Edoardo Dusi<p>The <span class="h-card"><a href="https://social.lfx.dev/@openssf" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>openssf</span></a></span> published the <a href="https://continuousdelivery.social/tags/OSCM" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>OSCM</span></a> to help companies and organizations that use <a href="https://continuousdelivery.social/tags/OSS" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>OSS</span></a> to be more aware of the risks and benefits, and to improve their security posture. It's a set of fifteen principles that can be used as a reference to create a security strategy for OSS consumption.</p><p>Software supply chain security is a critical issue, and the <a href="https://continuousdelivery.social/tags/OpenSSF" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>OpenSSF</span></a> and <span class="h-card"><a href="https://social.lfx.dev/@linuxfoundation" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>linuxfoundation</span></a></span> are trying to raise awareness and provide guidance on this topic.</p><p><a href="https://continuousdelivery.social/tags/opensource" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>opensource</span></a> <a href="https://continuousdelivery.social/tags/security" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>security</span></a></p><p><a href="https://tech.sparkfabrik.com/en/blog/oscm-open-source-consumption-manifesto/" rel="nofollow noopener noreferrer" target="_blank"><span class="invisible">https://</span><span class="ellipsis">tech.sparkfabrik.com/en/blog/o</span><span class="invisible">scm-open-source-consumption-manifesto/</span></a></p>