Ortelius Blog

Topics include Supply Chain Security, Vulnerability Management, Neat Tricks, and Contributor insights.

Become an Ortelius Pathfinder: Put Your Favorite Open-Source Project on the Map

Pathfinder Badge

Open source is built by people who do more than talk about problems—they put solutions into practice.

That is exactly what the new Ortelius Pathfinder Badge recognizes.

The Pathfinder Badge honors contributors who take Ortelius into the real world by implementing it for an open-source or private project. By onboarding projects into Ortelius, Pathfinders help demonstrate how software supply chain data can be connected to the applications that are actually deployed and running.

And there is an easy way to get started:

Pick your favorite open-source project and onboard it into Ortelius.

Get started today

Why We Need Pathfinders

One of the hardest problems in software security happens after deployment.

A vulnerability may be discovered in an open-source component days, months, or even years after an application has gone into production. At that point, security and development teams need to answer some very practical questions:

  • Is this vulnerable component actually being used?
  • Which applications contain it?
  • Where are those applications deployed?
  • Who owns them?
  • What needs to be fixed first?

Ortelius is designed to help answer those questions by connecting software supply chain information—including components, SBOMs, builds, releases, deployments, and vulnerabilities—into a continuously updated view of deployed applications.

But technology becomes much more valuable when people put it to work.

That is where Pathfinders come in.

Bring Your Favorite Project to Ortelius

Maybe you contribute to an Apache project. Maybe you maintain a CNCF project. Maybe there is a Linux Foundation project you use every day. Or perhaps there is a smaller open-source tool that deserves more visibility.

Bring it into Ortelius.

By onboarding a project, you help us:

  • Expand the Ortelius ecosystem.
  • Validate Ortelius against real-world software architectures.
  • Connect software supply chain and deployment data.
  • Improve SBOM and vulnerability visibility.
  • Identify new integrations and use cases.
  • Demonstrate how post-deployment vulnerability management can work in practice.

Every project teaches the community something.

And every implementation makes Ortelius stronger.

Earn the Ortelius Pathfinder Badge

Pathfinders can progress through three achievement levels:

🥉 Bronze Pathfinder Implement 1 open-source or private project.

🥈 Silver Pathfinder Implement 5 open-source or private projects.

🥇 Gold Pathfinder Implement 10 open-source or private projects.

The goal is not simply to collect badges. It is to build a community of people who are actively demonstrating better ways to understand and secure the software we depend on.

You Don’t Have to Be an Ortelius Expert

You do not need years of experience with Ortelius to become a Pathfinder.

In fact, onboarding a project is one of the best ways to learn.

Choose a project you already know. Connect its software supply chain information to Ortelius. See what works. Tell us what does not. Ask questions. Open issues. Improve documentation. Suggest integrations.

That feedback is enormously valuable.

Pathfinders help turn theoretical use cases into working examples that the rest of the community can learn from.

Help Solve a Really Difficult Problem

Post-deployment open-source vulnerability management is not an easy problem.

Modern applications can contain hundreds or thousands of open-source dependencies. Those components move through CI/CD pipelines, containers, registries, clusters, cloud platforms, edge systems, and production environments.

Then a new vulnerability appears.

Finding the CVE is often the easy part.

Understanding where the vulnerable component is actually running and how to fix it is much harder.

That is the problem the Ortelius community is working to solve.

And it is why our contributors matter so much.

To Our Contributors: Thank You

We want to thank every Ortelius committer and contributor who continues to work on this challenge.

You are helping solve one of the most difficult problems in modern software security: finding and fixing open-source vulnerabilities after software has already been deployed.

Whether you write code, improve documentation, test integrations, report issues, onboard projects, or help another contributor get started, you are moving the entire open-source ecosystem toward better software supply chain visibility and security.

You are all heroes.

Now we need a few more explorers.

Pick your favorite open-source project.

Onboard it into Ortelius.

Earn your Pathfinder Badge.

And help show the open-source community a better path toward securing the software already running in production.