<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/openssf-newsletter-august-2026-open-source-security-foundation-uftvr36ju" -->

---
title: OpenSSF Newsletter – August 2026 – Open Source Security...
description: The August 2026 OpenSSF newsletter rounds up CRA readiness content ahead of the September 11, 2026 reporting deadline, including an Ericsson case study on...
canonical: https://daily.dev/posts/openssf-newsletter-august-2026-open-source-security-foundation-uftvr36ju
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: OpenSSF Newsletter – August 2026 – Open Source Security Foundation | daily.dev
og:description: The August 2026 OpenSSF newsletter rounds up CRA readiness content ahead of the September 11, 2026 reporting deadline, including an Ericsson case study on...
og:url: https://daily.dev/posts/openssf-newsletter-august-2026-open-source-security-foundation-uftvr36ju
og:image: https://api.daily.dev/og/posts/UFtVr36jU.png
og:image:alt: OpenSSF Newsletter – August 2026 – Open Source Security Foundation
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# OpenSSF Newsletter – August 2026 – Open Source Security Foundation

**[OpenSSF](https://daily.dev/sources/openssf)** · 9 min read · 0 upvotes · 0 comments

## Summary

The August 2026 OpenSSF newsletter rounds up CRA readiness content ahead of the September 11, 2026 reporting deadline, including an Ericsson case study on eliminating private forks via 1,400 upstream fixes, a practitioner's guide to CRA compliance, and four new podcast episodes covering CRA strategies and open source funding. It also announces BOMHort joining the OpenSSF Sandbox, OpenBao v2.6 and v2.6.2 (with security fixes), Zarf v0.83.0, Minder v0.3.1, OSV Schema v1.9.0, Sigstore Cosign v3.1.3/v2.6.5 patching a verification bypass vulnerability, Gemara v1.5.0, and darnit's initial v0.1.0 release. Regulatory updates cover ENISA's Single Reporting Platform guidance, BSI's updated TR-03183-1, CISA's 2026 SBOM Minimum Elements, ETSI's CRA standards approval process, and EU Cybersecurity Act amendments. Upcoming events include AGNTCon + MCPCon North America, OpenSSF Community Day Europe, and KubeCon North America.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://openssf.org/newsletter/2026/08/31/openssf-newsletter-august-2026>

## Questions this post answers

### What vulnerability did Sigstore Cosign v3.1.3 fix?

Cosign v3.1.3 fixes a verification bypass vulnerability in legacy bundles, and the fix was also backported to v2.6.5 for users on the older major version. Both releases address the same underlying issue affecting signature verification for legacy Sigstore bundle formats.

_Teams verifying artifacts with cosign should track releases like this on daily.dev to avoid running a vulnerable bundle verifier._

### When is the EU Cyber Resilience Act reporting deadline and what has to be reported?

Manufacturers and open source stewards must begin reporting actively exploited vulnerabilities and severe incidents through ENISA's Single Reporting Platform starting September 11, 2026. Full CRA compliance is required by December 2027. ENISA has published FAQs, a two-page factsheet, and registration and notification guidance ahead of the deadline.

_Open source maintainers navigating CRA deadlines can follow compliance developments like this on daily.dev._

### What security fixes are included in OpenBao v2.6.2?

OpenBao v2.6.2 includes security fixes for inline authentication workflows and PKI IP SAN enforcement, along with multiple other bug fixes. This follows the v2.6 release, which added per-namespace sealing and a new workflow engine for cross-plugin communication.

