<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
  <updated>2026-07-25T00:23:36Z</updated>
  <generator>https://nostr.ae</generator>

  <title>Nostr notes by OpenSSF</title>
  <author>
    <name>OpenSSF</name>
  </author>
  <link rel="self" type="application/atom+xml" href="https://nostr.ae/npub1w8zuj6sdg9gxtf9sj836vwfr8n0s6qt5hhe3ymwfgj8pera4zsdsrwukje.rss" />
  <link href="https://nostr.ae/npub1w8zuj6sdg9gxtf9sj836vwfr8n0s6qt5hhe3ymwfgj8pera4zsdsrwukje" />
  <id>https://nostr.ae/npub1w8zuj6sdg9gxtf9sj836vwfr8n0s6qt5hhe3ymwfgj8pera4zsdsrwukje</id>
  <icon>https://cdn.masto.host/sociallfxdev/accounts/avatars/109/876/472/675/308/382/original/e85a00470ec8e28c.png</icon>
  <logo>https://cdn.masto.host/sociallfxdev/accounts/avatars/109/876/472/675/308/382/original/e85a00470ec8e28c.png</logo>




  <entry>
    <id>https://nostr.ae/nevent1qqsykm97ekn93lv8y4c87lf58q4zhlkrw3kgzy2fglh258ptujx4sjczypcutjt2p4q4qedykzg78f3eyv7d7rgpwj7lxynde9zgu8y0k52pk2guw89</id>
    
      <title type="html">Open Infrastructure Is Not Free. Part II is here. 10 trillion ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsykm97ekn93lv8y4c87lf58q4zhlkrw3kgzy2fglh258ptujx4sjczypcutjt2p4q4qedykzg78f3eyv7d7rgpwj7lxynde9zgu8y0k52pk2guw89" />
    <content type="html">
      Open Infrastructure Is Not Free. Part II is here.&lt;br/&gt;&lt;br/&gt;10 trillion open source package downloads in 2026. More than 1 billion per hour. Still running on donations and volunteers.&lt;br/&gt;&lt;br/&gt;AI is accelerating consumption and attacks. Registry leaders have formed the Sustaining Package Registries WG to change that.&lt;br/&gt;&lt;br/&gt;Read Part II: &lt;a href=&#34;https://openssf.org/blog/2026/05/06/open-infrastructure-is-not-free-part-ii-the-hidden-cost-of-running-package-registries/&#34;&gt;https://openssf.org/blog/2026/05/06/open-infrastructure-is-not-free-part-ii-the-hidden-cost-of-running-package-registries/&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;#PreserveOpenSource #FreeSoftwareIsntFree&lt;br/&gt; &lt;img src=&#34;https://cdn.masto.host/sociallfxdev/media_attachments/files/116/527/088/872/001/591/original/ad7e1576893b6cb2.jpg&#34;&gt; &lt;br/&gt;
    </content>
    <updated>2026-05-06T10:11:17Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsd9cd6kq9tv67qjh4hz22c65ydaj9xc2yg2alk8rtaum244xcwyfczypcutjt2p4q4qedykzg78f3eyv7d7rgpwj7lxynde9zgu8y0k52pk6feqnu</id>
    
      <title type="html">How do you prove your open source project is secure in minutes, ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsd9cd6kq9tv67qjh4hz22c65ydaj9xc2yg2alk8rtaum244xcwyfczypcutjt2p4q4qedykzg78f3eyv7d7rgpwj7lxynde9zgu8y0k52pk6feqnu" />
    <content type="html">
      How do you prove your open source project is secure in minutes, not weeks?&lt;br/&gt;&lt;br/&gt;#GUAC did it using #OpenSSF’s #OSPSBaseline &#43; #LFX Insights.&lt;br/&gt;&lt;br/&gt;Faster trust. Less friction. More time to build!&lt;br/&gt;&lt;br/&gt;Read the full story: &lt;a href=&#34;https://openssf.org/blog/2025/08/14/case-study-how-lfx-insights-and-osps-baseline-validated-guacs-security-in-under-an-hour/&#34;&gt;https://openssf.org/blog/2025/08/14/case-study-how-lfx-insights-and-osps-baseline-validated-guacs-security-in-under-an-hour/&lt;/a&gt;&lt;br/&gt; &lt;img src=&#34;https://cdn.masto.host/sociallfxdev/media_attachments/files/115/029/005/656/952/145/original/01ff9ddc15b8fde0.png&#34;&gt; &lt;br/&gt;
    </content>
    <updated>2025-08-14T20:29:05Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqs9xmm4hlwlsh4me8fzjq758e7vz9grd8llx3j8p3wp7q2js5fz2rgzypcutjt2p4q4qedykzg78f3eyv7d7rgpwj7lxynde9zgu8y0k52pk6qd7hx</id>
    
