BLOG
Mar 26, 2026
Measuring Least Privilege: Introducing cargo-capslock
By Adam Harvey, Senior Software Engineer, Rust Foundation In 2025, Alpha-Omega funded work by the Rust Foundation to implement an experimental tool to generate Capslock…
Mar 17, 2026
Scaling Open Source Security with AI
Open source software underpins much of today’s digital infrastructure, but securing it remains a difficult, constantly evolving challenge. As announced today, Alpha-Omega and the OpenSSF…
Mar 17, 2026
Linux Foundation Announces $12.5 Million in Grant Funding from Leading Organizations to Advance Open Source Security
Anthropic, Amazon Web Services (AWS), GitHub, Google, Google DeepMind, Microsoft, and OpenAI Join Forces with the Foundation to Invest in Sustainable Security Solutions for the…
Mar 13, 2026
Surfacing Security Advisories on crates.io: Bringing Vulnerability Data to the Point of Discovery
by Dirkjan Ochtman When Rust developers evaluate a new dependency, the first place most of them go is crates.io — the official Rust package registry.…
Feb 27, 2026
The Economics of Package Registries and Why It Matters
At FOSDEM 2026 in Brussels, Alpha-Omega co-founder Michael Winser delivered a direct message: the economics of package registries are misaligned with the security expectations placed…
Feb 17, 2026 In developer security, Eclipse Foundation, Open VSX
Strengthening supply-chain security in Open VSX
This blog was originally published on blogs.eclipse.org written by Christopher Guindon Introduction The Open VSX Registry is core infrastructure in the developer supply chain, delivering extensions developers…
Jan 21, 2026 In Alpha-Omega, Events, FOSDEM, FOSDEM-2026, Grants, Open Source Software, Security
Alpha-Omega at FOSDEM 2026: Confronting the Economics and Reality of Open Source Security
Every year, FOSDEM brings together the people who build, maintain, and depend on open source software. It is a place where hard technical problems meet…
Dec 19, 2025 In Ada Logics, Alpha-Omega, open source AI security, OSTIF
The Open Source AI Series: A security health check of 25 popular open source AI/LLM projects: Findings and lessons learned
Alpha-Omega partnered with Ada Logics and OSTIF to audit 25 widely used open source AI and LLM projects. This post shares key findings, common security…
Nov 24, 2025 In Beach Cleaning Initiative, FreeBSD Foundation, Open Source Security, software supply chain security
Strengthening FreeBSD’s Software Supply Chain: Year Two of Alpha-Omega Support
Alpha-Omega’s second year of support for the FreeBSD Foundation focuses on strengthening the security and maintenance of third party dependencies, advancing SBOM work for the…
Nov 21, 2025 In ecosystem analysis, Open Source Security, package manager data, Software Supply Chain
Documenting Package Manager Data: Insights from ecosyste.ms
ecosyste.ms released new open datasets documenting how 70+ package managers structure metadata, manifests, lockfiles, and registry APIs. This work helps strengthen software supply-chain security and…









