Programming language package repositories are juicy targets for attackers as they serve billions of requests per day. For the same reason, it’s a great place for defenders to see high impact from security capabilities. And yet, each package repository ecosystem has unique community values and architecture - so how do you support developing security capabilities in ecosystems you aren't familiar with? Over the past year, the OpenSSF Securing Software Repositories Working Group has done so by providing roadmaps (like the "Principles for Package Repository Security” co-published with CISA), implementation guidance Clike our biggest success to date "Trusted Publishers for All Package Repositories”), and partnering with other organizations to fund people in these ecosystems to implement these capabilities. As a result, we've seen tremendous progress in package repository security capabilities in the past year, and a healthy roadmap for what's ahead. These new security capabilities, as well as the support framework we used to facilitate their implementation in open source ecosystems, can inform your organization's security roadmap.