen source securityfoundation
https://support.hcl-software.com/community?id=community_blog&sys_id=4cd4383f3bcb26d828f8f547f4e45af6
HCL HCL PSIRT blog - Security Bulletin: Multiple vulnerabilities in open source components affect...
HCL PSIRT blog - Commerce PSIRTs - Summary Multiple vulnerabilities in open source components affect HCL Commerce 9.1.0 - 9.1.18.1. Vulnerability
open source componentsblog securitymultiple vulnerabilitieshclpsirt
https://openssf.org/projects/sbomit/
SBOMit – Open Source Security Foundation
open source securityfoundation
https://www.herodevs.com/solutions/government
Government - Security Support for EOL Open Source | HeroDevs
Security support for end-of-life open source software used by the government industry. Never-Ending Support (NES) from HeroDevs keeps your systems secure,...
eol open sourcegovernment securitysupportherodevs
https://opensourcesecurity.io/feeds/
Media | Open Source Security
Jan 1, 1 - RSS iTunes Spotify YouTube
open source securitymedia
https://openssf.org/resources/improving-risk-management-decisions-with-sbom-data/
Improving Risk Management Decisions with SBOM Data – Open Source Security Foundation
open source securityrisk managementsbom dataimprovingdecisions
https://openssf.org/projects/osps-baseline/
OSPS Baseline – Open Source Security Foundation
open source securitybaselinefoundation
https://source.android.com/docs/security/enhancements
Security enhancements | Android Open Source Project
android open sourcesecurity enhancementsproject
https://www.securitynewspaper.com/2025/07/23/how-to-use-googles-oss-rebuild-a-new-open-source-software-supply-chain-security-tool/
How to Use Google’s OSS Rebuild: A New Open Source Software Supply Chain Security Tool –...
new open sourcesoftware supply chainsecurity tooluseoss
https://openssf.org/blog/2025/06/06/from-sandbox-to-incubating-gittufs-next-step-in-open-source-security/
From Sandbox to Incubating: gittuf’s Next Step in Open Source Security – Open Source Security...
open source securitynext stepsandboxincubating
https://app.safedep.io/auth
SafeDep | Open Source Software Supply Chain Security Platform
Welcome to SafeDep. Onboard to SafeDep cloud, generate authentication credentials and access platform APIs
open source softwaresupply chain securitysafedepplatform
https://www.seal.security/product
Fix Open Source CVEs Without Breaking Your Stack | Seal Security
Seal Security automatically patches open-source CVEs without upgrades or workflow disruptions, delivering end-to-end protection with audit-ready fixes.
fix openwithout breakingseal securitysourcecves
https://openssf.org/our-events/category/upcoming-cfps/list/?eventDisplay=past
Past Events from March 8, 2024 – May 10, 2023 › Upcoming CFPs › – Open Source Security Foundation
march 8 2024may 10 2023open source securitypast eventsupcoming
https://openssf.org/event/openssf-community-day-korea/
OpenSSF Community Day Korea – Open Source Security Foundation
openssf community daysource security foundationkorea
https://libraries.io/npm/typescript
typescript 6.0.3 on npm - Libraries.io - security & maintenance data for open source software
TypeScript is a language for application scale JavaScript development - 6.0.3 - a TypeScript package on npm
typescript 6 0npm libraries iosecurity maintenance dataopen source software3
https://accounts.eclipse.org/mailing-list/vostack-security
Mailing List: vostack-security (1 subscriber) | Eclipse - The Eclipse Foundation open source...
1 subscriber eclipsefoundation open sourcemailing listvostacksecurity
https://securitylab.github.com/
GitHub Security Lab | Securing open source software, together.
Securing open source software, together.
securing open sourcegithub securitylabsoftwaretogether
https://3mdeb.com/open-source-software/
Open Source Software | Enhanced software performance and security.
open source softwareenhanced performancesecurity
https://www.paloaltonetworks.com/blog/cloud-security/checkov-2-deepening-open-source-iac-security/
Announcing Checkov 2.0: Deepening Open Source IaC Security
Oct 21, 2023 - Checkov 2.0 is a graph-based, open source IaC security tool for environments with complex dependencies across resources and modules.
2 0open sourceiac securityannouncingcheckov
https://opensource.com/article/21/7/open-source-news
Open source sustainable cities, AI on Arduino, supply chain security, and more | Opensource.com
Open source made it into a lot of news headlines last month. Read on to learn about some of the major advances.
supply chain securityopen sourcesustainable citiesarduinoopensource
https://www.heeler.com/resource/introducing-fix-first-a-new-model-for-open-source-security
Introducing Fix-First: A New Model for Open Source Security | Blog - Heeler
open source securityfix firstnew modelintroducingblog
https://openssf.org/soss-vision-brief/
Secure Open Source Software Vision Brief 2023 – Open Source Security Foundation
secure open sourcesoftware visionsecurity foundationbrief2023
https://libraries.io/npm/byo-skill
byo-skill 0.2.0 on npm - Libraries.io - security & maintenance data for open source software
Agent Skill (agentskills.io spec) teaching Cursor / Claude Code / Codex / Copilot / Goose / any SKILL.md-aware AI how to integrate BYO (bring-your-own-keys) ...
