OpenSSF Announces Member Expansion and New Global Policy Resources on European Community Day
PR Newswire
1h ago
Ai Focus
During its meeting in Prague, BJW announced the addition of four new members: A-, BJW-KEEP-2, BJW-KEEP-5, BJW-KEEP-3, and BJW-KEEP-6. It also released new guidelines, user paths, and case studies for the EU's Cyber Resilience Act. The organization also presented its third-quarter progress in open-source security, version updates, and the addition of BJW-KEEP-10 to its membership list.
Helpful
No.Help

Four new members have joined, and the foundation has released important CRA resources, continuing to heat up systematic collaboration in the field of open-source security.

Prague, October 6th / PRNewswire / -- Today, Open Source Security Foundation ( OpenSSF ), an interdisciplinary initiative under Linux Foundation that focuses on continuously ensuring the security of open-source software, announced the further expansion of its membership. A- Team Systems , Emphere , DACHS IT GMBH , and JetBrains are welcome to join the foundation. OpenSSF also stated that it is deepening its preparations for the Cyber Resilience Act ( Cyber Resilience Act , CRA ), releasing guidelines, user pathways, and a case study not only within the EU but also for other regions.

As the regulatory pressure on companies selling products to the European Union increases, the mandatory vulnerability and incident reporting requirements in CRA came into effect last month. Clear, direct, and easy-to-understand guidance is particularly important for this global legislation, especially as artificial intelligence significantly accelerates the speed of vulnerability discovery and reporting. As vulnerabilities become easier to detect and the reporting window continues to shrink, OpenSSF continues to serve as a credible and neutral platform for CRA education, collaboration, and security efforts.

OpenSSF The general manager Steve Fernandez stated: "Ensuring the security of the open-source ecosystem is no longer just about fixing isolated vulnerabilities. This requires proactive and systematic collaboration from the entire industry. Initiatives such as Open Secure AI Alliance and pioneering projects like Akrites reflect this critical shift. We are moving beyond fragmented defenses to build a united front, providing the global developer community with a comprehensive framework necessary to secure the next generation of software. OpenSSF and its members are key components of this transformation."

New members who have joined OpenSSF include A- Team Systems, Emphere, DACHS IT GMBH, and JetBrains. All four companies have joined the foundation as regular members. These organizations have become part of a community composed of working groups, technical teams, and experts, working together to shape the future of OpenSSF and software security. Their participation will directly impact the long-term sustainability of open source, as well as projects that are crucial to modern infrastructure.

Foundation Achievements for the Third Quarter of 2026

In addition to member growth, OpenSSF also made the following progress in the third quarter of 2026:

  • CRA has released a preparation guide – OpenSSF has issued practical compliance guidelines for the EU's Cyber Resilience Act. With the obligations of CRA now officially in effect, this guide transforms policy analysis into actionable steps to assist maintainers and suppliers who must comply. OpenSSF has also released a CRA user pathway to support more thorough preparation around this important regulation, regardless of the current starting point of each organization.
  • CRA Case Study: Ericsson Contributed 1,400 Fixes to Upstream -- To fulfill CRA obligations, Ericsson Software Technology abolished its private branches and, guided by the principles of OpenSSF, contributed over 1,400 dependency updates and security fixes to upstream. This case study provides concrete evidence that fixes should be submitted to upstream rather than retained in branches, which helps to create a safer software supply chain at the corporate level.
  • Paths for Different Roles — OpenSSF has launched a role-based “User Journeys” to help security professionals find the appropriate guides and resources. These customized navigation paths are designed for developers, security engineers, OSPO leaders, marketing personnel, and executives, ensuring that relevant information reaches those who truly need it.
  • OpenBao v2.6 Release — A new version of this open-source key management tool has added a namespace encapsulation feature, as well as a new workflow engine for cross-plugin communication.
  • BOMHort joins OpenSSF Sandbox — a SBOM visualization and governance tool for Kubernetes to enter OpenSSF Sandbox. As SBOM shifts from best practices to regulatory requirements (CRA, NIST SSDF, EO 14028), this tool can truly help teams manage and query SBOM on a large scale, rather than just generating SBOM, filling an important security gap.

Supporting quotes

Open-source software has played a central role for over twenty years in our support of the Linux and FreeBSD systems and their use in critical production environments. We rely on the security efforts of the entire open-source ecosystem. OpenSSF provides a fundamental part of that foundation, making secure and reliable production operations possible. Joining OpenSSF reflects our commitment to substantially supporting those who have shaped open source as it is today. We look forward to contributing from the perspective of infrastructure operations and supporting the important work carried out by OpenSSF within the entire open-source community.

——A- Team Systems President Adam Strohl

"Almost every key enterprise is built on open-source foundations. When everyone relies on this digital common foundation, maintaining its security becomes a shared responsibility. Ensuring the security of the supply chain helps to guarantee that open-source software remains secure, trustworthy, and open to everyone. Through our continuous efforts at Linux Foundation and CNCF, we have helped to build a cloud-native ecosystem. Now, with OpenSSF, we are expanding our scope of work to help protect and nurture the security foundations upon which they depend."

– DACHS IT GMBH Founder and CEO Alexander Schaber

Open source is about sharing code, and the responsibility for ensuring its security is also shared. Emphere is very pleased to join OpenSSF to help the community fix vulnerabilities before attackers, whether those attackers are humans or AI.

