Brian Behlendorf, OpenSSF GM, is laying out plans to fund open source supply chain security in a slowing economy and speak out against the EU's Cyber Resilience Act. Read this blog for insight.
What is the current funding status of OpenSSF?
As of now, OpenSSF has not yet met its initial funding goal of $150 million set last year. However, they have raised $7.5 million for their Alpha-Omega initiative and aim to match that amount this year. The foundation is focusing on ensuring that existing resources continue amidst economic challenges.
What are the implications of the EU Cyber Resilience Act?
The Cyber Resilience Act proposes obligations for open source software publishers, particularly those involved in critical infrastructure. This could impose costly requirements on developers, such as audits and certifications upon code publication, which may hinder open source contributions and innovation.
How does OpenSSF plan to enhance software security?
OpenSSF is focusing on funding security teams at major open source foundations and enhancing their security processes. They have allocated grants totaling about $2 million to various foundations to strengthen their security teams. Additionally, they are working on initiatives like the OpenSSF Incident Response Team to proactively address vulnerabilities in widely used open source projects.