A-Team Systems, Emphere, DACHS IT GMBH, and JetBrains are the latest to join the foundation, reinforcing a push toward systemic, industry-wide collaboration. These new members aim to support the long-term sustainability of critical infrastructure projects, moving beyond isolated patching toward unified security frameworks. General Manager Steve Fernandez emphasized that the shift is essential to equip developers against increasingly rapid vulnerability discovery.
In section Releases
OpenSSF Expands Membership and Releases New Cyber Resilience Act Guides
Four organizations joined the Open Source Security Foundation as the group unveiled a suite of compliance resources in Prague. The expansion comes as the EU’s Cyber Resilience Act mandates stricter vulnerability reporting, forcing vendors to overhaul how they manage and secure their software supply chains in an era of AI-driven threats.

To assist with the mandatory requirements of the Cyber Resilience Act, the foundation published a practitioner's guide and a user journey map to help vendors transition policy analysis into technical action. A notable case study involving Ericsson demonstrated the effectiveness of this approach, with the company contributing over 1,400 security fixes upstream rather than maintaining private forks. Alongside these regulatory tools, the foundation released OpenBao v2.6 for secrets management and integrated the BOMHort tool into its sandbox to improve SBOM governance.
Comments (0)
No comments yet. Be the first!