Logback Audit Complete!

OSTIF is proud to share the results of our security audit of Logback.  Logback is an inclusive, fast, and adaptable logging framework for Java. With the help of 7ASecurity and the Sovereign Tech Agency, this project continues to provide reliable and flexible architecture for Java applications.  Audit Process: This engagement…

Continue ReadingLogback Audit Complete!

OSTIF 2024 Annual Report

2024 was the 9th year of OSTIF, and what an exciting and groundbreaking year it was! Our annual report for 2024 starts with the OSTIF story then moves onto our impact, function, partnerships, funding, and future. We didn’t mince words here- it’s a quick read of less than five minutes.…

Continue ReadingOSTIF 2024 Annual Report

Notary Project Cryptography Audit Complete!

OSTIF is proud to share the results of our second security audit of Notary Project. Notary Project is “a set of specifications and tools intended to provide a cross-industry standard for securing software supply chains by using authentic container images and other OCI artifacts.”* With the help of Quarkslab and…

Continue ReadingNotary Project Cryptography Audit Complete!

2024 Sovereign Tech Agency/OSTIF Audit Impact Report

Open Source Technology Improvement Fund (OSTIF) is proud to share the results of our 2024 security audit collaboration with the Sovereign Tech Agency. The Sovereign Tech Agency has invested millions of Euros into technology improvement and hardening over the past two years, notably through their Sovereign Tech Resilience program. OSTIF…

Continue Reading2024 Sovereign Tech Agency/OSTIF Audit Impact Report

2024 CNCF/OSTIF Independent Security Audit Impact Report

OSTIF is proud to share the results of our 2024 security audit collaboration with the Cloud Native Computing Foundation (CNCF). Over the past three years, OSTIF and the CNCF have worked together to provide security audits for CNCF projects. These projects, as a part of the CNCF landscape, must undergo…

Continue Reading2024 CNCF/OSTIF Independent Security Audit Impact Report

Cloud Native Buildpacks Audit Complete!

OSTIF is proud to share the results of our security audit of Cloud Native Buildpacks. Cloud Native Buildpacks (or "Buildpacks") is an open source tool for making container images for any cloud directly from the application source code. With the help of Quarkslab and the Cloud Native Computing Foundation (CNCF),…

Continue ReadingCloud Native Buildpacks Audit Complete!

Reasons Why Most Audits are Still Waiting

“Audits cost too much” We’ve seen what happens in the open source ecosystem when audits are deferred – those vulnerabilities assumed to not exist are discovered, and the aftermath is a project, community, and entire ecosystem in shambles. If you ask those authors if they made the right choice deferring…

Continue ReadingReasons Why Most Audits are Still Waiting