Skip to content
Open
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
132 changes: 132 additions & 0 deletions TI-reports/2026/2026-Q2-BEAR-WG.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,132 @@
# 2026 Q2 BEAR WG

[Q1 2026 TAC report](https://github.com/ossf/tac/blob/main/TI-reports/2026/2026-Q1-BEAR-WG.md)

## Overview

The BEAR WG continues our mission to increase representation and strengthen the overall effectiveness of the cybersecurity workforce. The WG continues to see relatively low regular attendance in meetings (5 attendees on avg), we are seeing increased engagement on Slack.

Over the past quarter, we've made progress in these areas:

* We hosted one Welcome Call - BEAR WG on March 26.
* Summer 2026 Mentorship Program has been the main focus of this quarter so far:
* Received a total of 270+ applications for the 4 participating projects
* Acceptances to 8 mentees were sent on May 1
* Preparing two presentations on the BEAR WG at OSS NA and OpenSSF Community Day keynote.
* Hosting a lunch meetup on Wednesday after our OSSNA talk.
* OSSAfrica represented the SIG’s work and OpenSSF at the AfricaCyberFest with a booth managed by Ejiro, Ijeoma, and Harmony, as well as Ejiro’s talk about the state of OSS in Africa.

## Welcome Calls

### Purpose

Our Welcome Calls are a monthly event in which we highlight maintainers and/or contributors from OpenSSF Projects or working groups to talk about their initiative. The goal is to allow for information sharing for new members to understand the initiative, current efforts, where the TI needs help, and how to connect. Each month, we aim to host diverse TIs to help spread the awareness of OpenSSF WGs and Projects.

### Current Status

We hosted a third Welcome Call in March featuring the BEAR WG. Since, we have unfortunately been unable to engage with other working groups interested in participating in the Welcome Calls, as well as the calls conflicting with conference dates. We are canceling our May Welcome call.

### Up Next

Find willing working groups to participate in the upcoming June and July Welcome Calls. For August, we are working with Sal and Ejiro to run the Mentorship Showcase as our welcome call.

## OpenSSF Mentorship Program

### Purpose

Hands-on experience and contributions to OSS projects are a major advantage for obtaining a job in SWE and/or cybersecurity. At the same time, mentoring and coaching experiences are increasingly viewed as important leadership skills in tech jobs. The OpenSSF Mentorship Program (via LFX) offers these experiences and opportunities to students and individuals from underrepresented groups to boost the skills they need to enter the cybersecurity workforce, and to OpenSSF project maintainers wishing to grow their community by mentoring rising developers.

### Current Status

* Acceptances to 8 mentees were sent May 1:
* gittuf: 2
* RSTUF: 3
* Minder: 1
* SBOMit: 2
* Mentees will be onboarding until June 1

### Up Next

* Mentorship to run June 1-August 21 (12 weeks)
* Ejiro Oghenekome and Sal Kimmich to step in as interim co-chairs July-August 2026.
* Mentees will showcase their projects during the August Welcome Call (coordinated by Sal and Ejiro)
* Kate and Yesenia will follow up while Marcela is out June-August.
* Kate will support once Yesenia is out in August.

## Conference Participation

### Purpose

Members of the OpenSSF BEAR WG community present talks and panel discussions at major industry conferences to raise awareness about the WG and to engage with folks beyond the OpenSSF. A primary goal of the talks and panels is to share their experiences and advice for newcomers to the OSS and cybersecurity space.

### Current Status

We had two talks accepted at OSS NA and OpenSSF Community Day:

* OSS NA: BEAR-ing Fruit: How OpenSSF’s Working Group Is Diversifying Open Source Security
* OpenSSF Community Day Keynote: BEAR-ing Fruit: A Year of Learning, Mentorship, and Community Building in Open Source Security

In addition, we plan to host a BEAR Lunch Meetup on Wednesday during OSS NA.

### Up Next

Most conference participation for the remainder of the year will flow through the OSSAfrica and DelRev SIGs. We will revisit conferences in the later part of 2026 and early 2027.

## OSSAfrica SIG

### Purpose

The SIG is dedicated to fostering collaboration, education, and innovation in open source software and cybersecurity throughout Africa. Our goal is to empower African developers, security professionals, and enthusiasts to contribute to and benefit from the global open source ecosystem.

