#OpenSSF #OpenSSFScorecard #SAST #Infosec #WhatsMissing
The @ostifofficial recently completed a security audit of #OpenSSFScorecard.
With support from the OpenSSF, this audit covered five core repositories and included threat modelling, manual code review, and fuzz testing.
Read to learn more:๐ https://openssf.org/blog/2025/10/10/openssf-scorecard-audit-is-complete/
New to OpenSSF or thinking about getting involved? We've got you. ๐ก
This blog by Ejiro and Sal introduces all our working groups, tools, and projects like #sigstore, #SLSA, and #OpenSSFScorecard.
Start here ๐ https://openssf.org/blog/2025/08/08/from-beginner-to-builder-understanding-openssf-community-and-working-groups/
๐ก๏ธ Over 90% of modern apps rely on open source components, but are they secure?
The #OpenSSFScorecard helps assess #OSSsecurity yet adoption is uneven. A centralized dashboard like Ortelius could change the game.