OpenSSF Expands Membership and Global Policy Resources at European Community Day

Open Source Security Foundation Expands Its Reach



The Open Source Security Foundation (OpenSSF) recently made impressive strides in enhancing its membership and providing essential resources during its Community Day held in Prague on October 6, 2026. This cross-industry initiative, part of the Linux Foundation, focuses on promoting security in the open-source software ecosystem. Four new entities—A-Team Systems, Emphere, DACHS IT GMBH, and JetBrains—joined as General Members, solidifying a broader commitment to securing software infrastructure.

The growth in membership underscores the increasing recognition of the need for collective action in maintaining open source security. Steve Fernandez, General Manager of OpenSSF, highlighted how the landscape of open source security is shifting, necessitating active collaboration across the industry. "Securing the open-source ecosystem is no longer just about patching isolated vulnerabilities. It requires proactive, systemic collaboration across the entire industry," he stated, emphasizing the importance of building a united front against emerging security threats.

Cyber Resilience Act: A Focus of New Resources



One of the pivotal aspects of this gathering was the release of new resources concerning the Cyber Resilience Act (CRA), which entered into effect last month. With companies facing regulatory pressure to report vulnerabilities, OpenSSF has taken the lead in providing straightforward guidance on navigating this complex legislation. The initiative focuses on fostering a community equipped to handle security challenges posed by artificial intelligence and accelerated vulnerability discovery processes.

The CRA mandates organizations to proactively report security incidents and vulnerabilities, pushing for a standardized approach to software integrity and safety. OpenSSF has addressed this need by publishing the CRA Readiness Practitioner's Guide, which translates legal obligations into actionable strategies for software maintainers and vendors, thereby enhancing compliance across Europe and beyond.

Key Achievements of OpenSSF



During the third quarter of 2026, OpenSSF celebrated several noteworthy accomplishments:
  • - CRA Case Study Published: A critical case study featuring Ericsson Software Technology showcased the benefits of "fixing it upstream" by contributing over 1,400 updates and security fixes in compliance with the CRA guidelines. This model demonstrates that effective collaboration can significantly enhance software supply chain security.
  • - User Journey Initiatives: OpenSSF introduced curated navigational paths aimed at various roles within organizations, including developers and security engineers, ensuring they access the relevant information tailored for their specific needs. This initiative supports role-based security efforts while improving overall compliance with new regulatory frameworks.
  • - New Releases: Among other advancements, the foundation announced the release of OpenBao v2.6, an open-source tool designed for enhanced secrets management, alongside the introduction of BOMHort into the OpenSSF Sandbox—a platform dedicated to managing Software Bills of Materials (SBOM) effectively as regulatory requirements evolve.

Looking Ahead: Events and Engagements



The OpenSSF community continues to gather momentum, with upcoming events slated to deepen engagement and collaboration among members. The Operationalizing the Cyber Resilience Act workshop is part of a series of discussions aimed at aligning practices with the latest regulatory standards. Following this event, participants are encouraged to attend AGNTCon + MCPCon North America in San Jose on October 22-23, as well as the Open Source SecurityCon North America in Salt Lake City on November 9.

Conclusion



The Open Source Security Foundation's enhanced membership and comprehensive resources signal a vital turning point in the collective approach to open-source security. With a commitment to collaboration and proactive measures, OpenSSF is at the forefront of building a more resilient software supply chain. Organizations are urged to engage with the community, tap into the available resources, and actively participate in the ongoing dialogues focused on securing the future of open source.

For more information and to view the complete list of new members, visit OpenSSF’s website.

Topics Other)

【About Using Articles】

You can freely use the title and article content by linking to the page where the article is posted.
※ Images cannot be used.

【About Links】

Links are free to use.