The Open Source Security Foundation (OpenSSF) has announced the initial release of the Open Source Project Security Baseline (OSPS Baseline), a new initiative designed to help open-source projects enhance their security posture through tiered best practices. The OSPS Baseline aligns with global cybersecurity frameworks, including the EU Cyber Resilience Act (CRA) and NIST Secure Software Development Framework (SSDF), making it easier for maintainers and contributors to adopt practical security measures.
The OSPS Baseline provides a set of tiered security best practices designed to help open source projects improve their security posture. This initiative aligns with global cybersecurity frameworks like the EU Cyber Resilience Act (CRA) and NIST SSDF, facilitating easier adoption of security measures. Projects such as GUAC, OpenVEX, bomctl, and Open Telemetry have committed to adopting the OSPS Baseline, marking a significant step toward standardized security guidance for open source maintainers. This release aims to strengthen the security foundations of open source projects by providing clear, actionable guidelines that evolve with project needs.