Alpha-Omega
The Open Source AI Series: A security health check of 25 popular open source AI/LLM projects: Findings and lessons learned
Alpha-Omega partnered with Ada Logics and OSTIF to audit 25 widely used open source AI and LLM projects. This post shares key findings, common security gaps, and lessons learned that can help strengthen the security and resilience of the open source AI ecosystem.
Strengthening FreeBSD’s Software Supply Chain: Year Two of Alpha-Omega Support
Alpha-Omega’s second year of support for the FreeBSD Foundation focuses on strengthening the security and maintenance of third party dependencies, advancing SBOM work for the FreeBSD base system, and improving long-term software supply chain resilience across the project.
Documenting Package Manager Data: Insights from ecosyste.ms
ecosyste.ms released new open datasets documenting how 70+ package managers structure metadata, manifests, lockfiles, and registry APIs. This work helps strengthen software supply-chain security and supports tools built across ecosystems, an effort closely aligned with Alpha-Omega’s mission to improve the security of critical open source.
Slippery Zips and Sticky Tar-Pits: Security and Archives | White Paper by: Seth Larson – Python Software Foundation
This new white paper from Seth Larson of the Python Software Foundation explores how legacy archive formats like ZIP and tar introduce security risks, and how the Python ecosystem is advancing protections to keep software supply chains safe. Sponsored by Alpha Omega.
Apache Trusted Releases platform begins second Alpha
Apache Trusted Releases platform begins second Alpha — October 20, 2025 The Apache Software Foundation (ASF) Tooling team advances the Apache Trusted Releases (ATR) platform to Alpha2, expanding open participation across ASF projects, including Airflow, Arrow, Grails, Logging, Maven, and Tomcat.
How I Learned to Stop Worrying and Love the VEX
Written by Piotr P. Karwasz of the Apache Log4j PMC and OpenRefactory collaborator, this post explores how Vulnerability Exploitability eXchange (VEX) files help determine whether vulnerabilities in third-party dependencies are actually exploitable. Drawing from the evolution of Log4j’s security reporting, the article traces how the lack of VEX visibility complicated dependency management—until new automation efforts,…
Alpha-Omega Endorses the Joint Statement on Sustainable Stewardship
Open source powers the modern software ecosystem, but its foundation is fragile. Package registries and their surrounding infrastructure are the backbone of the open source ecosystem, including Maven Central, PyPI,...