      <title type="html">With the closure of the CISA #SBOM Working Group, we&amp;#39;re ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqs9xmm4hlwlsh4me8fzjq758e7vz9grd8llx3j8p3wp7q2js5fz2rgzypcutjt2p4q4qedykzg78f3eyv7d7rgpwj7lxynde9zgu8y0k52pk6qd7hx" />
    <content type="html">
      With the closure of the CISA #SBOM Working Group, we&amp;#39;re picking up the torch &lt;br/&gt;Join us starting Monday, August 11 at 11am ET for an open, cross-industry discussion on SBOMs, continuing the momentum right here in our community.&lt;br/&gt;&lt;br/&gt;Check out the OpenSSF Community Calendar for meeting details: &lt;a href=&#34;https://openssf.org/getinvolved/&#34;&gt;https://openssf.org/getinvolved/&lt;/a&gt;&lt;br/&gt; &lt;img src=&#34;https://cdn.masto.host/sociallfxdev/media_attachments/files/114/978/520/111/609/097/original/fb9ca9fbb7eaca4a.png&#34;&gt; &lt;br/&gt;
    </content>
    <updated>2025-08-05T22:31:14Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsdkqzejpxpqdmsp8te0kg83k0h0yc728jy8lw5czhl0v9ns8hwg6szypcutjt2p4q4qedykzg78f3eyv7d7rgpwj7lxynde9zgu8y0k52pkk28zpg</id>
    
      <title type="html">🎉 Today we celebrate #OpenSSFCommunity Day NA 2025, welcoming ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsdkqzejpxpqdmsp8te0kg83k0h0yc728jy8lw5czhl0v9ns8hwg6szypcutjt2p4q4qedykzg78f3eyv7d7rgpwj7lxynde9zgu8y0k52pkk28zpg" />
    <content type="html">
      🎉 Today we celebrate #OpenSSFCommunity Day NA 2025, welcoming six new member organizations and honoring incredible contributors with the Golden Egg Awards 🥚.&lt;br/&gt;&lt;br/&gt;Read the full update:&lt;br/&gt;🌐 &lt;a href=&#34;https://openssf.org/blog/2025/06/26/openssf-welcomes-new-members-and-presents-golden-egg-award&#34;&gt;https://openssf.org/blog/2025/06/26/openssf-welcomes-new-members-and-presents-golden-egg-award&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;#OpenSSF #OpenSource #SoftwareSecurity #OSS&lt;br/&gt; &lt;img src=&#34;https://cdn.masto.host/sociallfxdev/media_attachments/files/114/749/930/057/062/694/original/ec1ba92365f01b9a.png&#34;&gt; &lt;br/&gt;
    </content>
    <updated>2025-06-26T14:01:01Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsxz8jucj2rnu2y57056du7fp0jza3j28plwre7xncndxtnlwg7e0gzypcutjt2p4q4qedykzg78f3eyv7d7rgpwj7lxynde9zgu8y0k52pky8mj6t</id>
    
      <title type="html">🌍🔒 The Linux Foundation Europe and #OpenSSF communities are ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsxz8jucj2rnu2y57056du7fp0jza3j28plwre7xncndxtnlwg7e0gzypcutjt2p4q4qedykzg78f3eyv7d7rgpwj7lxynde9zgu8y0k52pky8mj6t" />
    <content type="html">
      🌍🔒 The Linux Foundation Europe and #OpenSSF communities are teaming up to help open source maintainers, manufacturers, and stewards navigate the EU Cyber Resilience Act (#CRA) and global cybersecurity regulations.&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://openssf.org/press-release/2025/01/31/linux-foundation-europe-and-openssf-launch-initiative-to-prepare-maintainers-manufacturers-and-open-source-stewards-for-global-cybersecurity-legislation/&#34;&gt;https://openssf.org/press-release/2025/01/31/linux-foundation-europe-and-openssf-launch-initiative-to-prepare-maintainers-manufacturers-and-open-source-stewards-for-global-cybersecurity-legislation/&lt;/a&gt;&lt;br/&gt; &lt;img src=&#34;https://cdn.masto.host/sociallfxdev/media_attachments/files/113/923/484/763/035/623/original/22a26413a4f65150.png&#34;&gt; &lt;br/&gt;
    </content>
    <updated>2025-01-31T14:41:15Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqs07ep7v9fytg32dmcxe5pyn7s48rfymkrdghyhp4rql9qy7g3k4aqzypcutjt2p4q4qedykzg78f3eyv7d7rgpwj7lxynde9zgu8y0k52pkpzxfh5</id>
    
