Trail of Bits

Read more about the article OSTIF 2024 Annual Report

OSTIF 2024 Annual Report

2024 was the 9th year of OSTIF, and what an exciting and groundbreaking year it was! Our annual report for 2024 starts with the OSTIF story then moves onto our impact, function, partnerships, funding, and future. We didn’t mince words here- it’s a quick read of less than five minutes.…

Read more about the article Temurin Audit Complete!

Temurin Audit Complete!

OSTIF is proud to share the results of our security audit of Temurin. Temurin is an open source project for building high performing Java runtime binaries. With the help of Trail of Bits and the Eclipse Foundation, this project will continue to securely support users who develop Java codes across…

Read more about the article cURL Audit Complete!

cURL Audit Complete!

OSTIF is proud to share the results of our security audit of cURL HTTP/3. cURL is an open source command line tool and library, the most widely used HTTP client software in the world. This engagement was for the new components of HTTP/3 in cURL. With the help of Trail…

Read more about the article Securing Open-Source Infrastructure with Trail of Bits

Securing Open-Source Infrastructure with Trail of Bits

OSTIF started performing security audits in earnest in 2018, tackling a new level of involvement open source security. That same year was OSTIF’s first collaboration with security firm Trail of Bits, working together to complete an audit of RandomX. Since then our two companies have worked together on 12 security…

Read more about the article The Buzz about Mosquitto ‘s Security Audit!

The Buzz about Mosquitto ‘s Security Audit!

Open source project Mosquitto underwent a security audit with OSTIF and Trail of Bits in collaboration with the Eclipse Foundation. The project, which is a message broker for the MQTT protocol, is designed to connect the Internet of Things. Projects that are open to the internet have increased landscape exposure…

Read more about the article In-Flux-ible on bugs- Flux undergoes Security Audit with OSTIF and Trail of Bits

In-Flux-ible on bugs- Flux undergoes Security Audit with OSTIF and Trail of Bits

OSTIF is proud to announce the publication of a security audit on the Kubernetes cluster tooling Flux in collaboration with Trail of Bits. Performed over four engineer weeks, this is the second security audit with OSTIF that Flux has undertaken, the first having taken place in November 2021. Repeated security…

Read more about the article OSTIF Has Completed an Audit of Jetty!

OSTIF Has Completed an Audit of Jetty!

OSTIF is pleased to announce the completion of a security audit of Eclipse Jetty in collaboration with the Eclipse Foundation and Trail of Bits. This audit was a part of a package of work organized and managed by OSTIF to provide security engagements to Eclipse Foundation projects. With funding and…

Read more about the article OSTIF Has Completed A Security Audit of wasmCloud!

OSTIF Has Completed A Security Audit of wasmCloud!

OSTIF and wasmCloud collaborated with Trail of Bits on a security audit of the application which is a deployment platform for distributed Wasm application development. The engagement priorities are listed as, but not limited to: wasmCloud sandboxing capabilities of user-provided code, if users were appropriately limited in their accessible features…

Read more about the article JKube Security Audit Completed!

JKube Security Audit Completed!

OSTIF and Trail of Bits coordinated and executed a security audit of Eclipse JKube, an Eclipse Foundation project. Eclipse JKube is an assembly of plugins and libraries for building container images using Docker, JIB or S2I build strategies. The project escorts Java applications to Kubernetes and OpenShift by forcing through…

Read more about the article OSTIF’s Favorite Bug- DragonFly!

OSTIF’s Favorite Bug- DragonFly!

This summer, over four engineer weeks, Trail of Bits and OSTIF collaborated on a security audit of DragonFly. A CNCF Incubating Project, DragonFly functions as file distribution for peer-to-peer technologies. Included in the scope was the sub-project Nydus’s repository that works in image distribution. The engagement was outlined and framed…

Archives

Archives