# secure open source

Published articles for secure open source.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## Expanding Athena

DevFeed: [Expanding Athena](<https://devfeed.tech/articles/expanding-athena-13034.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/expanding-athena>)

Published: 2026-07-07T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [open-source-security](<https://devfeed.tech/topics/open-source-security.md>), [Frontier AI](<https://devfeed.tech/topics/frontier-ai.md>), [AI Models](<https://devfeed.tech/topics/ai-models.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [Security](<https://devfeed.tech/topics/security.md>), [Maintainers](<https://devfeed.tech/topics/maintainers.md>), [Parser](<https://devfeed.tech/topics/parser.md>), [Library](<https://devfeed.tech/topics/library.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [akrites](<https://devfeed.tech/tags/akrites.md>), [athena](<https://devfeed.tech/tags/athena.md>), [chainguard-clearinghouse](<https://devfeed.tech/tags/chainguard-clearinghouse.md>), [chainguard-libraries](<https://devfeed.tech/tags/chainguard-libraries.md>), [frontier-ai](<https://devfeed.tech/tags/frontier-ai.md>), [library](<https://devfeed.tech/tags/library.md>), [maintainers](<https://devfeed.tech/tags/maintainers.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [parsing](<https://devfeed.tech/tags/parsing.md>), [secure-open-source](<https://devfeed.tech/tags/secure-open-source.md>), [secure-oss](<https://devfeed.tech/tags/secure-oss.md>), [security](<https://devfeed.tech/tags/security.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

Chainguard describes Athena, an industry coalition coordinating the discovery, remediation, protection, disclosure, and upstream fixing of vulnerabilities in open source software. The article reports that Athena has processed more than 40,000 vulnerabilities and emphasizes that frontier AI models can identify latent flaws and chain lower-severity bugs into serious attacks.

### Source excerpt

See how Athena is helping secure open source by coordinating AI-discovered vulnerabilities, partner protections, and upstream fixes at scale.

## Why Vulnerability Clearinghouses Alone Cannot Secure Open Source

DevFeed: [Why Vulnerability Clearinghouses Alone Cannot Secure Open Source](<https://devfeed.tech/articles/summer-of-clearinghouses-13244.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/summer-of-clearinghouses>)

Published: 2026-07-05T00:00:00Z

Content type: opinion

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [data](<https://devfeed.tech/topics/data.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [Security](<https://devfeed.tech/topics/security.md>), [NVD](<https://devfeed.tech/topics/nvd.md>), [Unix](<https://devfeed.tech/topics/unix.md>)

Tags: [akrites](<https://devfeed.tech/tags/akrites.md>), [athena](<https://devfeed.tech/tags/athena.md>), [chainguard-libraries](<https://devfeed.tech/tags/chainguard-libraries.md>), [data](<https://devfeed.tech/tags/data.md>), [ibm-red-hat-project-lightwell](<https://devfeed.tech/tags/ibm-red-hat-project-lightwell.md>), [nvd](<https://devfeed.tech/tags/nvd.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [press-release](<https://devfeed.tech/tags/press-release.md>), [secure-open-source](<https://devfeed.tech/tags/secure-open-source.md>), [security](<https://devfeed.tech/tags/security.md>), [security-research](<https://devfeed.tech/tags/security-research.md>), [vulnerability-clearinghouse](<https://devfeed.tech/tags/vulnerability-clearinghouse.md>), [vulnerability-data](<https://devfeed.tech/tags/vulnerability-data.md>)

### AI overview

The article argues that vulnerability clearinghouses are primarily pools of data and are not the most important part of securing open source. It emphasizes actuation--turning findings into fixes--along with trusted builds and secure-by-design software.

### Source excerpt

Clearinghouses alone won't secure open source. Learn why actuation, trusted builds, and secure-by-design software matter more than vulnerability data.

## AI-driven zero-day combinations are challenging software security and open-source consumption

DevFeed: [AI-driven zero-day combinations are challenging software security and open-source consumption](<https://devfeed.tech/articles/the-hardest-fork-13253.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/the-hardest-fork>)