npm libraries iosecurity maintenance dataopen source software0 2byo
https://owasp.org/donate/?reponame=www-project-cheat-sheets&title=OWASP+Cheat+Sheet+Series
Donate to Open Source Security Projects | OWASP Foundation
Donate to Open Source Security Projects on the main website for The OWASP Foundation. OWASP is a nonprofit foundation that works to improve the security of...
open source securityprojects owasp foundationdonate
https://openssf.org/blog/2023/09/14/openssf-releases-source-code-management-best-practices-guide/?hsLang=en
OpenSSF Releases Source Code Management Best Practices Guide – Open Source Security Foundation
source code managementbest practices guideopen securityopenssfreleases
https://libraries.io/pypi/pandas/3.0.1
pandas 3.0.1 on PyPI - Libraries.io - security & maintenance data for open source software
Powerful data structures for data analysis, time series, and statistics - 3.0.1 - a Python package on PyPI
pandas 3 0pypi libraries iosecurity maintenance dataopen source software1
https://source.android.com/docs/security/bulletin
Android Security and Update Bulletins | Android Open Source Project
open source projectandroid securityupdate bulletins
https://rubycentral.org/news/ruby-central-joins-eclipse-foundation-working-group-for-open-source-security-compliance/
Ruby Central Joins Eclipse Foundation Working Group for Open Source Security & Compliance
Nov 7, 2024 - We’re excited to announce that Ruby Central has become a member of the Eclipse Foundation's newly launched Open Regulatory Compliance (ORC) Working Group. This...
open source securityruby centraleclipse foundationworking groupjoins
https://openssf.org/category/policy/cra/
EU Cyber Resilience Act – Open Source Security Foundation
eu cyber resilienceopen source securityactfoundation
https://owasp.org/donate/?reponame=www-project-application-security-verification-standard&title=OWASP+Application+Security+Verification+Standard+%28ASVS%29
Donate to Open Source Security Projects | OWASP Foundation
Donate to Open Source Security Projects on the main website for The OWASP Foundation. OWASP is a nonprofit foundation that works to improve the security of...
open source securityprojects owasp foundationdonate
https://www.helpnetsecurity.com/2024/03/14/mobsf-open-source-mobile-security-framework/
MobSF: Open-source security research platform for mobile apps - Help Net Security
Mar 25, 2024 - The Mobile Security Framework (MobSF) is an open-source research platform for mobile application security, encompassing Android, iOS.
open source securitymobile apps helpresearch platform
https://openssf.org/membership-inquiries/
Membership Inquiries – Open Source Security Foundation
open source securitymembershipinquiriesfoundation
https://opensourcesecuritypodcast.libsyn.com/2018/11
Open Source Security
Open Source Security is a media project to help showcase and educate on open source security. Our goal is to give the community a platform educate both...
open source security
https://openssf.org/blog/2024/10/24/case-study-kusaris-implementation-of-openssf-tools-and-services/
Case Study: Kusari’s Implementation of OpenSSF Tools and Services – Open Source Security Foundation
open source securitycase studyimplementationopenssftools
https://openssf.org/technical-initiatives/sbom-tools/
SBOM Tools – Open Source Security Foundation
open source securitysbomtoolsfoundation
https://www.timesys.com/security/security-testing-embedded-open-source-systems-creates-stronger-enterprise-security-posture/
Security testing of embedded open source systems creates a stronger enterprise security posture -...
Nov 28, 2023 - Researchers and the technology media are reporting that the average application now contains more open source software components than proprietary code. And...
embedded open sourcesecurity testingsystemscreatesstronger
https://www.linuxfoundation.org/press/linux-foundation-welcomes-new-open-source-projects-from-peraton-labs-to-scale-5g-security
Linux Foundation Welcomes New Open Source Projects from Peraton Labs to Scale 5G Security
Feb 22, 2023 - Peraton Labs, the applied research unit of Peraton, open sources its ProD3 and SEDIMENT network security projects for 5G and IoT under neutral auspices of the...
linux foundation welcomesnew open source5g securityprojectsperaton
https://www.jumpserver.com/blog/secret-management-best-practices-2026
Secrets Management Best Practices for Enterprise Security (2026 Guide) - Open-Source Privileged...
management best practicesenterprise security 2026guide opensecretssource
https://owasp.org/donate/?reponame=www-chapter-belgium&title=OWASP+Belgium
Donate to Open Source Security Projects | OWASP Foundation
Donate to Open Source Security Projects on the main website for The OWASP Foundation. OWASP is a nonprofit foundation that works to improve the security of...
open source securityprojects owasp foundationdonate
https://source.android.com/docs/security/bulletin/xr
Android XR Security Bulletin | Android Open Source Project
open source projectandroid xrsecurity bulletin
https://libraries.io/pypi/kpireport-sql
kpireport-sql 0.1.0 on PyPI - Libraries.io - security & maintenance data for open source software
kpireport-sql - 0.1.0 - a package on PyPI
pypi libraries iosecurity maintenance dataopen source software0 1sql
https://www.blackduck.com/resources/analyst-reports/open-source-security-risk-analysis.html
2026 OSSRA Report: Open Source Security & Risk Analysis
2026 OSSRA: 107% rise in open source vulnerabilities. Discover AI development risks, licensing conflicts, and supply chain security guidance for your...
report open sourcesecurity risk analysis2026