OpenSSF’s September newsletter leads with its Governing Board’s commitment to durable funding models for public package registries, framed as enterprises paying as customers while individual developers keep access, after public registries warned that rising security and operating costs are outpacing their revenue. It also covers Cyber Resilience Act readiness guidance for maintainers, stewards and manufacturers, a fall Security Slam with CNCF TAG Security, an IBM case study on turning open source participation into stewardship, the summer mentorship showcase, and project releases from Scorecard, OpenBao, gittuf, Zarf, protobom, Gemara and Sigstore.
OpenSSF Newsletter – September 2026
OpenSSF's September newsletter leads with its Governing Board's commitment to durable funding models for public package registries, framed as enterprises paying as customers while individual developers keep access, after public registries warned that rising security and operating costs are outpacing their revenue. It also covers Cyber Resilience Act readiness guidance for maintainers, stewards and manufacturers, a fall Security Slam with CNCF TAG Security, an IBM case study on turning open source participation into stewardship, the summer mentorship showcase, and project releases from Scorecard, OpenBao, gittuf, Zarf, protobom, Gemara and Sigstore.
Source: OpenSSF