Published: 2026-05-28T00:00:00Z

Content type: opinion

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [open-source-security](<https://devfeed.tech/topics/open-source-security.md>), [Security](<https://devfeed.tech/topics/security.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [Machine Learning, Security Attacks](<https://devfeed.tech/topics/machine-learning-security-attacks.md>), [Critical Infrastructure](<https://devfeed.tech/topics/critical-infrastructure.md>), [openssf](<https://devfeed.tech/topics/openssf.md>), [sigstore](<https://devfeed.tech/topics/sigstore.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [anthropic-mythos](<https://devfeed.tech/tags/anthropic-mythos.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [critical-infrastructure](<https://devfeed.tech/tags/critical-infrastructure.md>), [fork](<https://devfeed.tech/tags/fork.md>), [mfa](<https://devfeed.tech/tags/mfa.md>), [mythos](<https://devfeed.tech/tags/mythos.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [open-source-security](<https://devfeed.tech/tags/open-source-security.md>), [openssf](<https://devfeed.tech/tags/openssf.md>), [oss](<https://devfeed.tech/tags/oss.md>), [project-glasswing](<https://devfeed.tech/tags/project-glasswing.md>), [rust](<https://devfeed.tech/tags/rust.md>), [sast](<https://devfeed.tech/tags/sast.md>), [secure-open-source](<https://devfeed.tech/tags/secure-open-source.md>), [security](<https://devfeed.tech/tags/security.md>), [sigstore](<https://devfeed.tech/tags/sigstore.md>)

### AI overview

The article argues that Mythos represents a potential new class of software-security threat: AI-driven combinations of existing issues that can produce more serious attacks than individual scanner findings. It discusses the limits of government regulation and calls for stronger trust infrastructure, coordinated disclosure, and safer open-source consumption.

### Source excerpt

Mythos is changing software security fast. AI-driven zero-days demand new trust infrastructure, coordinated disclosure, and secure open source consumption.

## Building the business case for a secure open source supply chain

DevFeed: [Building the business case for a secure open source supply chain](<https://devfeed.tech/articles/building-the-business-case-for-a-secure-open-source-supply-chain-12911.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/building-the-business-case-for-a-secure-open-source-supply-chain>)

Published: 2026-05-05T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Open Source](<https://devfeed.tech/topics/open-source.md>), [open-source-security](<https://devfeed.tech/topics/open-source-security.md>), [vulnerability management](<https://devfeed.tech/topics/vulnerability-management.md>), [cloud-infrastructure](<https://devfeed.tech/topics/cloud-infrastructure.md>), [CI/CD](<https://devfeed.tech/topics/cicd.md>), [distributed-systems](<https://devfeed.tech/topics/distributed-systems.md>), [container images](<https://devfeed.tech/topics/container-images.md>), [engineering-culture](<https://devfeed.tech/topics/engineering-culture.md>)

Tags: [chainguard-assemble](<https://devfeed.tech/tags/chainguard-assemble.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [chainguard-customers](<https://devfeed.tech/tags/chainguard-customers.md>), [cloud-infrastructure](<https://devfeed.tech/tags/cloud-infrastructure.md>), [cloud-native](<https://devfeed.tech/tags/cloud-native.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [continuous-delivery](<https://devfeed.tech/tags/continuous-delivery.md>), [cves](<https://devfeed.tech/tags/cves.md>), [dependencies](<https://devfeed.tech/tags/dependencies.md>), [distributed-systems](<https://devfeed.tech/tags/distributed-systems.md>), [kyndryl](<https://devfeed.tech/tags/kyndryl.md>), [kyndryl-open-source](<https://devfeed.tech/tags/kyndryl-open-source.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [productivity](<https://devfeed.tech/tags/productivity.md>), [resilience](<https://devfeed.tech/tags/resilience.md>), [secure-open-source](<https://devfeed.tech/tags/secure-open-source.md>), [software-supply-chain-security](<https://devfeed.tech/tags/software-supply-chain-security.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

The article explains how organizations can build a business case for a secure open source supply chain. It describes a shift from framing open source security solely around CVEs, scanner results, and patching toward presenting trusted open source as a driver of productivity, resilience, and delivery speed. It also explains why traditional vulnerability management struggles with continuous delivery, distributed systems, frequently rebuilt container images, changing dependencies, and global cloud infrastructure.

### Source excerpt

Learn how Kyndryl reframed open source security as a business driver -- reducing risk, lowering costs, and accelerating developer productivity.

## Chainguard and Cursor partner to bring secure open source artifacts to agentic coding

DevFeed: [Chainguard and Cursor partner to bring secure open source artifacts to agentic coding](<https://devfeed.tech/articles/chainguard-and-cursor-partner-to-bring-secure-open-source-artifacts-to-agentic-coding-12924.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/chainguard-and-cursor-partner-to-bring-secure-open-source-artifacts-to-agentic-coding>)

Published: 2026-04-21T00:00:00Z

Content type: release

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [agentic-coding](<https://devfeed.tech/topics/agentic-coding.md>), [cursor](<https://devfeed.tech/topics/cursor.md>), [chainguard containers](<https://devfeed.tech/topics/chainguard-containers.md>), [chainguard libraries](<https://devfeed.tech/topics/chainguard-libraries.md>), [Security](<https://devfeed.tech/topics/security.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [ai-coding](<https://devfeed.tech/topics/ai-coding.md>)

