Why OSTIF?

Why OSTIF? There’s a lot of misconceptions that cause stagnation when it comes to procuring and participating in security audits. How does one even begin to get an audit, much less fund it? There is too much work involved, and not enough help from the auditors. It’s just a way…

Continue ReadingWhy OSTIF?

OpenSSL Audit Complete!

OSTIF is proud to share the results of our security audit of OpenSSL. OpenSSL is a commercial-grade cryptographic communications open source library. With the help of Trail of Bits and the OpenSSL project, this project will run more securely for those looking to perform various SSL-related tasks. Audit highlights: This…

Continue ReadingOpenSSL Audit Complete!

Kuksa Audit Complete!

OSTIF is proud to share the results of our security audit of Kuksa.  Kuksa.val is an open source vehicle abstraction layer. With the help of Quarkslab and the Eclipse Foundation, this project will continue to provide in-vehicle software components for users working with in-vehicle signals in a secure and efficient…

Continue ReadingKuksa Audit Complete!

CloudCustodian Audit Complete!

OSTIF is proud to share the results of our security audit of CloudCustodian. CloudCustodian is an open source rules engine for cloud infrastructure management. Thanks to the help of Ada Logics and the Cloud Native Computing Foundation, this project underwent a third-party security audit to help strengthen CloudCustodian’s security as…

Continue ReadingCloudCustodian Audit Complete!