As it came up in a few conversations during "FOSDEM week", here's a link to the OpenSSF blog post about why the idea of "attestation for open source projects" is, in my opinion, and others, a bad idea:
openssf.org/blog/2026/01/21/pr…
Yes, FOSS foundations and projects need ways of getting funding, that is very important, but thinking that "attestation is how we will get that money!" might not be such a good idea given the risks involved, and the past experience for those that have attempted it.
reshared this
Soren Stoutner
in reply to vuji • • •That’s not behavior I have ever seen. If you would like help figuring it out, you can open a bug report at:
redmine.stoutner.com/projects/…
Issues - Privacy Browser Android - Stoutner - Redmine
redmine.stoutner.comvuji
in reply to Soren Stoutner • • •Soren Stoutner reshared this.