Driver FixRecommendedSound, Wi-Fi or graphics acting up? Check drivers firstFind missing or outdated drivers fast.Check DriversOctober DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsPC HealthRecommendedCrashes, freezes, slowdowns? Check your PC nowSpot repairable issues before they interrupt work.Check PC×
Skip to content
World desk5 min

OpenSSF’s March 2021 Security Initiative Gains Commitments From Six New Members

OpenSSF added six companies in March 2021, broadening collaborative work on open-source security, vulnerability disclosure, developer tooling and software-supply-chain trust.
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

On March 9, 2021, the Open Source Security Foundation (OpenSSF) announced six new members—Citi, Comcast, DevSamurai, Hewlett Packard Enterprise (HPE), Mirantis and Snyk. Their commitments supported shared work on open-source security education, best practices, vulnerability disclosure and software-supply-chain tooling.

What the OpenSSF announcement was

OpenSSF is a Linux Foundation-hosted collaboration between technology companies and open-source stakeholders. Its purpose is to improve the security of open-source software (OSS), which underpins data centers, consumer devices and online services.

The March 9 announcement presented the six companies’ participation as an industry-wide effort rather than a single product launch. Open-source software is assembled from code maintained by many contributors and from dependencies maintained by other projects. That structure makes it difficult for an organization to understand every component it relies on, verify its provenance and respond consistently when a vulnerability appears. OpenSSF’s model is to address those problems through shared tooling, education, disclosure practices and project work.

Which companies joined in March 2021

Company Perspective or contribution emphasized in the announcement
Citi Described collaboration with the open-source community as a key part of its security strategy.
Comcast Emphasized building security into every stage of development and said it looked forward to collaborating.
DevSamurai Presented participation as a way to learn from and contribute to the wider community.
Hewlett Packard Enterprise (HPE) Pointed to the challenge of stitching trust across disparate software and hardware components.
Mirantis Stressed the value of cooperation across industries.
Snyk Highlighted giving developers access to security capabilities, responsible vulnerability disclosure and CVE assignment.

OpenSSF said it had more than 35 members and associate members contributing to working groups, technical initiatives and its governing board at the time. The Linux Foundation separately described its broader organization as having support from more than 1,000 members; that figure refers to the foundation overall, not to OpenSSF alone.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What OpenSSF was working on

The foundation organized its work into several areas, each addressing a different point in the software supply chain:

  • Securing Critical Projects: improving the security of projects whose compromise could affect large numbers of users.
  • Security Tooling: developing and improving tools that help projects and organizations find, manage and reduce security risk.
  • Identifying Security Threats: improving understanding of threats affecting open-source ecosystems.
  • Vulnerability Disclosures: making reporting and coordinated response more reliable.
  • Digital Identity Attestation: supporting ways to establish trust in software identities and related supply-chain claims.
  • Best Practices: sharing practical guidance for secure development and project maintenance.

What membership provides—and what it does not

Membership gives organizations a formal route to support OpenSSF’s collaborative agenda through participation in working groups, technical initiatives and, for some members, governance. The six companies’ statements show the range of possible contributions: funding and industry support, developer-facing tooling, education, disclosure expertise, standards-oriented work and direct project involvement.

Membership is not a prerequisite for taking part. OpenSSF’s working groups and advisory forums were designed to allow maintainers and organizations to contribute without joining as members. Public project work and published best practices can therefore provide an access route for people who need the technical output but do not have a formal membership role.

How the initiative targets supply-chain security

Making dependencies more visible

Organizations often deploy software that includes code from many upstream projects. Shared tooling and best practices can help them identify those dependencies and understand where responsibility lies when a component changes or is found to be vulnerable.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Improving the vulnerability lifecycle

Disclosure work addresses the process from the first report through validation, coordination, remediation and communication. Snyk’s reference to responsible disclosure and CVE assignment illustrates the need for a common process that gives vulnerabilities an identifiable record and helps affected users act.

