Open Source Community Involvement

Explore top LinkedIn content from expert professionals.

  • View profile for David Carlin
    David Carlin David Carlin is an Influencer

    Founder of D.A. Carlin & Company | Former Head of Risk at UNEP FI | Keynote Speaker | Empowering Sustainability Execs in the Green and Digital Transition

    187,602 followers

    📢 The Landbanking Group has just made its Ecosystem Integrity Index (EII) fully open source. This marks a major step toward making nature-related risk and impact measurable at scale! What the index includes: -           Current-state mapping across all geographies -           Global ecosystem integrity data at 300m resolution -           Python API and Google Earth Engine integration -           Open methodology aligned with nature disclosure frameworks The EII builds on concepts developed by UNEP-WCMC, and aligns with guidance from the Taskforce on Nature-related Financial Disclosures (TNFD) on Nature-related Financial Disclosures and the Nature Positive Initiative. The current EII combines functional, structural, and compositional integrity into a single score. Here’s what you can do with EII: -           Sustainability professionals can report and set targets with more data -           Financial institutions can better screen assets for nature risk -           Corporates can set quantitative, trackable nature targets -           Investors can underwrite and verify nature-based solutions As nature moves into mainstream risk management, open and transparent tools like this are likely to become indispensable! Check out the EII website for more: https://lnkd.in/eEkrZPtC #nature #TNFD #biodiversity #opendata #naturerisk #ecosystems #sustainablefinance

  • View profile for Dr. Ron Dembo

    Founder & CEO at riskthinking.AI | Founder of Algorithmics | Author of “Risk Thinking” | Lifetime Fellow, Fields Institute | Former Yale Professor, with deep expertise in Mathematical Modelling/Climate Risk

    17,969 followers

    FINALLY. The world's first true stochastic climate physical-risk system goes OPEN SOURCE. Today RiskThinking.ai is launching the Climate Risk Commons(TM): a not-for-profit, founded and funded by RiskThinking.AI, that puts the same enterprise-grade physical climate-risk platform the world's largest banks use into your hands. Free for non-commercial research. Nothing in it is a demo. What you get: ▪ The same engine that powers the world's largest financial institutions, reached through CDTexpress: 50+ climate hazards, 241 billion geospatially aligned locations, 193 countries, all IPCC emissions scenarios, 15-time horizons to 2100. ▪ The Open Climate Risk Framework™ (OCRF): the spec, asset schema, and contracts that make results comparable across teams, firms, and vendors. ▪ Ecofusion, the open reference pipeline. It runs the entire standard end-to-end on a laptop or a cluster. Apache 2.0, with terms you can hand to your legal office. ▪ Python and R SDKs, sample notebooks, a validated impact-function library, a conformance test suite, and full documentation. ▪ An environment stocked with open datasets, plus the freedom to upload your own data, models, and damage functions. What you can do with it, often in an afternoon: ▪ Load real asset or loan-book addresses and get flood, heat, and wildfire exposure for the assets you hold, not a headline figure. ▪ Stand up a CMIP7 stress test: stochastic, multi-pathway, thousands of scenarios, in a structure a supervisor can read and an auditor can follow. ▪ Design and test new damage functions, then publish results anyone can replicate, because everyone is on the same schema, conformance suite, and engine. ▪ Screen a city, infrastructure plan, or development portfolio for priority physical risks and share the method with anyone who needs it. ▪ Be among the first to work on CMIP7, the new generation of climate science. CMIP6 data stopped at 2014. One thing you do not get, because clarity cuts both ways: our proprietary high-fidelity commercial data. That stays with paying customers, and its revenue is what sustains the open platform. Same machinery, different data. That honesty is the deal. Nineteen institutions are already on board: universities and research institutes across Canada, the UK, Germany, Switzerland, Cyprus, Israel, Sweden, and Brazil, alongside the Central Bank of Brazil. Membership is free for non-commercial research. Individual researchers apply with proof of institution and a sentence on intended use. A faculty or university can enrol everyone at once with a short letter of intent. Details: www.riskthinking.org Research access: academic@riskthinking.ai   Open-source community: opensource@riskthinking.ai

