Trending: On-device modelsSearch
iHeartGeek
iTECH

JetBrains joins the Open Source Security Foundation

JetBrains has joined the Open Source Security Foundation as a general member, pointing to the security work that AI coding agents have added to the software supply chain.

A JetBrains card with the JetBrains logo above large white lettering reading 'JetBrains Joins the Open Source Security Foundation' on a black and magenta gradient background

JetBrains has joined the Open Source Security Foundation (OpenSSF) as a general member. OpenSSF is a cross-industry effort run through the Linux Foundation, and the membership was announced at OpenSSF Community Day Europe in Prague, alongside other new members, at the Open Source Summit Europe.

Why the IDE maker signed up

In its announcement, JetBrains argues that coding agents make code cheaper to produce and more expensive to verify, and that much of that verification is security work. It says developers need to know where their code and dependencies come from, and that AI raises new questions about trusting the models and assistants that write it. JetBrains Air, the company's tool for checking what agents produce, is where it is tackling that inside its own products.

Where it lands in OpenSSF

OpenSSF already hosts projects that many teams depend on, including Sigstore for signing and verifying software and SLSA for supply chain integrity. Its AI and machine learning security working group publishes guidance on signing machine learning models and on writing safe instructions for AI code assistants, which is where JetBrains' interests overlap most directly with work the foundation has already started.

Our opinion

Joining a foundation is cheap to announce and expensive to follow through on, and JetBrains has given itself a real job here. Its own framing is the interesting part: if the volume of agent-written code keeps climbing, the bottleneck moves from writing to verifying, and verification is exactly where supply chain tooling struggled even without AI in the loop. Sigstore and SLSA solved part of that problem for human-written software, and extending the same guarantees to model output is still unsolved. A member with an install base this large has more reason than most to help. The risk is the familiar one for working groups, where the guidance lands long after the tools that needed it have shipped.