OpenSSF Newsletter – September 2026

Imported from official source

AI Cybersecurity Classified by Officially

#71 – S3E23 Navigating the New Era: The EU Cyber Resilience Act Explained with Madalin Neag
OpenSSF EU Policy Advisor Madalin Neag demystifies the EU Cyber Resilience Act (CRA). Learn how the CRA establishes a horizontal cybersecurity baseline for digital products. Listen now

Join Azure CTO and OpenSSF Board Chair Mark Russinovich as he discusses AI’s impact on software engineering, supply chain security, and vulnerability management. Listen now

In this episode of What’s in the SOSS, ActiveState CEO Abby Kearns breaks down the rapidly evolving open source security landscape. Listen now

  • Contribute in Prague: Project maintainers and contributors can lead 30-minute Lightning Learning sessions during OpenSSF Community Day Europe on October 6. Sign up for a session.
  • Volunteers at Open Source Summit Europe can take short shifts at the OpenSSF booth for demos and questions. Sign up for a booth shift.
  • OpenSSF Scorecard migrated its public infrastructure with AboutCode to AWS and published the scorecard-infra repository. Community-hosted Allstar ended in August; users should move to self-hosted Allstar.
  • The TAC approved the sandbox application for a new SBOM & VEX Working Group. Read the application.
  • OpenBao released v2.7.0 beta with external KMS-backed keys, post-quantum support, and PostgreSQL read scalability; v2.6.2 includes security fixes. Beta release; stable release.
  • gittuf v0.16.0 adds SHA-256 repository support, storage and TUI improvements, and key inspection tools. Release notes.
  • Zarf v0.85.0 adds v1beta1 component config publishing, OCI source prefixing, and Helm retry controls. Release notes.
  • Protobom v0.6.0 expanded SPDX support and serialization; v0.6.1 followed. v0.6.0; v0.6.1.
  • Gemara released go-gemara v0.10.0 and established repositories for GRC Store capabilities. Explore Gemara.
  • This is an extract. The publication continues at the source.

    Read the original at the source: https://openssf.org/newsletter/2026/09/30/openssf-newsletter-september-2026/

    Officially imported this from Open Source Security Foundation’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.

    Provenance

    Organization
    Open Source Security Foundation — imported from official source
    Official source
    https://openssf.org/feed/ RSS
    Imported
    September 30, 2026 12:00
    Versions
    1 recorded
    Identity
    https://openssf.org/?p=11909

    Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.