<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:media="http://search.yahoo.com/mrss/"><channel><title>Open Source Security</title><link>https://blog.google/security/open-source-security/</link><description>Open Source Security</description><atom:link href="https://blog.google/security/open-source-security/rss/" rel="self"/><language>en-us</language><lastBuildDate>Mon, 21 Jul 2025 21:34:00 +0000</lastBuildDate><image><url>https://blog.google/security/open-source-security/static/blogv2/images/google.png</url><title>Open Source Security</title><link>https://blog.google/security/open-source-security/</link></image><item><title>Introducing OSS Rebuild: Open Source, Rebuilt to Last</title><link>https://blog.google/security/introducing-oss-rebuild-open-source/</link><description>Today we're excited to announce OSS Rebuild, a new project to strengthen trust in open source package ecosystems by reproducing upstream artifacts. As supply chain attac…</description><pubDate>Mon, 21 Jul 2025 21:34:00 +0000</pubDate><guid>https://blog.google/security/introducing-oss-rebuild-open-source/</guid><category>Open Source Security</category><og xmlns:og="http://ogp.me/ns#"><type>article</type><title>Introducing OSS Rebuild: Open Source, Rebuilt to Last</title><description/><site_name>Google</site_name><url>https://blog.google/security/introducing-oss-rebuild-open-source/</url></og><author xmlns:author="http://www.w3.org/2005/Atom"><name>Matthew Suozzo</name><title>Google Open Source Security Team (GOSST)</title><department/><company/></author></item><item><title>Taming the Wild West of ML: Practical Model Signing with Sigstore</title><link>https://blog.google/security/taming-wild-west-of-ml-practical-mode/</link><description>In partnership with NVIDIA and HiddenLayer, as part of the Open Source Security Foundation, we are now launching the first stable version of our model signing library. U…</description><pubDate>Fri, 04 Apr 2025 17:00:00 +0000</pubDate><guid>https://blog.google/security/taming-wild-west-of-ml-practical-mode/</guid><category>Open Source Security</category><og xmlns:og="http://ogp.me/ns#"><type>article</type><title>Taming the Wild West of ML: Practical Model Signing with Sigstore</title><description/><site_name>Google</site_name><url>https://blog.google/security/taming-wild-west-of-ml-practical-mode/</url></og><author xmlns:author="http://www.w3.org/2005/Atom"><name>Mihai Maruseac</name><title>Google Open Source Security Team (GOSST)</title><department/><company/></author></item><item><title>Announcing OSV-Scanner V2: Vulnerability scanner and remediation tool for open source</title><link>https://blog.google/security/announcing-osv-scanner-v2-vulnerability/</link><description>In December 2022, we released the open source OSV-Scanner tool, and earlier this year, we open sourced OSV-SCALIBR. OSV-Scanner and OSV-SCALIBR, together with OSV.dev ar…</description><pubDate>Mon, 17 Mar 2025 16:46:00 +0000</pubDate><guid>https://blog.google/security/announcing-osv-scanner-v2-vulnerability/</guid><category>Open Source Security</category><og xmlns:og="http://ogp.me/ns#"><type>article</type><title>Announcing OSV-Scanner V2: Vulnerability scanner and remediation tool for open source</title><description/><site_name>Google</site_name><url>https://blog.google/security/announcing-osv-scanner-v2-vulnerability/</url></og><author xmlns:author="http://www.w3.org/2005/Atom"><name>Rex Pan</name><title>Google Open Source Security Team</title><department/><company/></author><author xmlns:author="http://www.w3.org/2005/Atom"><name>Xueqin Cui</name><title>Google Open Source Security Team</title><department/><company/></author></item><item><title>OSV-SCALIBR: A library for Software Composition Analysis</title><link>https://blog.google/security/osv-scalibr-library-for-software/</link><description>In December 2022, we announced OSV-Scanner, a tool to enable developers to easily scan for vulnerabilities in their open source dependencies. Together with the open sour…</description><pubDate>Thu, 16 Jan 2025 19:06:00 +0000</pubDate><guid>https://blog.google/security/osv-scalibr-library-for-software/</guid><category>Open Source Security</category><og xmlns:og="http://ogp.me/ns#"><type>article</type><title>OSV-SCALIBR: A library for Software Composition Analysis</title><description/><site_name>Google</site_name><url>https://blog.google/security/osv-scalibr-library-for-software/</url></og><author xmlns:author="http://www.w3.org/2005/Atom"><name>Erik Varga</name><title/><department/><company/></author><author xmlns:author="http://www.w3.org/2005/Atom"><name>Vulnerability Management</name><title/><department/><company/></author><author xmlns:author="http://www.w3.org/2005/Atom"><name>Rex Pan</name><title/><department/><company/></author><author xmlns:author="http://www.w3.org/2005/Atom"><name>Open Source Security Team</name><title/><department/><company/></author></item></channel></rss>