  • View profile for Varun Badhwar

    Founder & CEO @ Endor Labs | Creator, SVP, GM Prisma Cloud by PANW

    24,469 followers

    As an industry, we’ve poured billions into #ZeroTrust for users, devices, and networks. But when it comes to software - the thing powering every modern business, we’ve made one glaring exception: OPEN SOURCE SOFTWARE! Every day, enterprises ingest unvetted, unauthenticated code from strangers on the internet. No questions asked. No provenance checked. No validation enforced. We assume OSS is safe because everyone uses it. But last week’s #npm attacks should be a wake-up call. That’s not Zero Trust. That’s blind trust. If 80% of your codebase is open source, it’s time to extend Zero Trust to the software supply chain. That means: • Pin every dependency. • Delay adoption of brand-new versions. • Pull trusted versions of OSS libraries where available. #Google's Assured OSS offering is a good one for this. • Assess health and risk of malicious behavior before you approve a package. • Don’t just scan for CVEs—ask if the code is actually exploitable. Use tools that give you evidence and control, not just noise. I wrote more about this in the blog linked 👇 You can’t have a Zero Trust architecture while implicitly trusting 80% of your code. It's time to close the gap and mandate Zero Trust for OSS. #OSS #npmattacks #softwaresupplychainsecurity

  • View profile for Phil Venables

    Partner - Ballistic Ventures / Senior Advisor - Warburg Pincus / 4 x CISO / 5 x Board Director / Chief Risk Officer

    74,619 followers

    OSS-Rebuild from Google. Another tool in the toolbox for mitigating open source software risks. Automation to derive declarative build definitions for existing PyPI (Python), npm (JS/TS), and Crates.io (Rust) packages. SLSA Provenance for thousands of packages across our supported ecosystems, meeting SLSA Build Level 3 requirements with no publisher intervention. Build observability and verification tools that security teams can integrate into their existing vulnerability management workflows. Infrastructure definitions to allow organizations to easily run their own instances of OSS Rebuild to rebuild, generate, sign, and distribute provenance. https://lnkd.in/eZrxKSPK

  • View profile for Mads Steinmüller

    Head of Climate and Nature @ Danske Bank Asset Management

    5,016 followers

    🛠️ Another one for all my sustainable finance colleagues. These are some of the open-source tools I use to assess climate and nature risk. My last post on open-source tools got quite a bit of traction. It seems many of us are realizing we don't need to wait for the "perfect" commercial database to start modeling risk. The open-source ecosystem is already good enough to get started assessing risk and opportunities. Here are the primary tools I use, and how they fit into a responsible investment framework: • 𝗘𝗡𝗖𝗢𝗥𝗘 & 𝗘𝗫𝗜𝗢𝗕𝗔𝗦𝗘: ENCORE is great for mapping sector-level dependencies and impacts on nature. If you combine it with EXIOBASE, you can trace those footprints right through global supply chains. (We actually overlay this with corporate revenue data to bridge the gap between supply chain impact and actual financial exposure). • 𝗪𝗥𝗜 𝗔𝗾𝘂𝗲𝗱𝘂𝗰𝘁: This is my go-to for water stress. It translates complex hydrological data into clear risk indicators, helping you spot near-term operational halts or regulatory risks before they hit a portfolio company. • 𝗧𝗵𝗲 𝗣𝗿𝗼𝘁𝗲𝗰𝘁𝗲𝗱 𝗔𝗿𝗲𝗮 𝗣𝗮𝗰𝗸: (EU Natura 2000, PAD-US, OpenStreetMap, AZE, Ramsar, Resource Watch, and many more). This mix of registries gives you a definitive boundary map of the world's most vulnerable ecosystems. Can be used for TNFD or SFDR to check if asset locations overlap with protected habitats. • 𝗣𝗙𝗔𝗦 𝗧𝗿𝗮𝗰𝗸𝗶𝗻𝗴 (Forever Pollution Project Europe & EPA Records). PFAS is the next massive wave of litigation risk. These databases map known and suspected "forever chemical" contamination sites, which is vital for screening out massive toxic clean-up liabilities. • 𝗚𝗼𝗼𝗴𝗹𝗲 𝗘𝗮𝗿𝘁𝗵 𝗘𝗻𝗴𝗶𝗻𝗲 & 𝗠𝗮𝗽𝗕𝗶𝗼𝗺𝗮𝘀: Google Earth Engine is under utilized. It is a high-resolution satellite platform that let you track land conversion on different deforestation related crops. It essentially allows you to understand if companies are in close proximity to land conversion. • 𝗪𝗼𝗿𝗹𝗱 𝗕𝗮𝗻𝗸 𝗧𝗵𝗶𝗻𝗸𝗛𝗮𝘇𝗮𝗿𝗱! – This platform provides scenario data on 10+ natural hazards (floods, wildfires, etc.). If you combine this data yourself with asset location coordinates, you can get a great picture of physical climate risk and insurance exposure. Whether you are navigating regulatory pressure or just trying to get a better handle on localized risks, these are fantastic resources to start using. What other open data sources are you using in your processes? #Responsibleinvestment #dkfinans #climaterisk #naturerisk

