Security Scanning at Foundation Scale
Learn how the Apache Software Foundation used Anthropic's Claude Mythos 5 and Project Glasswing to run AI security scans across 230 repositories at scale.
Learn how the Apache Software Foundation used Anthropic's Claude Mythos 5 and Project Glasswing to run AI security scans across 230 repositories at scale.
Learn how the Erlang Ecosystem Foundation partners with Alpha-Omega to defend open source projects against AI-driven vulnerabilities and scale CVE management.
As open source maintainers face a growing flood of vulnerability reports, Alpha-Omega and OSTIF have partnered on the Security Engineer in Residence (SEiR) program. Discover how initiatives like Project V-LAT are providing rapid triage, dedicated engineering, and sustainable security resources to critical open source ecosystems.
An update on the Drupal AI Security Initiative: how a funded fractional team is leveraging AI tooling to find, triage, and resolve open source security vulnerabilities faster.
The Perl and Raku Foundation and CPAN Security Group have launched the April Task Force—a $250,000 Alpha-Omega-funded initiative to strengthen CPAN security, streamline CVE processing, and bolster supply chain resilience for Perl ecosystems.
Alpha-Omega is evolving. We are thrilled to announce our New Seasonal Grant Framework, transitioning to a predictable four-quarter cadence that provides open source maintainers with clear timelines, synchronized community cohorts, and faster funding decisions.
Open source software underpins over 90% of modern codebases, yet we heavily rely on volunteer goodwill to secure it. Explore how direct funding initiatives like Alpha-Omega are shifting the paradigm from treating open source security as a cost to implementing it as a core strategy.
Discover the results of the PyTorch ExecuTorch security audit conducted by Trail of Bits, supported by Alpha-Omega and OSTIF. Learn about the 42 findings addressed to improve on-device inference security.
To bring top-tier, unphishable protection to the Rust Project, the Rust Foundation has mandated hardware security keys as the default for all critical infrastructure access. Read about our vendor evaluation process, rollout strategy, and future security roadmap for hardening the ecosystem.