







How to design and implement information systems so they are safe and secure is a complex topic. Both high-level design principles and implementation guidance for software safety and security are well established and broadly accepted. For example, Jerome Saltzer and Michael Schroeder’s seminal overview of principles of secure design was published almost 50 years ago,10 and various community and governmental bodies have published comprehensive best practices about how to avoid common software weaknesses—for example, Common Weakness Enumeration (CWE)a and Open Worldwide Application Security Project (OWASP) Cheat Sheet Series.b
Open by Design: ROOST's Approach to Safety Tool Development

NSF investing in secure open-source ecosystems
Open-source software is ubiquitous, supporting artificial intelligence, data science, cloud computing, telecommunications and scientific research tools. Despite these benefits, the number of open-source developers is relatively small, and many projects lack sufficient resources, slowing the pace of innovation and making maintenance difficult. In addition, weaknesses in open-source software, such as security flaws, supply chain risks or insider threats, can spread across many connected systems. In extreme cases, these weaknesses could lead to large-scale failures that affect national or global systems.

AI-SLOP: Develop best current practises for Open Source maintainers · Issue #178 · ossf/wg-vulnerability-disclosures
Open source projects are increasingly facing a wave of low-quality, AI-generated vulnerability reports and contributions—commonly referred to as "AI-slop." This issue aims to develop best...
Ten quick tips to SNIFF out sustainable and secure scientific software
Modern computational biology depends heavily on open-source software tools, analysis pipelines, and containerized workflows developed and shared by the research community. While there is extensive guidance (including Quick Tips and Simple Rules articles) on how to build robust and sustainable scientific software, far less has been written for researchers in the role of software users evaluating whether an existing tool is reliable, secure, and sustainable enough for their work. Here we present ten quick tips to help researchers critically assess the tools they adopt. Our tips are organized around a framework that centers on key evaluation features: source, network, interaction, fit, and fragility (SNIFF). These dimensions prompt researchers to consider who maintains a tool and why, whether it is embedded in a broader ecosystem, how actively its developers and users engage, whether it matches the intended use case and licensing requirements, and how robust its dependencies and security practices are. By applying these tips, researchers can make more informed decisions, reduce the risk of relying on abandoned or insecure software, and contribute to a more sustainable scientific software ecosystem.
Codex Security: now in research preview
Codex Security is an AI application security agent that analyzes project context to detect, validate, and patch complex vulnerabilities with higher confidence and less noise.


Nicholas Carlini - Black-hat LLMs | [un]prompted 2026
Introducing gpt-oss-safeguard
OpenAI introduces gpt-oss-safeguard—open-weight reasoning models for safety classification that let developers apply and iterate on custom policies.

Laws of Software Engineering
A collection of principles and patterns that shape software systems, teams, and decisions.

AI CVE Slop: The Crisis Drowning Open Source Security
The proliferation of AI-generated vulnerability reports — commonly termed “AI slop” — has emerged as one of the most significant…
oss-security - Dirty Frag: Universal Linux LPE
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Under the hood: Security architecture of GitHub Agentic Workflows
Learn how our threat model and security architecture help teams run agents safely in GitHub Actions.

Software Security Engineer — Andrew Lilley Brinker
I’m a Principal Engineer at MITRE helping people make informed decisions about the software they depend on. I lead Hipcheck and contribute to the CVE system.

Robust Open Online Safety Tools


Scam Number Check Free Reverse Phone Lookup - Who Called Me? | Malwarebytes
taken.

EasyOptOuts - Personal Data Removal Service | Just $19.99/year

Privacy Badger

Tools from EFF's Tech Team

How to remove your images from Pimeyes search results | PimEyes