  • View profile for Ibrahim Haddad, Ph.D.

    Chief Open Source Officer & VP Engineering | Open Source + AI Ecosystem Strategy | Engineering Delivery at Scale | Founding ED, PyTorch Foundation | ex-VP Linux Foundation & Samsung

    7,581 followers

    🛑 Strengthening Security for Open Source Projects on GitHub 🛑 Open source security has become a priority for industries and governments, with regulations such as the US EO 14028 on cybersecurity, the EU Cyber Resilience Act (CRA), and other global efforts placing increased responsibility on maintainers & organizations to secure the software supply chain. Whether managing a small repo or a large GH org, you must take proactive steps to secure your codebases and protect your users, contributors, and ecosystem. ✅ To help with that, here’s a checklist of key security best practices that you can implement for GH-based projects: Identity and Access Management ☑️ Enforce 2FA for all org members & collaborators ☑️ Use GH's role-based access controls ☑️ Regularly audit team and member access to repositories Code Change Management ☑️ Enable branch protection rules ☑️ Use CODEOWNERS to assign reviewers for specific files or directories ☑️ Mandate signed commits using GPG or GH's verified commit signing Security During Development ☑️ Implement structured code reviews emphasizing security hygiene ☑️ Integrate GH advanced security tools (code scanning, secret scanning for credential leaks, dependabot for automated dependency updates, and vulnerability alerts) ☑️ Use the GH Advisory Database to inform dependency choices ☑️ Complement with 3rd party tools for deeper or language-specific analysis CI/CD Security: Secure GH Actions workflows by ☑️ Pinning action versions ☑️ Using permissions blocks to minimize token access ☑️ Avoiding untrusted PRs from running with secrets ☑️ Setting up ephemeral environments and ensuring artifact integrity ☑️ Monitor CI/CD pipelines as part of your attack surface Policies & Process ☑️ Publish a SECURITY .md file, include vulnerability disclosure policy & contact details ☑️ Setup a point of contact for triaging & fixing reported vulnerabilities ☑️ Use GH Security Advisories to privately coordinate fixes and publish transparent disclosures Open Source Maturity & Benchmarking ☑️ Achieve the OpenSSF Best Practices Badge https://lnkd.in/dNZ-DAjX ☑️ Run OpenSSF Scorecard https://lnkd.in/dy4DGVeK ☑️ Track progress over time using Scorecard metrics and GH Insights People & Education ☑️ Provide security training for contributors & maintainers ☑️ Use tools like Allstar to enforce security policies across your org 📕 Download ebook: "Recommended Practices for Hosting and Managing Open Source Projects on GitHub": https://lnkd.in/djf5729z. 📣 Security is a shared responsibility. The tools exist, the standards are emerging, and the open source community is better equipped than ever to defend itself. Every open source project is part of someone’s software supply chain. Acting with transparency and adopting layered security practices is part of maintaining that trust. #OSPO #OpenSource #Security The Linux Foundation Linux Foundation Japan Linux Foundation Europe OpenChain Project SPDX SBOM OpenSSF

  • View profile for David Matousek

    Agentic AI Security Leader | Creator of tachi, AOD-Kit & Agentic-Oriented Development | Risk, Compliance & Security Architecture, Commonwealth of MA

