security

Announcing Security Training on Vulnerability Management, SBOM and related subjects

Monday, May 19, 2025 - 09:11 by Marta Rybczynska
Do you want to know more about vulnerability management? As a developer, you might receive reports, or need to create some for your upstream projects. As a user, you might find something that could have security impacts. As a Committer, you want to know how to best manage reports your...

The Cyber Resilience Act is Here

Wednesday, November 20, 2024 - 12:02 by Mike Milinkovich
With the recent publication of the EU’s Cyber Resilience Act (CRA) in the EU official journal, a 3 year race now begins for compliance by the global technology industry. This legislation sets new cybersecurity requirements that manufacturers and the open source projects they rely upon must meet. The open source...

The Eclipse Foundation offers a free security training for all Committers and Contributors

Monday, October 21, 2024 - 11:39 by Marta Rybczynska
You know that security is important but just have no time to spend digging into numerous tutorials and guides to figure out what’s relevant to you. To support fellow developers, the Eclipse Foundation is offering free security training for all Committers and Contributors. The complete training contains three parts: the...

Securing the Future of Open Source: Launching the Open Regulatory Compliance Working Group

Tuesday, September 24, 2024 - 07:00 by Mike Milinkovich
Today marks an important milestone for the open source community. As open source software continues to drive innovation across industries, ensuring its relevance and compliance with emerging regulations has never been more critical.  To address these challenges, the Eclipse Foundation is proud to announce the formal launch of the Open...

Per-Project Security Teams FAQ

Wednesday, September 4, 2024 - 04:57 by Marta Rybczynska
In response to requests from various projects and after discussions between the Eclipse Foundation Security Team and the Architecture Council, we announced the creation of Project Security Teams (see the discussion at https://github.com/orgs/eclipse-csi/discussions/4 ) This blog post gives an overview of various questions that we have received in the last...

DO NOT USE IN PRODUCTION

Wednesday, August 28, 2024 - 00:41 by Marta Rybczynska
Do you have a demo or examples in a specific repository? Or perhaps you have a functionality that needs time to mature, and you publish it in the open source spirit, but nobody should use it (yet) in a production setup? If you have such a code, mark it clearly...

Using GitHub Private Vulnerability Reporting by Eclipse Foundation Projects

Thursday, August 8, 2024 - 14:31 by Marta Rybczynska
Eclipse Foundation projects can request to use GitHub Private Vulnerability Reporting . This feature allows committers of projects hosted on GitHub to receive potential vulnerability reports in a confidential way. When you are working on an existing vulnerability report, you might see the “Request CVE” button. Please do not use...

Update to vulnerability description - CVSS 4.0

Friday, July 26, 2024 - 02:56 by Marta Rybczynska
A vulnerability description includes several fields, like the title and description. However, one is causing difficulties for people writing CVE (Common Vulnerability Enumeration) entries: the CVSS (Common Vulnerability Scoring System) vector. CVSS is an important field because it answers a fundamental question about the vulnerability: "How serious is it?" A...