Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [thread-next>] [day] [month] [year] [list]
Message-Id: <D5B9E3F5-6C07-40DB-8303-15BE77956988@edvina.net>
Date: Fri, 23 Jan 2026 11:17:34 +0100
From: "Olle E. Johansson" <oej@...ina.net>
To: oss-security@...ts.openwall.com
Subject: Vulnerability management and Open Source: FOSDEM BoF

Hi!

We have discussed several vulnerability databases here, bad reports and AI slop. I just got a BoF session on FOSDEM granted to continue this discussion. If you are heading to Brussels next week, please mark this session in your calendar:

https://fosdem.org/2026/schedule/event/DAFMJX-vulnerability-today/


Title: Vulnerability today: What's the state of Open Source vulnerability management?

Text: The vulnerability management world is in a bit of turmoil. With the DoS-type attack AI slop is putting on Open Source projects at the same time as the funding of core systems is unsure, we need to agree on requirements for the future, ways of working and how we can handle the shift forced by the Cyber Resilience Act. Let's spend an hour talking about this and discuss ways forward.
The Global Vulnerability Intelligence Platform is a project that aims at working on a long term solution, a cooperation between OWASP, OpenSSF, Eclipse/ORCWG, OpenForum Europe with support from the Sovereign Tech Resilience project.
https://www.gvip-project.org <https://www.gvip-project.org/>

It’s part of the BOF/Unconference track. Room K.4.401 Saturday at 15:00 - 15:55


I hope to see many of you there!

/Olle

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.