Hack to the Future: The Impact and Legacy of the DARPA AIxCC Challenge

AIxCC Competition Background & Results:  In 2023, DARPA announced a two-year long competition called the Artificial Intelligence Cyber Challenge (AIxCC) with the goal to safeguard open source software used in critical infrastructure throughout America. The intent is to hasten the development of open source AI tooling that can assist developers…

Continue ReadingHack to the Future: The Impact and Legacy of the DARPA AIxCC Challenge

Requests, CacheControl, and urllib3 Audits Complete!

The Open Source Technology Improvement Fund is proud to share the results of our security audit of Requests, CacheControl, and urllib3. Requests is a widely used, elegant HTTP library for Python, designed to make HTTP requests simple and human-friendly, CacheControl is a port of the caching algorithms from httplib2 for…

Continue ReadingRequests, CacheControl, and urllib3 Audits Complete!

2025 Annual Report

2025 marked the 10th year of OSTIF. This year, we published 24 audits, worked on behalf of almost 50 projects, and partnered with 10 different funding bodies to create security outcomes for open source projects. As a result, 231 findings with security impact have been reported and over 98% of…

Continue Reading2025 Annual Report

OpenSSF Scorecard Audit is Complete!

The Open Source Technology Improvement Fund is proud to share the results of our security audit of OpenSSF Scorecard. OpenSSF Scorecard is an open source automated testing resource to help projects continually assess security risks. With the help of ADA Logics and the OpenSSF, this project can continue to provide…

Continue ReadingOpenSSF Scorecard Audit is Complete!

OSTIF’s Audit of Equinox P2 is Complete!

The Eclipse Foundation’s Equinox P2 was audited by Include Security in November 2022. Equinox P2 is a provisioning platform, started by IBM in 2001. The Eclipse Foundation was founded three years later to act as an open, non-for-profit leader of the Eclipse Project community.  OSTIF was contacted by the Foundation,…

Continue ReadingOSTIF’s Audit of Equinox P2 is Complete!

The OSTIF Independent Security Audit Impact Report

Today OSTIF is thrilled to release the Independent Security Audit Impact Report.  This report is the culmination of over a year’s worth of work that OSTIF organized thanks to funding from Google and OpenSSF.  “I am extremely proud of this work and what OSTIF continues to accomplish. Organizations like Google,…

Continue ReadingThe OSTIF Independent Security Audit Impact Report

Our Audits of Jackson-Core and Jackson-Databind are Complete

We’re excited to report the results for the security audits of Jackson-Core and Jackson-Databind. Jackson-Core and Jackson-Databind are Java projects that are widely adopted for parsing and binding data. The security review was facilitated by Open Source Technology Improvement Fund backed by the OpenSSF and carried out by Adalogics. The…

Continue ReadingOur Audits of Jackson-Core and Jackson-Databind are Complete

Our Audit of sigstore is complete. High risk vulnerability found and fixed.

We’re excited to report the results for the security audit of sigstore.  Sigstore is a new standard for signing, verifying and protecting software; and has quickly grown into a premier tool for securing the software supply chain. The security review was facilitated by Open Source Technology Improvement Fund and carried…

Continue ReadingOur Audit of sigstore is complete. High risk vulnerability found and fixed.