As it came up in a few conversations during "FOSDEM week", here's a link to the OpenSSF blog post about why the idea of "attestation for open source projects" is, in my opinion, and others, a bad idea:

https://openssf.org/blog/2026/01/21/preserving-open-source-sustainability-while-advancing-cybersecurity-compliance/

Yes, FOSS foundations and projects need ways of getting funding, that is very important, but thinking that "attestation is how we will get that money!" might not be such a good idea given the risks involved, and the past experience for those that have attempted it.
0

If you have a fediverse account, you can quote this note from your own instance. Search https://social.kernel.org/objects/95234c66-1d2d-4b46-8800-4e24fc49af5e on your instance and quote it. (Note that quoting is not supported in Mastodon.)