We have scheduled the community meetings for March 2026. This is where you meet fellows working with the same issues, discuss and help us set our priorities for the project.
Register for free here: https://www.gvip-project.org/community/
A few weeks ago I had a conversation with Josh Bressers about the The Global Vulnerability Intelligence Platform and what we're doing there. It's now available on YouTube and your favourite podcast channels!
https://opensourcesecurity.io/2026/2026-02-GVIP-olle-johansson/
Join our community and contribute to the work! Register today at https://www.gvip-project.org/community/
Want to help working on a future global vulnerability intelligence platform with us? Join our community meetings!
Everyone that manages security reports for Open Source projects have been getting a higher workload because of AI. Both real reports and just slop - reports including vulnerabilities in code that doesn't exist. For some, this is becoming a denial of service attack, with developers having to spend valuable, and in some cases unpaid, time to sort out what's real and may be a vulnerability.
Jarek Potiuk, member of The Apache Software Foundation will talk about this on the GVIP Summit Wednesday Jan 28th in Brussels. We still have a few seats available - but hurry up to register!
Bloody great. NVD is behind CloudFlare and it's now blocking HTTP requests from GitHub Actions.
https://github.com/postmodern/nvd-json_feeds.rb/actions/runs/20915134462/job/60086722826
https://github.com/postmodern/nvd-json_feeds.rb/issues/2
Join us for the GVIP Summit - the pre-FOSDEM conference on vulnerability management. Supported by the @sovtechfund