      <title type="html">🚨 Breaking: The OpenSSF welcomes Honda Motor Co., Ltd. and ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqs07ep7v9fytg32dmcxe5pyn7s48rfymkrdghyhp4rql9qy7g3k4aqzypcutjt2p4q4qedykzg78f3eyv7d7rgpwj7lxynde9zgu8y0k52pkpzxfh5" />
    <content type="html">
      🚨 Breaking: The OpenSSF welcomes Honda Motor Co., Ltd. and Guidewire Software, Inc. as new members!&lt;br/&gt;&lt;br/&gt;From Delhi, we’re celebrating #SOSSCommunityDay India, advancing collaboration and innovation to secure open source software.&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://openssf.org/press-release/2024/12/09/in-the-face-of-mounting-regulatory-oversight-honda-and-guidewire-join-industry-leaders-securing-software-development-at-the-open-source-security-foundation-openssf/&#34;&gt;https://openssf.org/press-release/2024/12/09/in-the-face-of-mounting-regulatory-oversight-honda-and-guidewire-join-industry-leaders-securing-software-development-at-the-open-source-security-foundation-openssf/&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;#OpenSSF #OpenSourceSecurity&lt;br/&gt; &lt;img src=&#34;https://cdn.masto.host/sociallfxdev/media_attachments/files/113/625/752/489/782/413/original/bce985445eb2f650.png&#34;&gt; &lt;br/&gt;
    </content>
    <updated>2024-12-10T04:12:07Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsr08ptjecwtyykd4gs0crpayq6mafg2jhjxhvpnxznmsj679f3pxgzypcutjt2p4q4qedykzg78f3eyv7d7rgpwj7lxynde9zgu8y0k52pk5d4hv8</id>
    
      <title type="html">ICYMI: What’s in the SOSS? Podcast 20 🎙️ Before the ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsr08ptjecwtyykd4gs0crpayq6mafg2jhjxhvpnxznmsj679f3pxgzypcutjt2p4q4qedykzg78f3eyv7d7rgpwj7lxynde9zgu8y0k52pk5d4hv8" />
    <content type="html">
      ICYMI: What’s in the SOSS? Podcast 20 🎙️&lt;br/&gt;&lt;br/&gt;Before the Thanksgiving break, we released an insightful episode featuring Jack Cable of CISA and Zach Steindler of GitHub, diving deep into package repository security. 🚀&lt;br/&gt;&lt;br/&gt;🎧 Tune in now: &lt;a href=&#34;https://openssf.org/podcast/2024/11/26/whats-in-the-soss-podcast-20-jack-cable-of-cisa-and-zach-steindler-of-github-dig-into-package-repository-security/&#34;&gt;https://openssf.org/podcast/2024/11/26/whats-in-the-soss-podcast-20-jack-cable-of-cisa-and-zach-steindler-of-github-dig-into-package-repository-security/&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;#OpenSource&lt;br/&gt; &lt;img src=&#34;https://cdn.masto.host/sociallfxdev/media_attachments/files/113/600/723/670/821/753/original/6186cdc8610a0da2.png&#34;&gt; &lt;br/&gt;
    </content>
    <updated>2024-12-05T14:38:55Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqs256vzh2zk2ttfprzln83zy59k8x5lm5atngam9sqxgqyd6ze2uegzypcutjt2p4q4qedykzg78f3eyv7d7rgpwj7lxynde9zgu8y0k52pk7ff99a</id>
    
