Join us

ContentUpdates from The Open Source Security Foundation (OpenSSF) is a...
News FAUN.dev() Team Trending
@kala shared an update, 5 months, 2 weeks ago
FAUN.dev()

Anthropic unveils three infrastructure bugs behind Claude's performance issues

Anthropic resolves infrastructure bugs affecting Claude AI performance, revises processes to prevent future disruptions across AWS, NVIDIA, and Google platforms.

News FAUN.dev() Team
@kala shared an update, 5 months, 2 weeks ago
FAUN.dev()

ChatGPT Launches Interactive Apps with New Apps SDK Preview

ChatGPT

ChatGPT introduces an app ecosystem with an Apps SDK Preview, enabling developers to create interactive applications integrated into conversations, initially available to non-EU users with partners like Booking.com and Spotify.

News FAUN.dev() Team
@kala shared an update, 5 months, 2 weeks ago
FAUN.dev()

Google DeepMind Launches Gemini 2.5 Model for Enhanced API Performance

Google DeepMind releases Gemini 2.5 model, enhancing API performance for browser and mobile tasks with lower latency and improved UI interaction.

News FAUN.dev() Team
@kala shared an update, 5 months, 2 weeks ago
FAUN.dev()

Anthropic Launches Petri: Open-Source Tool for AI Safety Audits

Anthropic introduces Petri, an open-source tool for automating AI safety audits, revealing risky behaviors in leading language models.

News FAUN.dev() Team
@devopslinks shared an update, 5 months, 2 weeks ago
FAUN.dev()

Qovery Secures $13M Series A to Boost DevOps Automation Platform

Kubernetes

Qovery raises $13M Series A to enhance its DevOps automation platform, addressing the DevOps engineer shortage and supporting regional expansion and AI-driven development.

Story
@laura_garcia shared a post, 5 months, 2 weeks ago
Software Developer, RELIANOID

Japan’s new Active Cyberdefence Law

Japan’s new Active Cyberdefence Law (ACD) is redefining how the nation tackles cyber threats — shifting from a defensive stance to a proactive cybersecurity strategy. Key measures include: ⚙️ Authority to neutralize hostile servers 🤝 Closer public–private collaboration 📢 Mandatory breach reporting A..

Japan's Active Cyberdefence Law
Story
@laura_garcia shared a post, 5 months, 2 weeks ago
Software Developer, RELIANOID

Asia Hits 50% IPv6 Capability — A Global Milestone

- Asia has reached a major internet milestone: 50% of its systems are now IPv6 capable, positioning the region as a global leader in IPv6 user adoption. - Why this matters: - India (78.1%) and China (810M users) are driving this growth. - Historical IPv4 scarcity in Asia helped fuel early IPv6 inves..

Blog Asia reaches 50 percent IPv6 capability
Story
@laura_garcia shared a post, 5 months, 3 weeks ago
Software Developer, RELIANOID

🚀 RELIANOID is heading to it-sa Expo&Congress 2025!

📍 Nuremberg, Germany | October 7–9, 2025 🔒 Europe’s largest IT security event with 900+ exhibitors, expert talks & global networking. We’ll be there to showcase how RELIANOID helps businesses stay ahead of evolving cyber threats. 👉 See you in Nuremberg! Send us a DM to make an appointment. #itSa2025..

itsa nuremberg
Link
@faun shared a link, 5 months, 3 weeks ago
FAUN.dev()

Building a Resilient Data Platform with Write-Ahead Log at Netflix

Netflix faced challenges like data loss, system entropy, updates across partitions, and reliable retries. To address these, they built a generic Write-Ahead Log (WAL) system serving a variety of use cases like delayed queues, generic cross-region replication, and multi-partition mutations. WAL abstr.. read more  

Link
@faun shared a link, 5 months, 3 weeks ago
FAUN.dev()

Writing Load Balancer From Scratch In 250 Line of Code

A developer rolled out a fully working **Go load balancer** with a clean **Round Robin** setup—and hooks for dropping in smarter strategies like **Least Connection** or **IP Hash**. Backend servers live in a custom server pool. Swapping balancing logic? Just plug into the interface... read more  

Writing Load Balancer From Scratch In 250 Line of Code
The Open Source Security Foundation (OpenSSF) is an industry-backed foundation focused on strengthening the security of the global open source software ecosystem. It brings together major technology companies, cloud providers, open source communities, and security experts to address systemic security challenges that affect how software is built, distributed, and consumed.

OpenSSF was launched in 2021 and operates under the Linux Foundation, combining efforts from earlier initiatives such as the Core Infrastructure Initiative (CII) and industry-led supply chain security programs. Its mission is to make open source software more trustworthy, resilient, and secure by default, without placing unrealistic burdens on maintainers.

The foundation works across several key areas:

- Supply chain security: Developing frameworks, best practices, and tools to secure the software lifecycle from source to deployment. This includes stewardship of projects like sigstore and leadership on SLSA (Supply-chain Levels for Software Artifacts).

- Security tooling: Supporting and incubating open source tools that help developers detect, prevent, and remediate vulnerabilities at scale.

- Vulnerability management: Improving how vulnerabilities are discovered, disclosed, scored, and fixed across open source projects.

- Education and best practices: Publishing guidance, training, and maturity models such as the OpenSSF Best Practices Badge Program, which helps projects assess and improve their security posture.

- Metrics and research: Advancing data-driven approaches to understanding open source security risks and ecosystem health.

OpenSSF operates through working groups and special interest groups (SIGs) that focus on specific problem areas like securing builds, improving dependency management, or automating provenance generation. This structure allows practitioners to collaborate on concrete, actionable solutions rather than high-level policy alone.

By aligning maintainers, enterprises, and security teams, OpenSSF plays a central role in reducing large-scale risks such as dependency confusion, compromised build systems, and malicious package injection. Its work underpins many modern DevSecOps and cloud-native security practices and is increasingly referenced by governments and enterprises as a baseline for secure software development.