Logback Audit Complete!

OSTIF is proud to share the results of our security audit of Logback.  Logback is an inclusive, fast, and adaptable logging framework for Java. With the help of 7ASecurity and the Sovereign Tech Agency, this project continues to provide reliable and flexible architecture for Java applications.  Audit Process: This engagement…

Continue ReadingLogback Audit Complete!

Linkerd Audit Complete!

The Open Source Technology Improvement Fund (OSTIF) is proud to share the results of our security audit of Linkerd. Linkerd is an open source service mesh for Kubernetes which prioritizes reliability, security, and simplicity. Thanks to the help of 7ASecurity and the Cloud Native Computing Foundation, this project can continue…

Continue ReadingLinkerd Audit Complete!

OSTIF 2024 Annual Report

2024 was the 9th year of OSTIF, and what an exciting and groundbreaking year it was! Our annual report for 2024 starts with the OSTIF story then moves onto our impact, function, partnerships, funding, and future. We didn’t mince words here- it’s a quick read of less than five minutes.…

Continue ReadingOSTIF 2024 Annual Report

Notary Project Cryptography Audit Complete!

OSTIF is proud to share the results of our second security audit of Notary Project. Notary Project is “a set of specifications and tools intended to provide a cross-industry standard for securing software supply chains by using authentic container images and other OCI artifacts.”* With the help of Quarkslab and…

Continue ReadingNotary Project Cryptography Audit Complete!

Karmada Audit Complete!

OSTIF is proud to share the results of our security audit of Karmada. Karmada is an open source Kubernetes orchestration system for running cloud-native applications seamlessly across different clouds and clusters. With the help of Shielder and the Cloud Native Computing Foundation (CNCF), this project offers users improved open, multi-cloud,…

Continue ReadingKarmada Audit Complete!

2024 Sovereign Tech Agency/OSTIF Audit Impact Report

Open Source Technology Improvement Fund (OSTIF) is proud to share the results of our 2024 security audit collaboration with the Sovereign Tech Agency. The Sovereign Tech Agency has invested millions of Euros into technology improvement and hardening over the past two years, notably through their Sovereign Tech Resilience program. OSTIF…

Continue Reading2024 Sovereign Tech Agency/OSTIF Audit Impact Report

2024 CNCF/OSTIF Independent Security Audit Impact Report

OSTIF is proud to share the results of our 2024 security audit collaboration with the Cloud Native Computing Foundation (CNCF). Over the past three years, OSTIF and the CNCF have worked together to provide security audits for CNCF projects. These projects, as a part of the CNCF landscape, must undergo…

Continue Reading2024 CNCF/OSTIF Independent Security Audit Impact Report

OSTIF Receives a Fourth Yearly Donation from DuckDuckGo

For a fourth year in a row, DuckDuckGo has generously donated to the Open Source Technology Improvement Fund (OSTIF) as part of its annual charitable donations program.  Funding administrative overhead as a small nonprofit is incredibly tricky. The feast-or-famine nature of nonprofit work makes it complicated to budget, as well…

Continue ReadingOSTIF Receives a Fourth Yearly Donation from DuckDuckGo