Siren is a new mailing list by the OpenSSF which aims to monitor the threat landscape of open-source project vulnerabilities in order to provide real time alerts to anyone subscribed.This is yet another stepping stone in OpenSSF's ongoing campaign for sane software security.This mailing list is addressed literally to anyone; as we described in "The State Of Secure Software Development - Three OpenSSF Courses"
It's about infrastructure as well, something that although not attracting the limelight, is as important as the open source software it hosts. Today the stewards of the largest open source registries in the world have issued an open letter demanding urgent reform in how open source infrastructure is funded, maintained, and operated. https://www.i-programmer.info/news/136-open-source/18334-open-source-is-not-just-about-software.html
Comments