Four new members have joined, and the foundation has released important CRA resources, continuing to heat up systematic collaboration in the field of open-source security.
Prague, October 6th / PRNewswire / -- Today, Open Source Security Foundation ( OpenSSF ), an interdisciplinary initiative under Linux Foundation that focuses on continuously ensuring the security of open-source software, announced the further expansion of its membership. A- Team Systems , Emphere , DACHS IT GMBH , and JetBrains are welcome to join the foundation. OpenSSF also stated that it is deepening its preparations for the Cyber Resilience Act ( Cyber Resilience Act , CRA ), releasing guidelines, user pathways, and a case study not only within the EU but also for other regions.
As the regulatory pressure on companies selling products to the European Union increases, the mandatory vulnerability and incident reporting requirements in CRA came into effect last month. Clear, direct, and easy-to-understand guidance is particularly important for this global legislation, especially as artificial intelligence significantly accelerates the speed of vulnerability discovery and reporting. As vulnerabilities become easier to detect and the reporting window continues to shrink, OpenSSF continues to serve as a credible and neutral platform for CRA education, collaboration, and security efforts.
OpenSSF The general manager Steve Fernandez stated: "Ensuring the security of the open-source ecosystem is no longer just about fixing isolated vulnerabilities. This requires proactive and systematic collaboration from the entire industry. Initiatives such as Open Secure AI Alliance and pioneering projects like Akrites reflect this critical shift. We are moving beyond fragmented defenses to build a united front, providing the global developer community with a comprehensive framework necessary to secure the next generation of software. OpenSSF and its members are key components of this transformation."
New members who have joined OpenSSF include A- Team Systems, Emphere, DACHS IT GMBH, and JetBrains. All four companies have joined the foundation as regular members. These organizations have become part of a community composed of working groups, technical teams, and experts, working together to shape the future of OpenSSF and software security. Their participation will directly impact the long-term sustainability of open source, as well as projects that are crucial to modern infrastructure.
Foundation Achievements for the Third Quarter of 2026
In addition to member growth, OpenSSF also made the following progress in the third quarter of 2026:
- CRA has released a preparation guide – OpenSSF has issued practical compliance guidelines for the EU's Cyber Resilience Act. With the obligations of CRA now officially in effect, this guide transforms policy analysis into actionable steps to assist maintainers and suppliers who must comply. OpenSSF has also released a CRA user pathway to support more thorough preparation around this important regulation, regardless of the current starting point of each organization.
- CRA Case Study: Ericsson Contributed 1,400 Fixes to Upstream -- To fulfill CRA obligations, Ericsson Software Technology abolished its private branches and, guided by the principles of OpenSSF, contributed over 1,400 dependency updates and security fixes to upstream. This case study provides concrete evidence that fixes should be submitted to upstream rather than retained in branches, which helps to create a safer software supply chain at the corporate level.
- Paths for Different Roles — OpenSSF has launched a role-based “User Journeys” to help security professionals find the appropriate guides and resources. These customized navigation paths are designed for developers, security engineers, OSPO leaders, marketing personnel, and executives, ensuring that relevant information reaches those who truly need it.
- OpenBao v2.6 Release — A new version of this open-source key management tool has added a namespace encapsulation feature, as well as a new workflow engine for cross-plugin communication.
- BOMHort joins OpenSSF Sandbox — a SBOM visualization and governance tool for Kubernetes to enter OpenSSF Sandbox. As SBOM shifts from best practices to regulatory requirements (CRA, NIST SSDF, EO 14028), this tool can truly help teams manage and query SBOM on a large scale, rather than just generating SBOM, filling an important security gap.
Supporting quotes
Open-source software has played a central role for over twenty years in our support of the Linux and FreeBSD systems and their use in critical production environments. We rely on the security efforts of the entire open-source ecosystem. OpenSSF provides a fundamental part of that foundation, making secure and reliable production operations possible. Joining OpenSSF reflects our commitment to substantially supporting those who have shaped open source as it is today. We look forward to contributing from the perspective of infrastructure operations and supporting the important work carried out by OpenSSF within the entire open-source community.
——A- Team Systems President Adam Strohl
"Almost every key enterprise is built on open-source foundations. When everyone relies on this digital common foundation, maintaining its security becomes a shared responsibility. Ensuring the security of the supply chain helps to guarantee that open-source software remains secure, trustworthy, and open to everyone. Through our continuous efforts at Linux Foundation and CNCF, we have helped to build a cloud-native ecosystem. Now, with OpenSSF, we are expanding our scope of work to help protect and nurture the security foundations upon which they depend."
– DACHS IT GMBH Founder and CEO Alexander Schaber
Open source is about sharing code, and the responsibility for ensuring its security is also shared. Emphere is very pleased to join OpenSSF to help the community fix vulnerabilities before attackers, whether those attackers are humans or AI.
—— Emphere Chief Executive Officer Ankit Kumar
Software development is at a turning point. AI is changing the way software is built and bringing new security challenges, which makes it more important than ever for developers to understand, verify, and trust the software they produce. JetBrains has been supporting professional software development for over twenty years, and we believe that the best approach is to stay ahead through collaboration in an open environment. OpenSSF brings together some of the strongest professionals in the industry, and we are delighted to join this community and help shape the future of secure software development.
—— JetBrains Community and Partnership Relations Officer Katherine Druckman
Events and Gatherings
OpenSSF members are currently participating in OpenSSF Community Day Europe in Prague this week, and will be hosting " Workshop : Operationalizing the Cyber Resilience Act " on Friday, October 9th. If you wish to join the OpenSSF community, you can also attend the following upcoming events: AGNTCon + MCPCon North America (San Jose, California; October 22nd to 23rd) as well as Open Source SecurityCon North America (Salt Lake City, Utah; November 9th).
More resources
- View the complete list of OpenSSF members.
- Contribute to one or more active OpenSSF workgroups and projects.
- Subscribe to OpenSSF newsletter to get updates on upcoming events, resources, and community news.
About OpenSSF
Open Source Security Foundation ( OpenSSF ) is a cross-industry organization under Linux Foundation, bringing together the most important open-source security initiatives in the industry, as well as individuals and companies that support these initiatives. OpenSSF is committed to collaboration and works with upstream parties and existing communities to promote open-source security for the benefit of all. For more information, please visit openssf.org.
About Linux Foundation
Linux Foundation is a globally leading open-source software, hardware, standards, and data collaboration platform. The projects of Linux Foundation include Linux, Kubernetes, Model Context Protocol ( MCP ), OpenChain, OpenSearch, OpenSSF, OpenStack, PyTorch, Ray, RISC-V, SPDX, and Zephyr, providing support for global infrastructure. Linux Foundation is committed to utilizing best practices and meeting the needs of contributors, users, and solution providers in order to create a sustainable open collaboration model. For more information, please visit linuxfoundation.org.
Linux Foundation is a registered trademark and is in use. For a list of its trademarks, please refer to the Trademark Usage page: www.linuxfoundation.org / trademark-usage. Linux is a registered trademark of Linus Torvalds.
Media Contact
Grace Lucier
The Linux Foundation[ email protected ]









