Trendora

OpenSSF

Assess

Platforms

The Open Source Security Foundation community working on software supply chain and open-source security.

Why it's here

Placed in Assess: 2 article(s) of evidence from 3 source(s), led by security coverage, with 2 in the last 30 days. Confidence 45%.

Evidence (2)

  • 8GitHub Blog·8/6/2026security
    GitHub expands malware advisories beyond npm

    GitHub says Dependabot malware advisories now cover eight package ecosystems, including PyPI, by ingesting reports from OpenSSF’s malicious-packages repository. The update replaces a GitHub-only npm path with a shared importer that validates and normalizes OSV-format malware reports before they reach the advisory database.

  • 8NVIDIA GenAI·7/27/2026security
    Industry Leaders Launch Open Secure AI Alliance for AI Safety

    NVIDIA and other industry partners announced the Open Secure AI Alliance to develop open technologies, techniques, and tools for securing AI systems and agents. The initiative emphasizes open models, open harnesses, and community-driven remediation and vulnerability disclosure for cybersecurity and defensive use cases.