📰 Google Open Source Security Team News
Google Open Source Security Team News Today
Fast, Ad-Free News Updates
Stay updated with breaking news from Google Open Source Security Team. Real-time updates on events, politics, business and more.
October 27, 2023
It is only a couple of weeks since the debut of the Microsoft AI Bounty Program, and now Google has launched its own bug bounty program specific to generative AI.
October 13, 2023
The Malicious Packages repository acts as a public database where reports of malicious packages are stored.
April 21, 2023
Announcing a new, more secure way to publish to PyPI
April 19, 2023
/PRNewswire/ -- The Open Source Security Foundation (OpenSSF) is proud to announce the release of version 1.0 of Supply-chain Levels for Software Artifacts...
April 19, 2023
SLSA v1.0 has been designed to make the software supply chain security framework more accessible and specific to areas of the software delivery lifecycle.
April 13, 2023
With the two new services, Google aims to help minimise risk from malicious code in the software supply chain.
April 12, 2023
With the two new services, Google aims to help minimize risk from malicious code in the software supply chain.
January 14, 2023
Sigstore is an open source project launched by Linux Foundation with the goal of providing free and stable services for all developers to easily sign, verify and protect their software projects. While code signing is a valuable tool to prevent hackers from co-opting patching systems and delivering malware, it is difficult to implement in open source projects given the complexity of key management.
December 15, 2022
OSV-Scanner is a free vulnerability scanner that open source developers can use to check for vulnerabilities in their projects' dependencies.
November 29, 2022
Here's a comprehensive look at some of the lesser-known, but no less serious, types of software supply chain attacks.