_Teams running OpenBao track patch releases like this on daily.dev to stay ahead of security fixes._

## Similar posts on daily.dev

- [OpenSSF Newsletter – June 2026 – Open Source Security Foundation](https://daily.dev/posts/openssf-newsletter-june-2026-open-source-security-foundation-jgziplo2l) · OpenSSF · 0 upvotes · 0 comments
- [OpenSSF Newsletter – July 2026 – Open Source Security Foundation](https://daily.dev/posts/openssf-newsletter-july-2026-open-source-security-foundation-pfg1vkjsr) · OpenSSF · 0 upvotes · 0 comments
- [OpenSSF Newsletter – April 2026 – Open Source Security Foundation](https://daily.dev/posts/openssf-newsletter-april-2026-open-source-security-foundation-fxb6ebk7q) · OpenSSF · 1 upvotes · 0 comments
- [OpenSSF Newsletter – May 2026 – Open Source Security Foundation](https://daily.dev/posts/openssf-newsletter-may-2026-open-source-security-foundation-envxbelwn) · OpenSSF · 0 upvotes · 0 comments
- [CRA Readiness: A Practitioner’s Guide to Compliance – Open Source Security Foundation](https://daily.dev/posts/cra-readiness-a-practitioner-s-guide-to-compliance-open-source-security-foundation-5fxka16py) · OpenSSF · 0 upvotes · 0 comments

---

Tags: [#security](https://daily.dev/tags/security), [#sbom](https://daily.dev/tags/sbom)

[View this post on daily.dev](https://daily.dev/posts/openssf-newsletter-august-2026-open-source-security-foundation-uftvr36ju)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"OpenSSF Newsletter – August 2026 – Open Source Security Foundation","url":"https://daily.dev/posts/openssf-newsletter-august-2026-open-source-security-foundation-uftvr36ju","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/openssf-newsletter-august-2026-open-source-security-foundation-uftvr36ju"},"datePublished":"2026-08-31T18:25:58.987Z","dateModified":"2026-08-31T19:01:29.316Z","description":"The August 2026 OpenSSF newsletter rounds up CRA readiness content ahead of the September 11, 2026 reporting deadline, including an Ericsson case study on...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/4a8453b03342ab3b3ddab957e735c71a?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/4a8453b03342ab3b3ddab957e735c71a?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"OpenSSF","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"OpenSSF","logo":"https://media.daily.dev/image/upload/s--l6RJ5uPj--/f_auto,q_auto/v1774959959/logos/openssf?_a=BAMAMiWQ0","url":"https://daily.dev/sources/openssf"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/openssf-newsletter-august-2026-open-source-security-foundation-uftvr36ju","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":0},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"security,sbom","timeRequired":"PT9M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"OpenSSF","item":"https://daily.dev/sources/openssf"},{"@type":"ListItem","position":3,"name":"OpenSSF Newsletter – August 2026 – Open Source Security Foundation"}]}
{"@context":"https://schema.org","@type":"FAQPage","@id":"https://daily.dev/posts/openssf-newsletter-august-2026-open-source-security-foundation-uftvr36ju#faq","mainEntity":[{"@type":"Question","name":"What vulnerability did Sigstore Cosign v3.1.3 fix?","acceptedAnswer":{"@type":"Answer","text":"Cosign v3.1.3 fixes a verification bypass vulnerability in legacy bundles, and the fix was also backported to v2.6.5 for users on the older major version. Both releases address the same underlying issue affecting signature verification for legacy Sigstore bundle formats. Teams verifying artifacts with cosign should track releases like this on daily.dev to avoid running a vulnerable bundle verifier."}},{"@type":"Question","name":"When is the EU Cyber Resilience Act reporting deadline and what has to be reported?","acceptedAnswer":{"@type":"Answer","text":"Manufacturers and open source stewards must begin reporting actively exploited vulnerabilities and severe incidents through ENISA's Single Reporting Platform starting September 11, 2026. Full CRA compliance is required by December 2027. ENISA has published FAQs, a two-page factsheet, and registration and notification guidance ahead of the deadline. Open source maintainers navigating CRA deadlines can follow compliance developments like this on daily.dev."}},{"@type":"Question","name":"What security fixes are included in OpenBao v2.6.2?","acceptedAnswer":{"@type":"Answer","text":"OpenBao v2.6.2 includes security fixes for inline authentication workflows and PKI IP SAN enforcement, along with multiple other bug fixes. This follows the v2.6 release, which added per-namespace sealing and a new workflow engine for cross-plugin communication. Teams running OpenBao track patch releases like this on daily.dev to stay ahead of security fixes."}}]}
```

