CyberzSOC

Publication detail
← Back to advisories & guidance

Open Source Software: Security Principles and Practices ↗ source

July 30, 2026 CISA Advisory

Summary

practices for contributing to OSS projects. These recommendations are rooted in software development and software supply chain risk management best practices and are tailored to address the benefits and risks unique to OSS. Agencies should implement the practices and processes outlined in this guidance

News Coverage

No coverage found in monitored research blogs or news feeds.

CVEs Referenced in This Publication

CVECVSSAffected
CVE-2021-44228 10.0 Critical Apache Log4j2 Apache Log4j2 contains a vulnerability where JNDI features do not protect against attacker-controlled JNDI-related endpoints, allowing for remote cod…
CVE-2024-3094 10.0 Critical — Malicious code was discovered in the upstream tarballs of xz, starting with version 5.6.0. Through a series of complex obfuscations, the liblzma bu…

Extracted from the publication text. Each CVE links to its tracked detail page.

Vendors Named in This Publication

Each vendor links to its Known Exploited Vulnerabilities catalog page. Only vendors that appear in the KEV catalog are listed, either because the publication cites one of their KEV entries or because it names them directly.