Tags: [agentic-coding](<https://devfeed.tech/tags/agentic-coding.md>), [ai-agents](<https://devfeed.tech/tags/ai-agents.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [chainguard-cursor-partnership](<https://devfeed.tech/tags/chainguard-cursor-partnership.md>), [chainguard-libraries](<https://devfeed.tech/tags/chainguard-libraries.md>), [cursor](<https://devfeed.tech/tags/cursor.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [secure-open-source](<https://devfeed.tech/tags/secure-open-source.md>), [security](<https://devfeed.tech/tags/security.md>), [shai-hulud](<https://devfeed.tech/tags/shai-hulud.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>)

### AI overview

Chainguard and Cursor are partnering to provide trusted, secure open source containers and libraries for agentic coding. The integration directs developers away from insecure public registries toward Chainguard Repository artifacts, helping reduce malware and software supply chain risks without slowing development.

### Source excerpt

Chainguard and Cursor partner to secure AI-generated code with trusted, source-built containers and libraries, reducing risk without slowing developers.

## How GoReleaser strengthened security through GitHub's Secure Open Source Fund

DevFeed: [How GoReleaser strengthened security through GitHub's Secure Open Source Fund](<https://devfeed.tech/articles/how-goreleaser-strengthened-security-through-github-s-secure-open-source-fund-37754.md>)

Original publisher: [Read original article](<https://carlosbecker.com/posts/goreleaser-github-secure-oss-fund/>)

Author: Carlos Alexandro Becker

Published: 2026-02-17T00:00:00Z

Content type: article

Language: en

Sources: [Carlos Becker](<https://devfeed.tech/sources/carlos-becker.md>)

Topics: [GitHub](<https://devfeed.tech/topics/github.md>), [Security](<https://devfeed.tech/topics/security.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>)

Tags: [announcement](<https://devfeed.tech/tags/announcement.md>), [github](<https://devfeed.tech/tags/github.md>), [release](<https://devfeed.tech/tags/release.md>), [secure-open-source](<https://devfeed.tech/tags/secure-open-source.md>), [security](<https://devfeed.tech/tags/security.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>)

### AI overview

GoReleaser was selected for the third session of the GitHub Secure Open Source Fund. The article explains that GoReleaser builds and ships release artifacts for thousands of projects, making it a high-value supply-chain target.

### Source excerpt

GoReleaser builds and ships release artifacts for thousands of projects, making it a high-value supply-chain target. That's why we were thrilled to be selected for the third session of the GitHub Secure Open Source Fund.

## GitHub Secure Open Source Fund

DevFeed: [GitHub Secure Open Source Fund](<https://devfeed.tech/articles/github-secure-open-source-fund-22299.md>)

Original publisher: [Read original article](<https://blog.getbootstrap.com/2025/08/10/github-secure-open-source-fund/>)

Author: Julien Déramond

Published: 2025-08-10T08:40:00Z

Content type: article

Language: en

Sources: [Bootstrap.com](<https://devfeed.tech/sources/bootstrap-com.md>)

Topics: [Open Source](<https://devfeed.tech/topics/open-source.md>), [GitHub](<https://devfeed.tech/topics/github.md>), [Security](<https://devfeed.tech/topics/security.md>), [Maintainers](<https://devfeed.tech/topics/maintainers.md>), [incident response plan](<https://devfeed.tech/topics/incident-response-plan.md>), [GitHub Actions](<https://devfeed.tech/topics/github-actions.md>)

Tags: [github](<https://devfeed.tech/tags/github.md>), [incident-response-plan](<https://devfeed.tech/tags/incident-response-plan.md>), [maintainers](<https://devfeed.tech/tags/maintainers.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [open-ssf](<https://devfeed.tech/tags/open-ssf.md>), [secure-github-actions](<https://devfeed.tech/tags/secure-github-actions.md>), [secure-open-source](<https://devfeed.tech/tags/secure-open-source.md>), [security](<https://devfeed.tech/tags/security.md>), [workflows](<https://devfeed.tech/tags/workflows.md>), [workshops](<https://devfeed.tech/tags/workshops.md>)

### AI overview

Bootstrap team members Mark and Julien describe participating in the second round of GitHub's Secure Open Source Fund. The three-week program combined presentations, workshops, office hours, and project-specific work focused on strengthening open-source security, code, workflows, and processes.

### Source excerpt

Mark and Julien recently represented Bootstrap in the second round of the GitHub Secure Open Source Fund this past June. The program is designed to programmatically and financially improve the security and sustainability of open source projects, and we were honored to be a part of it. GitHub brought together open source maintainers, security experts, and ecosystem partners for an intensive, hands-on learning experience. Throughout three weeks, we had a few days of mixed expert-led presentations, collaborative workshops, and dedicated office hours with security specialists. Between sessions, we had homework: concrete, project-specific actions to immediately strengthen our codebase, workflows, and processes.

