Our Audit of libjpeg-turbo is Complete!

OSTIF and X41 are excited to announce the completion of our security audit of libjpeg-turbo! X-41 DSec and OSTIF collaborated in May of 2023 on a source code audit of libjpeg-turbo, the accelerated JPEG image decoding software.  The audit’s emphasis was on reviewing input validation, memory management practices, and analysis…

Continue ReadingOur Audit of libjpeg-turbo is Complete!

OSTIF’s Security Audit of Notation-duly Noted!

During the Spring of 2023, OSTIF, ADA Logics, and The Notary Project collaborated on a security audit of the new Notation libraries. Notation is a CLI project to add signatures as standard items in the registry ecosystem and to build a set of simple tooling for signing and verifying signatures. …

Continue ReadingOSTIF’s Security Audit of Notation-duly Noted!

LIBLOUIS CONTINUOUS FUZZING IMPROVEMENTS BY ADA LOGICS AND OSTIF

Open Source Technology Improvement Fund (OSTIF) is thrilled to announce the results of security improvements via improved fuzzing capabilities on the Liblouis project by ADA Logics! Liblouis is a braille translator with expansive capabilities that runs on open source code. In 2021, the project onboarded to OSS-Fuzz to perform ongoing…

Continue ReadingLIBLOUIS CONTINUOUS FUZZING IMPROVEMENTS BY ADA LOGICS AND OSTIF

Our audit of in-toto is complete!

In collaboration with X41 and in-toto, OSTIF is pleased to announce the publication of our audit of in-toto’s source code. In-toto, which has implementations in Python and Go, is a framework software for supply chain security. Integrating security and transparency through the entire process of application, in-toto’s holistic view of…

Continue ReadingOur audit of in-toto is complete!

The OSTIF Audit of Curl with Trail of Bits is Complete

Results of curl Security Audit  By: Amir Montazery, OSTIF Open Source Technology Improvement Fund (OSTIF) is thrilled to announce the results of a security audit and threat model for curl. In development since 1998, curl is a command line tool and library for transferring data with URLs. Curl is used…

Continue ReadingThe OSTIF Audit of Curl with Trail of Bits is Complete

Results of the CloudEvents Security Assessment

Open Source Technology Improvement Fund, Inc is happy to announce the results of the CloudEvents Security Assessment. CloudEvents is a specification for describing event data in a common way that simplifies event declaration and delivery across services, platforms, and beyond. CloudEvents has a robust network of contributors and active development…

Continue ReadingResults of the CloudEvents Security Assessment

Our Audit of Python-TUF is Complete. Multiple Issues Found and Fixed

Open Source Technology Improvement Fund is thrilled to report the results of another security audit. Python-TUF is a reference implementation written in Python for The Update Framework (TUF); a framework for secure content delivery and updates. The primary result of the work is one medium and four low-severity issues. Details…

Continue ReadingOur Audit of Python-TUF is Complete. Multiple Issues Found and Fixed