StackGen has partnered with Google Cloud Platform (GCP) to bring its platform to the Google Cloud Marketplace.
The Open Source Security Foundation (OpenSSF) announced an expansion of its free course “Developing Secure Software” (LFD121).
The course now features interactive learning scenarios to better equip developers to build software that resists modern cyberattacks.
While threats continue to evolve, secure software starts with fundamental design principles. However, OpenSSF research shows that most practitioners (69%) learn on the job and 53% have not taken courses on developing secure software. LFD121 provides developers with a simple, self-directed opportunity to learn the basics of secure software development—now with interactive labs, quizzes, and other hands-on activities to boost engagement and knowledge retention.
“OpenSSF recognizes the need for security education. Developing software to counter today’s attackers requires that software developers know how to counter them. We are constantly improving to provide broad access and better education opportunities for software developers,” said David A. Wheeler, director, open source supply chain security at OpenSSF. “We’ve created multiple labs where developers can experiment with practical techniques that counter common attacks. The labs include helpful hints to make it easy for practitioners to learn quickly and effectively.”
Secure Software Development Course Components
Since its inception, more than 25,000 individuals have enrolled in this course material; over 18,000 enrolled in LFD121, over 6,000 enrolled in LFD104x (the first section of its equivalent on edX), and over 1,000 enrolled in its Japanese translations. The virtual course is available for free on the Linux Foundation Education platform. Developers who complete the 14-18 hour course and pass the final exam will earn a certificate of completion, valid for two years. The course includes the following components:
- Part I, Requirements, Design, and Reuse: Introduces the basics of secure software development including how to implement secure design principles and how to secure your software supply chain by picking the right components and dependencies.
- Part II, Implementation: Focuses on implementation and practical steps to improve security so that developers can counter the most common kinds of attacks.
- Part III, Verification and More Specialized Topics: Discusses security testing, including static and dynamic analysis, and how to apply these tools in CI/CD pipelines. It also discusses more specialized topics, such as threat modeling, fielding, and formal methods to justify that software is secure.
The easy-to-access interactive labs are optional but recommended for an enhanced education experience. No special software is required; labs launch directly in users’ web browsers, enabling an immediate hands-on experience. Once initiated, labs provide background and information on the specific task, then users are asked to complete the task and are told when they solve it. Users who get stuck can ask for a hint, which will give them a context-specific hint on how to complete the lab. These hints help users quickly move to mastery of a concept, even in programming languages they are less familiar with.
Course content is also freely available on GitHub under a Creative Commons Attribution License (CC-BY) version 4.0. Accredited Educational Institutions and OpenSSF Premier members are eligible to host this security training course on their Learning Management System (LMS) for unlimited, complimentary access for students and employees. For LMS integration details, interested parties can complete a request form.
Industry News
Tricentis announced its spring release of new cloud capabilities for the company’s AI-powered, model-based test automation solution, Tricentis Tosca.
Lucid Software has acquired airfocus, an AI-powered product management and roadmapping platform designed to help teams prioritize and build the right products faster.
AutonomyAI announced its launch from stealth with $4 million in pre-seed funding.
Kong announced the launch of the latest version of Kong AI Gateway, which introduces new features to provide the AI security and governance guardrails needed to make GenAI and Agentic AI production-ready.
Traefik Labs announced significant enhancements to its AI Gateway platform along with new developer tools designed to streamline enterprise AI adoption and API development.
Zencoder released its next-generation AI coding and unit testing agents, designed to accelerate software development for professional engineers.
Windsurf (formerly Codeium) and Netlify announced a new technology partnership that brings seamless, one-click deployment directly into the developer's integrated development environment (IDE.)
The Cloud Native Computing Foundation® (CNCF®), which builds sustainable ecosystems for cloud native software, is making significant updates to its certification offerings.
The Cloud Native Computing Foundation® (CNCF®), which builds sustainable ecosystems for cloud native software, announced the Golden Kubestronaut program, a distinguished recognition for professionals who have demonstrated the highest level of expertise in Kubernetes, cloud native technologies, and Linux administration.
Red Hat announced new capabilities and enhancements for Red Hat Developer Hub, Red Hat’s enterprise-grade internal developer portal based on the Backstage project.
Platform9 announced that Private Cloud Director Community Edition is generally available.
Sonatype expanded support for software development in Rust via the Cargo registry to the entire Sonatype product suite.
CloudBolt Software announced its acquisition of StormForge, a provider of machine learning-powered Kubernetes resource optimization.