## Chainguard enhances security with OSV advisory feed

DevFeed: [Chainguard enhances security with OSV advisory feed](<https://devfeed.tech/articles/chainguard-enhances-security-with-osv-advisory-feed-12943.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/chainguard-enhances-security-with-osv-advisory-feed>)

Published: 2024-07-02T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard](<https://devfeed.tech/topics/chainguard.md>), [vulnerability management](<https://devfeed.tech/topics/vulnerability-management.md>), [open-source-security](<https://devfeed.tech/topics/open-source-security.md>), [vulnerability](<https://devfeed.tech/topics/vulnerability.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Maintainers](<https://devfeed.tech/topics/maintainers.md>), [chainguard images](<https://devfeed.tech/topics/chainguard-images.md>), [data](<https://devfeed.tech/topics/data.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [Google](<https://devfeed.tech/topics/google.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [google](<https://devfeed.tech/tags/google.md>), [maintainers](<https://devfeed.tech/tags/maintainers.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [open-source-vulnerabilities](<https://devfeed.tech/tags/open-source-vulnerabilities.md>), [openssf](<https://devfeed.tech/tags/openssf.md>), [osv](<https://devfeed.tech/tags/osv.md>), [secure-open-source](<https://devfeed.tech/tags/secure-open-source.md>), [secure-software](<https://devfeed.tech/tags/secure-software.md>), [security](<https://devfeed.tech/tags/security.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>), [vulnerability-data](<https://devfeed.tech/tags/vulnerability-data.md>), [vulnerability-management](<https://devfeed.tech/tags/vulnerability-management.md>), [wolfi](<https://devfeed.tech/tags/wolfi.md>)

### AI overview

Chainguard is publishing its security advisory feed in the OSV format, improving the precision and usability of vulnerability information for open source maintainers and downstream consumers.

### Source excerpt

Explore Chainguard's new OSV advisory feed, delivering comprehensive and up-to-date vulnerability information to enhance your security posture.

## Priorities from the OpenSSF Secure Open Source Software Summit 2023

DevFeed: [Priorities from the OpenSSF Secure Open Source Software Summit 2023](<https://devfeed.tech/articles/priorities-from-the-openssf-secure-open-source-software-summit-2023-8041.md>)

Original publisher: [Read original article](<https://snyk.io/blog/openssf-secure-open-source-software-summit-2023/>)

Author: Dan Appelquist

Published: 2023-10-04T15:00:00Z

Content type: article

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [open-source-security](<https://devfeed.tech/topics/open-source-security.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [Security](<https://devfeed.tech/topics/security.md>), [GitHub](<https://devfeed.tech/topics/github.md>), [GitLab](<https://devfeed.tech/topics/gitlab.md>), [Incident response](<https://devfeed.tech/topics/incident-response.md>), [Maintainers](<https://devfeed.tech/topics/maintainers.md>)

Tags: [awareness](<https://devfeed.tech/tags/awareness.md>), [best-practices](<https://devfeed.tech/tags/best-practices.md>), [blog](<https://devfeed.tech/tags/blog.md>), [collaboration](<https://devfeed.tech/tags/collaboration.md>), [engineering](<https://devfeed.tech/tags/engineering.md>), [github](<https://devfeed.tech/tags/github.md>), [gitlab](<https://devfeed.tech/tags/gitlab.md>), [government](<https://devfeed.tech/tags/government.md>), [incident-response](<https://devfeed.tech/tags/incident-response.md>), [maintainers](<https://devfeed.tech/tags/maintainers.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [open-source-security](<https://devfeed.tech/tags/open-source-security.md>), [openssf](<https://devfeed.tech/tags/openssf.md>), [scm](<https://devfeed.tech/tags/scm.md>), [secure-open-source](<https://devfeed.tech/tags/secure-open-source.md>), [security](<https://devfeed.tech/tags/security.md>), [snyk-open-source](<https://devfeed.tech/tags/snyk-open-source.md>), [summit](<https://devfeed.tech/tags/summit.md>), [workflows](<https://devfeed.tech/tags/workflows.md>)

### AI overview

The OpenSSF Secure Open Source Software Summit 2023 identified priorities for improving open source security, including maintainer education, repository security, and cross-industry incident response. Snyk describes a Source Code Management Best Practices Guide for GitHub and GitLab repositories, used with OpenSSF Scorecard to improve permissions, workflows, policies, and security practices.

### Source excerpt

A recent summit meeting convened by the OpenSSF with the White House brought together various US Government departments for a chat about open source security.