    5,167 followers

    Most teams skip threat modeling entirely. Not because they don't care about security. Because it takes weeks, costs a fortune, and by the time the report lands, the architecture has already changed twice. I got tired of watching that cycle repeat. So I built tachi, an open-source threat modeling tool that runs inside Claude Code. One command. Fifteen specialized agents dispatched based on your architecture. A full threat model in minutes instead of months. It reads whatever you have. Mermaid diagrams, prose descriptions, YAML, JSON, C4 DSL, even ASCII sketches. You don't pick the format. You just describe your system and tachi figures out what you gave it. The part I'm most proud of is the AI-aware analysis. If your architecture includes LLMs, agents, MCP servers, or tool-calling patterns, tachi automatically activates threat categories that traditional STRIDE models completely miss. Prompt injection, data poisoning, model theft, agent autonomy risks, tool abuse. These are the threats that keep showing up in production and keep getting left out of security reviews. It is early. This is an alpha release and the project is still very much in active development. But it works today, it is free, open source, and it does not require a security background to run. GitHub link in the comments.

  • View profile for Jermaine Oldham

    Sr. Director Infrastructure & Services @ TQL | AI & Cloud | Optimizing IT operations, modernizing infrastructure & spearheading digital transformation | Air Force Veteran

    10,433 followers

    📢 Recent npm attacks show we must treat open source like an untrusted network: assume nothing, verify everything, enforce guardrails.  Zero Trust for OSS — key principles: - 🚫 Default deny: don’t pull packages without approval   - 🔍 Continuous verification: monitor direct & transitive deps   - 🔐 Least privilege: remove unused/over-permissive libs   - ⚠️ Assume compromise: have rollback/patch plans   - 🔎 Visibility & provenance: SBOMs, SLSA/VEX, clear ownership Practical controls: - 📌 Pin exact versions   - 🧊 “Cool down” new packages/versions   - 📊 Use risk/health scoring (beyond CVEs)   - 🧾 Enforce SBOMs & provenance checks   - 💻 Validate in the IDE/pre-commit to stop unsafe deps early   - 🛠️ Evidence-based remediation to patch/replace fast Automation + policy enforcement in CI/PR makes this scalable. If your AppSec still trusts public packages by default—change your playbook. Zero Trust for OSS is the new baseline. https://lnkd.in/gVNm-ben

  • View profile for Abby Kearns

    Board Director & Executive Leader | Scaling Open Source & AI Platforms | Strategy & Growth | Ex-Cloud Foundry, Puppet

    7,150 followers

    The organizations least exposed to the next attack have already made 4 decisions before it happens. 1. A deliberate decision about where their open source comes from. 2. Verified build infrastructure, not inherited binaries. 3. Remediation cycles that deliver secure versions immediately following upstream patch releases. 4. Visibility deep into transitive dependencies. That is where the last attack operated. It is where the next one will be. None of those are tool decisions. They are governance decisions. And they are the ones that determine whether your security stack performs or just observes. The organizations I've watched make real progress on software supply chain risk are the ones that shifted from scan-and-pray to curate-and-govern.  Which posture describes your environment today? #SoftwareSupplyChain #OpenSourceSecurity #CISO #SecurityEngineering #RiskManagement

    • +1
  • View profile for Chris H.

    Security Leader | Founder @ Resilient Cyber | 3x Author | Veteran | Advisor

    81,214 followers

    Security Risk Evaluation in Open-Source LLM Agent Skills Agent skills continue to get a lot of attention as a new software supply chain attack vector, and rightfully so, as they are widely used with little to no governance or security rigor. This is an excellent paper that: - Digs into the gaps of existing scanners that just operate at the code layer and don't account for instruction-layer and multi-agent risks - Introduces a multi-dimensional vetting system rather than another signature matcher. - Presents "SkillsVetBench", which is a live public leaderboard on Hugging Face, using LLM-as-a-Judge to vet agent skills, with zero false negatives against 78 confirmed-malicious skills and zero false positives across 22 benign controls. - Introduces "Skills Agentic Risk Score (SARS), a five-dimensional agentic-risk metric. Really concise and excellent read on the state of Agent Skills, their (in)security, gaps of current static scanning approaches and an excellent real-time dashboard where skill files can be evaluated and ranked. https://lnkd.in/ePh69yyY

Explore categories