Skip to main content
THE LINUX FOUNDATION PROJECTS

Alpha-Omega (AO) is an associated project of the OpenSSF, established in February 2022.  AO is funded by Microsoft, Google, Amazon and Citi, with a mission to protect society by catalyzing sustainable security improvements to the most critical open source software projects and ecosystems. The project aims to build a world where critical open source projects are secure and where security vulnerabilities are found and fixed quickly.

Learn More

MEMBER ORGANIZATIONS

Premier Members

General Members

Inquire to Join

Organizations join Alpha-Omega because they want to take an active role in improving the security of open source software models.

ABOUT ALPHA-OMEGA

Partnering with open source software project maintainers to systematically find new, as-yet-undiscovered vulnerabilities in open source code – and get them fixed – to improve global software supply chain security.

Alpha” will work with the maintainers of the most critical open source projects to help them identify and fix security vulnerabilities, and improve their security posture.

Omega” will identify at least 10,000 widely deployed OSS projects where it can apply automated security analysis, scoring, and remediation guidance to their open source maintainer communities.

LATEST FROM ALPHA-OMEGA

Slippery Zips and Sticky Tar-Pits: Security and Archives | White Paper by: Seth Larson – Python Software Foundation

| Blog | No Comments
This new white paper from Seth Larson of the Python Software Foundation explores how legacy archive formats like ZIP and tar introduce security risks, and how the Python ecosystem is…

Apache Trusted Releases platform begins second Alpha

| Blog | No Comments
Apache Trusted Releases platform begins second Alpha — October 20, 2025 The Apache Software Foundation (ASF) Tooling team advances the Apache Trusted Releases (ATR) platform to Alpha2, expanding open participation…

How I Learned to Stop Worrying and Love the VEX

| Blog | No Comments
Written by Piotr P. Karwasz of the Apache Log4j PMC and OpenRefactory collaborator, this post explores how Vulnerability Exploitability eXchange (VEX) files help determine whether vulnerabilities in third-party dependencies are…

LEADERSHIP TEAM

STAFF

AN ASSOCIATED PROJECT OF THE OPEN SOURCE SECURITY FOUNDATION