Alpha-Omega (AO) is an associated project of the OpenSSF, established in February 2022. AO is funded by Microsoft, Google, Amazon and Citi, with a mission to protect society by catalyzing sustainable security improvements to the most critical open source software projects and ecosystems. The project aims to build a world where critical open source projects are secure and where security vulnerabilities are found and fixed quickly.
| CARVIEW |
MEMBER ORGANIZATIONS
Premier Members
General Members
Inquire to JoinOrganizations join Alpha-Omega because they want to take an active role in improving the security of open source software models.
ABOUT ALPHA-OMEGA
Partnering with open source software project maintainers to systematically find new, as-yet-undiscovered vulnerabilities in open source code – and get them fixed – to improve global software supply chain security.
“Alpha” will work with the maintainers of the most critical open source projects to help them identify and fix security vulnerabilities, and improve their security posture.
“Omega” will identify at least 10,000 widely deployed OSS projects where it can apply automated security analysis, scoring, and remediation guidance to their open source maintainer communities.
LATEST FROM ALPHA-OMEGA
The Open Source AI Series: A security health check of 25 popular open source AI/LLM projects: Findings and lessons learned
Alpha-Omega | Blog | No Comments
Strengthening FreeBSD’s Software Supply Chain: Year Two of Alpha-Omega Support
Alpha-Omega | Blog | No CommentsLEADERSHIP TEAM
Bob Callaway
Microsoft
Michael Scovetta
Principal, Open Source
Henri Yandell
Michael Winser
Amazon Web Services
Miaolai Zhou
Microsoft
Yesenia Yser
OSS Supply Chain Security
Google
Bob Callaway
Bob Callaway is the leader of Google’s Open Source Security Team (GOSST), spearheading initiatives to bolster the security of open source software, benefiting both Google and the global community. Under his leadership, the GOSST team develops and contributes to projects that address critical areas such as supply chain integrity, observability, and vulnerability management. GOSST also plays a pivotal role in managing essential internet infrastructure services, including OSV, Sigstore, and Certificate Transparency logs. Bob’s influence extends to advisory positions in key organizations: he serves as a member of the Technical Advisory Council for the OpenSSF, is a co-founder and technical steering committee member of Sigstore, and represents Google on the Alpha-Omega project leadership team. His extensive experience includes engineering and leadership roles at Red Hat, NetApp, and IBM. Bob holds a PhD in Computer Engineering from NC State University, where he also shares his expertise as an adjunct assistant professor in the ECE department.
Principal Security PM Manager
Microsoft
Michael Scovetta
Michael Scovetta leads a security team at Microsoft, focused on understanding and addressing emerging security threats related to open source software and the ecosystem around it. He and his team do this by building security tools, advising engineering teams, and evangelizing good practices. Within OpenSSF, Michael co-leads the Alpha-Omega project and leads the Identifying Security Threats working group. Michael brings around 25 years of software engineering and security experience and earned a Master of Engineering in Computer Science from Cornell University and Bachelor of Science from Hofstra University.
AWS
Principal, Open Source
Henri Yandell
Henri specializes in large-scale organization of Open Source. Starting as a committer with Jakarta and Apache Commons projects in 2001, he has served on Apache Software Foundation legal and security committees, and as a board member. From 2007 he has led Open Source at Amazon, tackling licensing, upstreaming, company projects, and now the growing field of open source security.
Technical Strategist
Michael Winser
Open Source Program Manager
Amazon Web Services
Miaolai Zhou
Mila Zhou is an open source program manager at AWS, leading funding initiatives that provide crucial support to open source projects. Drawing from her multidisciplinary background in Digital Media Technology, Economics, and Taxation, Mila brings a unique blend of technical knowledge and financial acumen to her role. Her expertise in managing large-scale open source funding programs and measuring their impact has proven invaluable in setting metrics and providing successful examples for enterprise leadership.
Senior Security Program Manager
Microsoft
Yesenia Yser
Yesenia specializes in helping high-growth tech organizations secure the future of innovation by designing supply chain security programs that enable speed without sacrificing safety. Yesenia brings 13 years of software engineering and cybersecurity and experience spanning incident response, security tooling, software supply chain security, open source security, and AI safety—currently, empowering the world with changes for AI Safety & Security and Open Source Security at Microsoft. Within OpenSSF, she is the co-host of the “What’s in the SOSS” podcast, co-lead of the BEAR (Belonging, Empowerment, Allyship, and Representation). Yesenia holds a Bachelors of Science in Computer Science from Florida International University and a Masters of Science in Digital Forensic from University of Central Florida.
STAFF
The Linux Foundation
Michelle Favalora
The Linux Foundation
Kate Powell
The Linux Foundation
Sally Cooper
Senior Program Manager
The Linux Foundation
Michelle Favalora
Michelle Favalora is the Senior Program Manager II for Alpha-Omega, an OpenSSF associated project, leading core business operations and grantee relations. Michelle brings over 10 years of experience in project optimization and program strategy with a focus on process improvement and building teams.
Program Manager
The Linux Foundation
Kate Powell
Senior Marketing and Communications Manager
The Linux Foundation
Sally Cooper
Sally Cooper is the Senior Marketing and Communications Manager for Alpha-Omega, an OpenSSF associated project, leading all marketing and communications activities. Sally brings over 25 years of experience in technology, with expertise in making complex concepts easy to understand. She thrives in building brand awareness, fostering open source community engagement, and driving impactful social media strategies.
AN ASSOCIATED PROJECT OF THE OPEN SOURCE SECURITY FOUNDATION
Copyright © 2023 The Linux Foundation®. All rights reserved. The Linux Foundation has registered trademarks and uses trademarks. For a list of trademarks of The Linux Foundation, please see our Trademark Usage page. Linux is a registered trademark of Linus Torvalds. Privacy Policy and Terms of Use.
