BOLT Security Engagement Complete!

The Open Source Technology Improvement Fund is proud to share the results of our security work on the BOLT binary scanner for LLVM.  LLVM is an open source compiler for translating human-readable source code for machine-readable hardware. In 2024, Arm engineer Kristof Beyls developed a static binary analyzer on BOLT,…

Continue ReadingBOLT Security Engagement Complete!

Hack to the Future: The Impact and Legacy of the DARPA AIxCC Challenge

AIxCC Competition Background & Results:  In 2023, DARPA announced a two-year long competition called the Artificial Intelligence Cyber Challenge (AIxCC) with the goal to safeguard open source software used in critical infrastructure throughout America. The intent is to hasten the development of open source AI tooling that can assist developers…

Continue ReadingHack to the Future: The Impact and Legacy of the DARPA AIxCC Challenge

Requests, CacheControl, and urllib3 Audits Complete!

The Open Source Technology Improvement Fund is proud to share the results of our security audit of Requests, CacheControl, and urllib3. Requests is a widely used, elegant HTTP library for Python, designed to make HTTP requests simple and human-friendly, CacheControl is a port of the caching algorithms from httplib2 for…

Continue ReadingRequests, CacheControl, and urllib3 Audits Complete!

DEfO Audit Complete!

The Open Source Technology Improvement Fund is proud to share the results of our security engagement on Developing ECH for OpenSSL (“DEfO”). DEfO is an open source implementation of Encrypted Client Hello (ECH) for OpenSSL, and provides proof-of-concept implementations for various clients and servers that use OpenSSL as a demonstration…

Continue ReadingDEfO Audit Complete!

Sovereign Tech Agency and OSTIF Security Audit Report

OSTIF is a proud participant in the Sovereign Tech Agency's Sovereign Tech Resilience Program. Outside of that work, we've also been funded to carried out ad hoc security engagements on critical open source software. Funding security solutions that are quantifiable, sustainable, and verifiable is an important part of the Sovereign…

Continue ReadingSovereign Tech Agency and OSTIF Security Audit Report

2025 Annual Report

2025 marked the 10th year of OSTIF. This year, we published 24 audits, worked on behalf of almost 50 projects, and partnered with 10 different funding bodies to create security outcomes for open source projects. As a result, 231 findings with security impact have been reported and over 98% of…

Continue Reading2025 Annual Report