OpenSSL Audit Complete!

OSTIF is proud to share the results of our security audit of OpenSSL. OpenSSL is a commercial-grade cryptographic communications open source library. With the help of Trail of Bits and the OpenSSL project, this project will run more securely for those looking to perform various SSL-related tasks. Audit highlights: This…

Continue ReadingOpenSSL Audit Complete!

Kuksa Audit Complete!

OSTIF is proud to share the results of our security audit of Kuksa.  Kuksa.val is an open source vehicle abstraction layer. With the help of Quarkslab and the Eclipse Foundation, this project will continue to provide in-vehicle software components for users working with in-vehicle signals in a secure and efficient…

Continue ReadingKuksa Audit Complete!

CloudCustodian Audit Complete!

OSTIF is proud to share the results of our security audit of CloudCustodian. CloudCustodian is an open source rules engine for cloud infrastructure management. Thanks to the help of Ada Logics and the Cloud Native Computing Foundation, this project underwent a third-party security audit to help strengthen CloudCustodian’s security as…

Continue ReadingCloudCustodian Audit Complete!

Audit of Jackson-Dataformats and Jackson-Datatypes Complete

OSTIF is proud to share the results of our security audit of Jackson subprojects. Jackson-dataformats-binary, Jackson-dataformats-text, Jackson-dataformat-xml, Jackson-datatype-joda, and Jackson-datatypes-collections are open source subprojects that contribute to Jackson (described as “JSON for Java”). With the help of Ada Logics and the Sovereign Tech Fund, these subprojects will be more secure…

Continue ReadingAudit of Jackson-Dataformats and Jackson-Datatypes Complete

OSTIF joins the Sovereign Tech Fund’s Bug Resilience Program

The Sovereign Tech Fund and the Open Source Technology Improvement Fund (OSTIF) are collaborating upon multiple security reviews for open source projects. As part of STF’s Bug Resilience Program, we are organizing and providing projects that are rooted in infrastructure with audits and engagements to reduce their open and undiscovered…

Continue ReadingOSTIF joins the Sovereign Tech Fund’s Bug Resilience Program