Security Projects

We have thousands of posts on a wide variety of open source and security topics, conveniently organized for searching or just browsing.

Discover Security Projects News

Linux Foundation Addresses Open Source Security

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

The Linux Foundation recently announced that it has launched yet another consortium - this time with the aim of bringing some order to multiple previous efforts to address open source security. The Open Source Security Foundation (OpenSSF) will consolidate the efforts of the Core Infrastructure Initiative and the Open Source Security Coalition previously launched by GitHub.

Linux Developers May Discuss Allowing Rust Code Within The Kernel

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

Nick Desaulniers, a Google engineer, is looking to discuss at this year's Linux Plumbers Conference the possibility of allowing in-tree Rust language support within the Linux kernel. Because of its memory safety guarantees and other security benefits, many argue that Rust should play a larger role at lower-levels of the system. What are your thoughts?

Why CII best practices gold badges are important

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

“A CII Best Practices badge, especially a gold badge, shows that an OSS project has implemented a large number of good practices to keep the project sustainable, counter vulnerabilities from entering their software, and address vulnerabilities when found.” – David A. Wheeler, Director of Open Source Supply Chain Security