OpenSSF

OpenSSF

Creator
0 followers

Open source software security, supply chain risk

Gemara: GRC Engineering Model for Automated Risk Assessment | OpenSSF Project Spotlight
VideoFeb 25, 2026

Gemara: GRC Engineering Model for Automated Risk Assessment | OpenSSF Project Spotlight

Jamara, the GRC Engineering Model for Automated Risk Assessment, is an OpenSSF‑hosted open‑source project that defines a multi‑layer logical model for integrating governance, risk, and compliance (GRC) directly into software engineering pipelines. Its purpose is to replace fragmented, tool‑specific data...

By OpenSSF
Best Practices Badge for Free/Libre and Open Source Software | OpenSSF Project Spotlight
VideoFeb 25, 2026

Best Practices Badge for Free/Libre and Open Source Software | OpenSSF Project Spotlight

David Wheeler, director of open‑source supply‑chain security at the OpenSSF, introduced the OpenSSF Best Practices Badge – a three‑tier (passing, silver, gold) certification that evaluates open‑source projects against a curated set of security‑focused criteria drawn from well‑run repositories. The badge...

By OpenSSF
Minder: Policy-Based Control of Software Security | OpenSSF Project Spotlight
VideoFeb 25, 2026

Minder: Policy-Based Control of Software Security | OpenSSF Project Spotlight

OpenSSF’s sandbox project Minder provides policy‑based security automation across the software development lifecycle. It lets open‑source communities, enterprises, and individual developers define policies that continuously monitor repositories, dependencies, CI/CD pipelines, and container builds. By integrating with OSV and other vulnerability...

By OpenSSF