







Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Tock OS A Rust Based Open Platform for Transparent and Secure Root of Trust Devices
Genode - Genode Operating System Framework
We understand the complexity of code and policy as the most fundamental security problem shared by modern general-purpose operating systems. Because of high functional demands and dynamic workloads, however, this complexity cannot be avoided. But it can be organized. Genode is a novel OS architecture that is able to master complexity by applying a strict organizational structure to all software components including device drivers, system services, and applications. The Genode OS framework is an open-source tool kit for building highly secure component-based operating systems. It scales from embedded devices to dynamic general-purpose computing.
Hackathon on Decentralised Media - TEP (Trusted European Platforms) Bluesky, Nostr · Luma
Every year, thousands of developers of free and open-source software from all over the world gather at FOSDEM. For two weeks around this event – from the 26th…
OpenFang — The Agent Operating System
Open-source Agent OS built in Rust. 7 autonomous Hands. 16 security layers. 40 channels. 27 providers. Single binary. Battle-tested.
oss-security - Re: CVE request: io_uring zcrx freelist OOB write
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Histomat of F/OSS: We should reclaim LLMs, not reject them
A few days ago, I came across a blog post titled On FLOSS and training LLMs that articulates a growing frustration within the free and open source software…
I can haz smoller NixOS ISOs? | natkr's ramblings
In which I painstakingly remove functionality from a Linux live image. Like a normal person.
imput
We develop private, efficient, and respectful software. We also do security research, reverse engineering, and develop network services.
AI-SLOP: Develop best current practises for Open Source maintainers · Issue #178 · ossf/wg-vulnerability-disclosures
Open source projects are increasingly facing a wave of low-quality, AI-generated vulnerability reports and contributions—commonly referred to as "AI-slop." This issue aims to develop best...
Developer Ecosystems for Software Safety
How to design and implement information systems so they are safe and secure is a complex topic. Both high-level design principles and implementation guidance for software safety and security are well established and broadly accepted. For example, Jerome Saltzer and Michael Schroeder’s seminal overview of principles of secure design was published almost 50 years ago,10 and various community and governmental bodies have published comprehensive best practices about how to avoid common software weaknesses—for example, Common Weakness Enumeration (CWE)a and Open Worldwide Application Security Project (OWASP) Cheat Sheet Series.b

The GNU Operating System and the Free Software Movement
Since 1983, developing the free Unix style operating system GNU, so that computer users can have the freedom to share and improve the software they use.
Linux distributions worldwide targeted by the Copy Fail exploit
An exploit for the "Copy Fail" security vulnerability (CVE-2026-31431) in the Linux kernel has been made public. The vulnerability affects all major Linux

The just-announced Open Source Endowment is now on Bluesky, and we're open to your ideas on how to identify critical OSS projects 🙏
Open Source Endowment
We heard the Bluesky community cares about Open Source, so we showed up 👋 Our endowment dedicated to supporting Open Source maintainers is already at $729k, and we're developing a model for distributing our first funding round. Have ideas on how to identify critical OSS projects? We're listening.
Install Spider on Linux | Flathub
wimpysworld/sidra
Install Buffer on Linux | Flathub
johnfactotum/runemaster
Install Gear Lever on Linux | Flathub
Install Concessio on Linux | Flathub