Finding a vulnerability is only half the battle. If nobody is available to review the code or merge it those findings just sit in a queue and gather dust. The Drupal AI Security Initiative recognized this exact bottleneck. They used funding from the Alpha-Omega Security Engineer in Residence (SEiR) program to build a complete response pipeline. Rather than just paying someone to find bugs they funded a fractional team that covers every step from discovery to final merge. Read the full update on the blog by Tiffany Farriss: https://lnkd.in/gdbhNTsf Volker Dusch Open Source Technology Improvement Fund, Inc (OSTIF) Drew Webber Greg Knaddison Michael Hess
Alpha-Omega
Information Services
Building a world where critical open source projects are secure and security vulnerabilities are found and fixed quickly
About us
Alpha-Omega is an OpenSSF project, established in February 2022, with a mission to protect society by improving the security of open source software through direct maintainer engagement and expert analysis, trying to build a world where critical open source projects are secure and that security vulnerabilities are found and fixed quickly.
- Website
-
https://github.com/ossf/alpha-omega
External link for Alpha-Omega
- Industry
- Information Services
- Company size
- 11-50 employees
- Founded
- 2022
- Specialties
- open source, cybersecurity, sbom, security, and software
Updates
-
Open source package registries require structured investment to keep pace with commercial scale. The CPAN Security Group and the Perl and Raku Foundation established the April Task Force. Following the September 2025 OpenSSF open letter, the industry recognized the clear need to secure shared digital infrastructure. This task force improves the security posture of the Comprehensive Perl Archive Network (CPAN). The core objective is to prepare the ecosystem for the impact of security analysis-capable large language models. This collaborative effort relies on the expertise of Salve J. Nilsen, Stuart Mackintosh, Olaf Alders, Paul Johnson, Stig Palmquist, Leon Timmermans, Robert Rothenberg, and Timothy Legge. Read the details: https://lnkd.in/gnGzYZT3
-
-
Alpha-Omega reposted this
Open source security continues to move forward with the latest Scrutineer release. It's exciting to see how quickly Scrutineer, an Alpha-Omega project under the OpenSSF, continues to evolve as an AI-powered open source security auditing platform. This release brings a number of impactful improvements, including: 🔹 Automated recurring scans with smart skip logic 🔹 Parallel auditing for large repositories 🔹 New forensic investigation mode for compromise analysis 🔹 Repository-wide variant vulnerability detection 🔹 AI-powered evaluation and scoring improvements 🔹 Support for Swift projects and Anthropic Opus 5 🔹 Stronger scanner hardening, security checks and reliability improvements One thing I really appreciate about this project is how each release goes beyond traditional vulnerability detection, introducing capabilities that make security audits more scalable, explainable, and practical for maintainers and security teams. Kudos to Andrew Nesbitt for leading another fantastic release, along with the Alpha-Omega team, the OpenSSF community and everyone who contributed. Want to explore everything that's new? Check out the full changelog: https://lnkd.in/d_eM_YXE #OpenSource #CyberSecurity #OpenSSF #AlphaOmega #AI #DevSecOps #GitHub #Security #Scrutineer
-
Alpha-Omega reposted this
What if AI worked for maintainers instead of burying them? In the newest What's in the SOSS?, Christopher Robinson sits down with Michael Winser, co-founder of Alpha-Omega to unpack a big idea: putting AI assists directly in maintainers' hands, on their terms, as a defensive power tool instead of another firehose of low-context vulnerability slop. 🎧 Listen now: https://lnkd.in/guwBqset
-
Looking for funding to secure your open source project? Discover the new Alpha-Omega Seasonal Grant Framework. Our 12-week quarterly cycles offer predictable decision windows, collaborative security co-design, and faster capital deployment to maximize impact in the open source ecosystem. Learn more: https://lnkd.in/e5R_HMWU
-
-
The most critical work in open source is rarely the most visible. Maintainers carry a massive mental load trying to keep up with evolving security policies. The team at The Apache Software Foundation knew their contributors needed relief from manual compliance tasks. They envisioned a completely automated release process. They built Apache Trusted Releases to handle the frustrating parts of software distribution. It automates vote tabulation. It manages SBOM validation behind the scenes. A recent case study highlighted the massive impact of their work. The tool took a mountain of missing SBOM data. It turned that gap into near total compliance. Learn more: https://lnkd.in/gBEKD6mz
-
-
Open source software underpins the world’s digital infrastructure. Security is often treated as a short-term operational cost. Read the latest blog from Miaolai Z. exploring why treating open source security as a long-term strategy builds genuine ecosystem resilience. https://lnkd.in/gU6ZPDGZ
-
-
More than ever, machine learning models run directly on edge devices instead of centralized servers. Securing the infrastructure that makes this possible is critical for the open source ecosystem. The recent security audit of PyTorch ExecuTorch highlights what it takes to find vulnerabilities before they reach production. Supported by Alpha-Omega, the researchers at Open Source Technology Improvement Fund, Inc (OSTIF) partnered with Trail of Bits to conduct an audit. The engagement focused on memory safety. The team additionally reviewed file parsing. The PyTorch maintainers quickly addressed high severity issues identified during the process. Read the blog by Helen Woeste to learn more: https://lnkd.in/ggS7xRwz
-
-
Alpha-Omega reposted this
One month into the new AI Security Engineer in Residence role, Jacob Finkelman shares what's been keeping him busy at the Rust Foundation: talking with maintainers and security teams across the ecosystem, building a prioritized database of crates to scan, and running early scans with Scrutineer, plus the tricky question of when bugs should be embargoed vs. reported openly. https://lnkd.in/ewhwp-7C #rustlang
-
-
Alpha-Omega reposted this
We are proud to share the results of our security audit of PyTorch ExecuTorch. Thanks to Trail of Bits and Alpha-Omega, this project underwent a custom engagement of security review and testing. Read more on our blog- https://lnkd.in/gfkR_2qP #OSTIF #PyTorch #TrailofBits #AlphaOmega
-