—— Emphere Chief Executive Officer Ankit Kumar

Software development is at a turning point. AI is changing the way software is built and bringing new security challenges, which makes it more important than ever for developers to understand, verify, and trust the software they produce. JetBrains has been supporting professional software development for over twenty years, and we believe that the best approach is to stay ahead through collaboration in an open environment. OpenSSF brings together some of the strongest professionals in the industry, and we are delighted to join this community and help shape the future of secure software development.

—— JetBrains Community and Partnership Relations Officer Katherine Druckman

Events and Gatherings

OpenSSF members are currently participating in OpenSSF Community Day Europe in Prague this week, and will be hosting " Workshop : Operationalizing the Cyber Resilience Act " on Friday, October 9th. If you wish to join the OpenSSF community, you can also attend the following upcoming events: AGNTCon + MCPCon North America (San Jose, California; October 22nd to 23rd) as well as Open Source SecurityCon North America (Salt Lake City, Utah; November 9th).

More resources

  • View the complete list of OpenSSF members.
  • Contribute to one or more active OpenSSF workgroups and projects.
  • Subscribe to OpenSSF newsletter to get updates on upcoming events, resources, and community news.

About OpenSSF

Open Source Security Foundation ( OpenSSF ) is a cross-industry organization under Linux Foundation, bringing together the most important open-source security initiatives in the industry, as well as individuals and companies that support these initiatives. OpenSSF is committed to collaboration and works with upstream parties and existing communities to promote open-source security for the benefit of all. For more information, please visit openssf.org.

About Linux Foundation

Linux Foundation is a globally leading open-source software, hardware, standards, and data collaboration platform. The projects of Linux Foundation include Linux, Kubernetes, Model Context Protocol ( MCP ), OpenChain, OpenSearch, OpenSSF, OpenStack, PyTorch, Ray, RISC-V, SPDX, and Zephyr, providing support for global infrastructure. Linux Foundation is committed to utilizing best practices and meeting the needs of contributors, users, and solution providers in order to create a sustainable open collaboration model. For more information, please visit linuxfoundation.org.

Linux Foundation is a registered trademark and is in use. For a list of its trademarks, please refer to the Trademark Usage page: www.linuxfoundation.org / trademark-usage. Linux is a registered trademark of Linus Torvalds.

Media Contact

Grace Lucier

The Linux Foundation
[ email protected ]

Tip
$0
Like
0
Save
0
Views 34
WalletJYS reminds readers to view blockchain rationally, stay aware of risks, and beware of virtual token issuance and speculation. All content on this site represents market information or related viewpoints only and does not constitute any form of investment advice. If you find sensitive content, please click“Report”,and we will handle it promptly。
Submit
Comment 0
Hot
Latest
No comments yet. Be the first!
Related
Qualcomm Sues Arm: Accusing It of Withholding Chip Testing Tools and Leaking Confidential Information, Seeking Exemption from Billions in Licensing Fees Over 5 Years
According to Reuters, Qualcomm and Arm once again faced each other in a court of law in the U.S. District Court of Delaware. Qualcomm accused Arm of withholding chip testing tools and threatening to disclose information about the termination of the licensing agreement to the media, claiming that such actions damaged its chip trading cooperation with Meta. Qualcomm also sought to stop paying licensing fees that could amount to several billion dollars over a period of up to 5 years to Arm.
The Block
·2026-10-06 18:12:28
9
Renesas Launches Its First Brand of Low-Voltage Gallium Nitride Power Semiconductors, Targeting AI Data Centers, Humanoid Robots, and Other Fields
Renesas Electronics announces the launch of its first low-voltage gallium nitride power semiconductor product, which belongs to the 100V enhanced GaN discrete power transistor series. It is targeted at applications such as AI data centers, humanoid robots, factory automation, and industrial motor drives. The company claims that this series offers improvements in FOM, efficiency, and switching losses compared to similar silicon-based solutions.
The Block
·2026-10-06 18:12:26
10
Bitcoin price repeatedly encounters resistance around $87,000, what is holding back the rise?
Bitcoin fell back to around $85,500 on October 6, after encountering resistance near $87,000 once again earlier in the week. US spot Bitcoin ETF saw a net outflow of $89.9 million on Monday, ending the two-day net inflow that preceded it. Analysts said that the range between $83,300 and $84,600 serves as a major support level, while $86,700 is a key level that buyers need to break through.
crypto.news
·2026-10-06 18:04:15
9
The Pros and Cons of Layoffs to Be Determined Later
Some companies will issue notices of layoffs in advance, but it can take weeks or even months to determine which positions will be affected. Nike, Meta, and GitLab have all done this before. The article states that this approach may give employees time to find new jobs, but it could also increase anxiety throughout the company.
Businessinsider
·2026-10-06 17:53:37
20
ChainIT released the complete business architecture of Agentic Web3 in Singapore during TOKEN2049 week
ChainIT Inc released its “Agentic Web3 Complete Commerce” architecture during the week of TOKEN2049 in Singapore, and launched an executive white paper titled “ChainIT Transaction Truth: Stablecoins, Web3 Wallets, and Multi-Track Commerce.” The company stated that this architecture is designed to enable AI agents to conduct transactions through Web3 wallets, stablecoins, and traditional payment channels within a framework that ensures verified identities, authorized boundaries, runtime compliance, and controlled execution, while providing verifiable evidence for settlements and business outcomes.
PR Newswire
·2026-10-06 17:44:01
18
View More