The Open Source Security Foundation was a long time coming


years old. After years of attackers exploiting bugs in OpenSSL, Apache Struts, and countless other projects, along with our laziness in patching them, it seems that long ago we would have combined to protect the open source supply chain upon which every organization depends. But we haven't.