      <title type="html">📢 The @npub1nsd…7jsu with Harvard&amp;#39;s Laboratory for ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqs256vzh2zk2ttfprzln83zy59k8x5lm5atngam9sqxgqyd6ze2uegzypcutjt2p4q4qedykzg78f3eyv7d7rgpwj7lxynde9zgu8y0k52pk7ff99a" />
    <content type="html">
      📢 The &lt;span itemprop=&#34;mentions&#34; itemscope itemtype=&#34;https://schema.org/Person&#34;&gt;&lt;a itemprop=&#34;url&#34; href=&#34;/npub1nsd5eee587lwzxw4sp3562nrg9y0utgmx2xsrewxvj9q36f90eyq8v7jsu&#34; class=&#34;bg-lavender dark:prose:text-neutral-50 dark:text-neutral-50 dark:bg-garnet px-1&#34;&gt;&lt;span&gt;The Linux Foundation&lt;/span&gt; (&lt;span class=&#34;italic&#34;&gt;npub1nsd…7jsu&lt;/span&gt;)&lt;/a&gt;&lt;/span&gt; with Harvard&amp;#39;s Laboratory for Innovation Science, has released Census III of Free and Open Source Software – Application Libraries. 🖥️ Key insights from OpenSSF help reduce FOSS vulnerabilities and secure supply chains. Read more: &lt;a href=&#34;https://openssf.org/press-release/2024/12/04/open-source-usage-trends-and-security-challenges-revealed-in-new-study/&#34;&gt;https://openssf.org/press-release/2024/12/04/open-source-usage-trends-and-security-challenges-revealed-in-new-study/&lt;/a&gt;&lt;br/&gt; &lt;img src=&#34;https://cdn.masto.host/sociallfxdev/media_attachments/files/113/595/356/538/127/122/original/83d5ec30dfb22e00.png&#34;&gt; &lt;br/&gt;
    </content>
    <updated>2024-12-04T15:53:36Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqstf3pa6msa38xxjhs98ztjw5u2nqqms3qm0970a4tdstk0g608xlgzypcutjt2p4q4qedykzg78f3eyv7d7rgpwj7lxynde9zgu8y0k52pkk95fdv</id>
    
      <title type="html">Join us for a FREE webinar with insights from Census III on ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqstf3pa6msa38xxjhs98ztjw5u2nqqms3qm0970a4tdstk0g608xlgzypcutjt2p4q4qedykzg78f3eyv7d7rgpwj7lxynde9zgu8y0k52pkk95fdv" />
    <content type="html">
      Join us for a FREE webinar with insights from Census III on application-level FOSS usage &amp;amp; security on December 5! &lt;br/&gt;📅 Don’t miss this opportunity to learn from top researchers and industry experts.&lt;br/&gt;👉 Register now: &lt;a href=&#34;https://www.linuxfoundation.org/webinars/census-iii-of-free-and-open-source-software-application-libraries?hsLang=en&#34;&gt;https://www.linuxfoundation.org/webinars/census-iii-of-free-and-open-source-software-application-libraries?hsLang=en&lt;/a&gt;&lt;br/&gt; &lt;img src=&#34;https://cdn.masto.host/sociallfxdev/media_attachments/files/113/590/022/951/623/496/original/55e1eca8aff6264d.png&#34;&gt; &lt;br/&gt;
    </content>
    <updated>2024-12-03T17:16:44Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqs2kd9mwwg8asjsjqjl76u6ek30q38zfawdakmev525wprd6as97aszypcutjt2p4q4qedykzg78f3eyv7d7rgpwj7lxynde9zgu8y0k52pk43tdl9</id>
    
      <title type="html">📣 We are excited to announce that OpenSSF is an Ecosystem ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqs2kd9mwwg8asjsjqjl76u6ek30q38zfawdakmev525wprd6as97aszypcutjt2p4q4qedykzg78f3eyv7d7rgpwj7lxynde9zgu8y0k52pk43tdl9" />
    <content type="html">
      📣 We are excited to announce that OpenSSF is an Ecosystem Partner of the new GitHub Secure Open Source Fund. 🎉 &lt;br/&gt;&lt;br/&gt;💪 We are proud to help improve open source security and to collaborate with other industry leaders to make an impact. Open source security is crucial and we are committed to creating a safer ecosystem for everyone. &lt;br/&gt;&lt;br/&gt;Read the blog: &lt;a href=&#34;https://github.blog/news-insights/company-news/announcing-github-secure-open-source-fund/&#34;&gt;https://github.blog/news-insights/company-news/announcing-github-secure-open-source-fund/&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;#OpenSSF #GitHub #GitHubSecure #SupplyChainSecurity #CyberSecurity #opensource
    </content>
    <updated>2024-11-19T19:17:51Z</updated>
  </entry>

</feed>