The OSTIF Impact Report for the Cloud Native Computing Foundation

Open Source Technology Improvement Fund (OSTIF) is proud to share the Cloud Native Computing Foundation (CNCF) Impact Report for 2022. This report is a follow-up to our August 2022 post and is based on CNCF’s strong commitment to improving security posture of projects, a sound guiding policy and project maturity…

Continue ReadingThe OSTIF Impact Report for the Cloud Native Computing Foundation

The OSTIF Independent Security Audit Impact Report

Today OSTIF is thrilled to release the Independent Security Audit Impact Report.  This report is the culmination of over a year’s worth of work that OSTIF organized thanks to funding from Google and OpenSSF.  “I am extremely proud of this work and what OSTIF continues to accomplish. Organizations like Google,…

Continue ReadingThe OSTIF Independent Security Audit Impact Report

The OSTIF Audit of Curl with Trail of Bits is Complete

Results of curl Security Audit  By: Amir Montazery, OSTIF Open Source Technology Improvement Fund (OSTIF) is thrilled to announce the results of a security audit and threat model for curl. In development since 1998, curl is a command line tool and library for transferring data with URLs. Curl is used…

Continue ReadingThe OSTIF Audit of Curl with Trail of Bits is Complete

Our Audit of Python-TUF is Complete. Multiple Issues Found and Fixed

Open Source Technology Improvement Fund is thrilled to report the results of another security audit. Python-TUF is a reference implementation written in Python for The Update Framework (TUF); a framework for secure content delivery and updates. The primary result of the work is one medium and four low-severity issues. Details…

Continue ReadingOur Audit of Python-TUF is Complete. Multiple Issues Found and Fixed

OSTIF Partners with Omidyar Network

Open Source Technology Improvement Fund is thrilled to announce its first philanthropic partnership with Omidyar Network (ON). OSTIF is joining a strong network of open source advocates and specialists under the ON portfolio to further the Open and Secure Internet Ecosystem. “This is a significant accomplishment for OSTIF and expands…

Continue ReadingOSTIF Partners with Omidyar Network

Our Audit of Argo is Complete. Critical and High Severity Security Issues Found and Fixed.

Open Source Technology Improvement Fund is happy to report the results of yet another security audit, this time of the Argo project. The Argo project is a collection of tools for getting work done with Kubernetes. The main components of Argo audited are:  Argo Workflows - Container-native Workflow Engine Argo…

Continue ReadingOur Audit of Argo is Complete. Critical and High Severity Security Issues Found and Fixed.

Our Audit of KubeEdge is Complete. Multiple Security Issues Found and Fixed.

Open Source Technology Improvement Fund (ostif.org) is thrilled to report the results of a security audit of KubeEdge. KubeEdge is an edge computing framework built on top of Kubernetes and extends native containerized application orchestration and management to hosts at the edge. The result of this engagement is the finding…

Continue ReadingOur Audit of KubeEdge is Complete. Multiple Security Issues Found and Fixed.

OSTIF has Received Another Contribution from DuckDuckGo

Duckduckgo, the privacy search engine, has contributed to OSTIF for a second time by donating $25,000 USD. Their site that tracks their charitable donations Spread Privacy has the official announcement. These funds are not allocated to any specific project, which helps OSTIF tremendously by allowing us to spend resources on…

Continue ReadingOSTIF has Received Another Contribution from DuckDuckGo

OSTIF is working with the Open Source Security Foundation on Symfony

  • Post category:NewsSecurity

OSTIF has been working with the Open Source Security Foundation's Securing Critical Projects working group to help identify critical pieces of infrastructure that require focused security attention. Symfony, a widely used PHP framework has consistently been near the top of multiple reports, underscoring the criticality of the project to the…

Continue ReadingOSTIF is working with the Open Source Security Foundation on Symfony