Strengthening trust in build and delivery claims

Digital identity attestation focuses on linking software and supply-chain statements to verifiable identities. This is intended to help users distinguish trustworthy project, build or component information from unverified claims.

Raising the baseline for maintainers

Education and secure-development guidance can give maintainers repeatable practices for handling credentials, reviewing changes, managing releases and responding to reports. The aim is not to replace project maintainers, but to make effective security practices easier to adopt across projects with different resources.

Why industry collaboration was central

Open-source security crosses organizational boundaries. A maintainer may create the code, a vendor may package it, an enterprise may deploy it and a security researcher may discover a flaw. No single participant sees the entire chain. Kay Williams, OpenSSF governing board chair and supply-chain security lead in Microsoft’s Azure Office of the CTO, described open source as embedded in the world’s technology infrastructure and deserving dedicated security investment. HPE’s Sunil James similarly said greater industry collaboration was critical to improving OSS security.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The commitments therefore sought to combine perspectives that are often separated: enterprise risk management, developer tooling, hardware and software trust, vulnerability response and day-to-day project maintenance.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What happened after the March announcement

In a later 2021 context release, the Linux Foundation said it had raised $10 million in new investments to expand and support OpenSSF. That figure is follow-on context about the foundation’s broader support for OpenSSF; it was not part of the March 9 announcement and should not be read as a contribution amount for any of the six companies listed above.

How to participate without becoming a member

  1. Find a relevant OpenSSF working group. Choose an area that matches your role, such as critical-project maintenance, tooling, threat identification, disclosure, identity attestation or best practices.
  2. Use the advisory and public-project routes. Maintainers and organizations can contribute through working groups, advisory forums and publicly available project work without taking a membership seat.
  3. Bring a concrete security problem. Examples include dependency inventory, release integrity, vulnerability coordination or secure-development education.
  4. Contribute expertise or implementation. Useful contributions can include code, documentation, threat analysis, disclosure coordination, standards input or maintainer support.
  5. Measure the outcome. Tie the work to a practical result, such as better dependency visibility, faster vulnerability response, stronger identity evidence or improved maintenance practices.

What the announcement did not promise

  • It did not announce a consumer security product, pricing plan or guarantee that joining OpenSSF makes a project secure.
  • It did not make membership mandatory for maintainers or organizations that want to participate.
  • It did not establish that every open-source project would receive direct funding or hands-on remediation.
  • It did not identify a single tool or standard that solves software-supply-chain risk on its own.

The Bottom Line

The March 2021 commitments expanded OpenSSF’s industry coalition around a shared goal: make open-source software safer through coordinated maintenance, tooling, disclosure, identity and education work. Organizations could support that effort as members or participate through working groups and advisory forums without formal membership.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More from the Wire

  1. Shenzhen desk3 min
    HONOR Expands Beyond Smartphones With Humanoid Robot RevealHONOR said it unveiled its first humanoid robot at MWC 2026 and named shopping assistance, workplace inspections, and supportive companionship as intended uses. Later Robotics D1 claims and a reported…
  2. Cupertino desk5 min
    Apple Unveils AirPods Max 2: The Upgrade That Should Have Happened Years AgoAirPods Max 2 adds H2-powered audio features and Apple claims up to 1.5× more effective ANC, but its design, Smart Case, and 20-hour battery rating are unchanged. Wired lossless audio…
  3. Cupertino desk4 min
    Apple’s OLED Touch MacBooks Are Coming—but the Dynamic Island Is the Real GambleApple has not announced an OLED touchscreen MacBook, but reports point to high-end models arriving in late 2026 or early 2027. The reported Mac Dynamic Island could be useful, but…
Recommended PC Tool
Recommended PC Tool
Crashes, No Sound, or Screen Glitches?Free driver scan
Windows Errors? Fix Them Before They SpreadFree repair scan

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.