### Current Status

In the remainder of Q1 2026 and throughout Q2, the SIG:

* Ramped up social media engagement to increase awareness of OpenSSF technical and non-technical initiatives.
* Participated in [AfricaCyberFest](https://africacyberfest.com/) on May 2 in Lagos, Nigeria with a talk (Ejiro Oghenekome) and a booth (Ijeoma Onwuka and Harmony Elendu)
* Hosted a webinar "Advancing Open Source Security in Africa: OpenSSF and OSSAfrica" on March 27 with panelists Abigail Mesrenyame Dogbe, Aaron Will Djaba, Marcela Melara and David Wheeler. Host: Prince Oforh Asiedu
* Worked on some pre-sandbox projects and have some working prototypes
* [Skillguard](https://github.com/ossafrica/skillguard): Security Scanner For AI Agent Skills

### Up Next

EDIT 5/14 post-TAC meeting: After internal discussions among the SIG and BEAR WG leadership, and identifying irreconcilable differences, the OSSAfrica initiative has decided to break it's affiliation with OpenSSF towards establishing an independent organization. The BEAR WG does remain committed to supporting the growing OSS/cybersecurity community across Africa, so the WG is in the process of establishing a separate OpenSSF Africa SIG within the WG. The WG co-chairs wish the OSSAfrica group leads all the best in the next chapter of their initiative!

## DevRel SIG

### Purpose

* Demonstrate the value proposition of making developer's lives easier and reduce perceived workload of OpenSSF
* Increase community engagement with OpenSSF Technical Initiatives and Events.
* Increase awareness and visibility of OpenSSF, its projects, tools, initiatives.
* Increase non-member contributions / participation
* Increase adoption

### Current Status

* Two DevRel community sessions accepted at Open Source Summit NA / cdCon (May 18–20, Minneapolis) — see Up Next for details
* Work underway to build CFP support and speaker resources so Ambassadors and other community members can effectively represent OpenSSF technical initiatives at external events.

### Up Next

* DevRel community meeting May 14 11:30am ET
* Two sessions from DevRel community members (Katherine Druckman (JetBrains), Stacey Potter (OpenSSF), Tabatha DiDomenico (G-Research), Kadi McKean (ReversingLabs)) at cdCon (May 18–20, Minneapolis), both Room 200C, Tuesday May 19:
* Bring Your Lunch, We'll Bring Our Notebooks: Securing Software Workflows — 12:45pm CDT — Open-floor feedback session with project maintainers in the room — no slides, no pitches.
* Security Things: How OpenSSF's Technical Initiatives Keep You Safe From the Upside Down! — 2:10pm CDT — Real supply chain problems mapped to OpenSSF solutions, with lightning-round demos from Working Group Leads and Project Maintainers.

## Funding requests and updates

The [LFX Mentorship (summer cycle ‘26)\]([https://github.com/ossf/tac/issues/573](https://github.com/ossf/tac/issues/573)) request has been closed upon the acceptance of 8 summer mentees. Mentees will be paid in two installments following successful 6-week and final 12-week reviews.

No new requests at this time.

## Questions/Issues for the TAC

* Welcome Calls: We have been struggling to get responses from other WGs willing to host a Welcome Call. Would love the TAC’s help in promoting these as part of our more general community onboarding resources.
Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think the quarterly TAC reviews would be a good opportunity for us to advertise this and incite TIs to sign up for it.

* OSSAfrica SIG would like to host software projects (TAC process for SIG-sponsored projects isn’t 100% clear) — should the SIG follow the regular Project Sandbox process?
Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Is it too much of a burden for a SIG to have their WG own this?

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

At least in the context of OSSAfrica, I think this just became a moot point, since the group has decided to leave OpenSSF.


## Additional Information

* Reminder: Marcela is planning to go on 12-week parental leave on/about the first week of June.
* Reminder: Yesenia is planning to go on parental leave on/about the beginning of August. More details to follow.
* There will be about a 3 meeting gap between Yesenia leaving and Marcela returning. Our idea is to cancel the BEAR WG calls until Marcela returns with Ejiro Oghenekome and Sal Kimmich serving as interim co-chairs to support the August Mentorship Showcase.