On March 9, 2021, the Open Source Security Foundation (OpenSSF) announced six new members—Citi, Comcast, DevSamurai, Hewlett Packard Enterprise (HPE), Mirantis and Snyk. Their commitments supported shared work on open-source security education, best practices, vulnerability disclosure and software-supply-chain tooling.
What the OpenSSF announcement was
OpenSSF is a Linux Foundation-hosted collaboration between technology companies and open-source stakeholders. Its purpose is to improve the security of open-source software (OSS), which underpins data centers, consumer devices and online services.
The March 9 announcement presented the six companies’ participation as an industry-wide effort rather than a single product launch. Open-source software is assembled from code maintained by many contributors and from dependencies maintained by other projects. That structure makes it difficult for an organization to understand every component it relies on, verify its provenance and respond consistently when a vulnerability appears. OpenSSF’s model is to address those problems through shared tooling, education, disclosure practices and project work.
Which companies joined in March 2021
| Company | Perspective or contribution emphasized in the announcement |
|---|---|
| Citi | Described collaboration with the open-source community as a key part of its security strategy. |
| Comcast | Emphasized building security into every stage of development and said it looked forward to collaborating. |
| DevSamurai | Presented participation as a way to learn from and contribute to the wider community. |
| Hewlett Packard Enterprise (HPE) | Pointed to the challenge of stitching trust across disparate software and hardware components. |
| Mirantis | Stressed the value of cooperation across industries. |
| Snyk | Highlighted giving developers access to security capabilities, responsible vulnerability disclosure and CVE assignment. |
OpenSSF said it had more than 35 members and associate members contributing to working groups, technical initiatives and its governing board at the time. The Linux Foundation separately described its broader organization as having support from more than 1,000 members; that figure refers to the foundation overall, not to OpenSSF alone.
Do these 3 things before closing this tab:
1Scan for outdated or missing drivers - takes under a minute2Clear out junk files and repair common Windows errors3Fix the driver behind crashes, sound loss and screen glitches#1 Best Overall
What OpenSSF was working on
The foundation organized its work into several areas, each addressing a different point in the software supply chain:
- Securing Critical Projects: improving the security of projects whose compromise could affect large numbers of users.
- Security Tooling: developing and improving tools that help projects and organizations find, manage and reduce security risk.
- Identifying Security Threats: improving understanding of threats affecting open-source ecosystems.
- Vulnerability Disclosures: making reporting and coordinated response more reliable.
- Digital Identity Attestation: supporting ways to establish trust in software identities and related supply-chain claims.
- Best Practices: sharing practical guidance for secure development and project maintenance.
What membership provides—and what it does not
Membership gives organizations a formal route to support OpenSSF’s collaborative agenda through participation in working groups, technical initiatives and, for some members, governance. The six companies’ statements show the range of possible contributions: funding and industry support, developer-facing tooling, education, disclosure expertise, standards-oriented work and direct project involvement.
Membership is not a prerequisite for taking part. OpenSSF’s working groups and advisory forums were designed to allow maintainers and organizations to contribute without joining as members. Public project work and published best practices can therefore provide an access route for people who need the technical output but do not have a formal membership role.
How the initiative targets supply-chain security
Making dependencies more visible
Organizations often deploy software that includes code from many upstream projects. Shared tooling and best practices can help them identify those dependencies and understand where responsibility lies when a component changes or is found to be vulnerable.
Quick wins for a faster PC:
Scan for outdated or missing drivers - takes under a minuteDriver Scan →Clear out junk files and repair common Windows errorsFree Scan →Rank #3
Improving the vulnerability lifecycle
Disclosure work addresses the process from the first report through validation, coordination, remediation and communication. Snyk’s reference to responsible disclosure and CVE assignment illustrates the need for a common process that gives vulnerabilities an identifiable record and helps affected users act.
Strengthening trust in build and delivery claims
Digital identity attestation focuses on linking software and supply-chain statements to verifiable identities. This is intended to help users distinguish trustworthy project, build or component information from unverified claims.
Rank #4
Raising the baseline for maintainers
Education and secure-development guidance can give maintainers repeatable practices for handling credentials, reviewing changes, managing releases and responding to reports. The aim is not to replace project maintainers, but to make effective security practices easier to adopt across projects with different resources.
Why industry collaboration was central
Open-source security crosses organizational boundaries. A maintainer may create the code, a vendor may package it, an enterprise may deploy it and a security researcher may discover a flaw. No single participant sees the entire chain. Kay Williams, OpenSSF governing board chair and supply-chain security lead in Microsoft’s Azure Office of the CTO, described open source as embedded in the world’s technology infrastructure and deserving dedicated security investment. HPE’s Sunil James similarly said greater industry collaboration was critical to improving OSS security.
PC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minuteBest Value
The commitments therefore sought to combine perspectives that are often separated: enterprise risk management, developer tooling, hardware and software trust, vulnerability response and day-to-day project maintenance.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.What happened after the March announcement
In a later 2021 context release, the Linux Foundation said it had raised $10 million in new investments to expand and support OpenSSF. That figure is follow-on context about the foundation’s broader support for OpenSSF; it was not part of the March 9 announcement and should not be read as a contribution amount for any of the six companies listed above.
How to participate without becoming a member
- Find a relevant OpenSSF working group. Choose an area that matches your role, such as critical-project maintenance, tooling, threat identification, disclosure, identity attestation or best practices.
- Use the advisory and public-project routes. Maintainers and organizations can contribute through working groups, advisory forums and publicly available project work without taking a membership seat.
- Bring a concrete security problem. Examples include dependency inventory, release integrity, vulnerability coordination or secure-development education.
- Contribute expertise or implementation. Useful contributions can include code, documentation, threat analysis, disclosure coordination, standards input or maintainer support.
- Measure the outcome. Tie the work to a practical result, such as better dependency visibility, faster vulnerability response, stronger identity evidence or improved maintenance practices.
What the announcement did not promise
- It did not announce a consumer security product, pricing plan or guarantee that joining OpenSSF makes a project secure.
- It did not make membership mandatory for maintainers or organizations that want to participate.
- It did not establish that every open-source project would receive direct funding or hands-on remediation.
- It did not identify a single tool or standard that solves software-supply-chain risk on its own.
The Bottom Line
The March 2021 commitments expanded OpenSSF’s industry coalition around a shared goal: make open-source software safer through coordinated maintenance, tooling, disclosure, identity and education work. Organizations could support that effort as members or participate through working groups and advisory forums without formal membership.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




