@ostifofficial.bsky.social
š¤ 41
š„ 26
š 63
reposted by
KubeVirt
6 days ago
We are pleased to announce that the KubeVirt Security Audit report has been published, in collaboration with
@quarkslab.bsky.social
and
@ostifofficial.bsky.social
Check out our blog post for all the details:
kubevirt.io/2025/Announc...
loading . . .
Announcing the results of our Security Audit | KubeVirt.io
As part of our application to Graduate, KubeVirt has a security audit performed by a third-party, organised through the CNCF and OSTIF.
https://kubevirt.io/2025/Announcing-KubeVirt-Security-Audit-Results.html
0
3
2
reposted by
Rey Lejano
7 days ago
#KubeCon
day 1 keynotes: Amir Montaziry from
@ostifofficial.bsky.social
talking about securing open source projects and an update on the
@kubernetes.io
audit which I helped out with along with
@iainsmart.bsky.social
0
3
1
OSTIF is proud to announce that our audit of
@kubevirt.bsky.social
is now public! This would not be possible without the contributions of Quarkslab and the Cloud Native Computing Foundation. Read about the work on our blog:
ostif.org/kubevirt-aud...
loading . . .
KubeVirt Audit is Complete! ā OSTIF.org
https://ostif.org/kubevirt-audit-complete/
11 days ago
0
1
1
Amir and Derek present Reflections on 10 Years: Celebrating the Open Source Technology Improvement Fund next Thursday, November 6th 13:00 CST. Hear our friends and collaborators in discussion with us about our past, present, and future. RSVP here:
luma.com/nudnh5sv
loading . . .
Reflections on 10 Years w/ OSTIF Ā· Luma
Description The Open Source Technology Improvement Fund is celebrating its 10th year, and we're spilling our secrets to the community! Come learn about ourā¦
https://luma.com/nudnh5sv
19 days ago
0
1
1
Boo! Publish your threat models! š» Does that scare you? Join us Wednesday, Oct 29th at 14:00 CT with
@adamshostack.bsky.social
, who will be presenting on why transparency isn't something to be frightened of. RSVP to add straight to your calendar:
luma.com/6fvp6orm
loading . . .
Threat Modeling w/ Adam Shostack Ā· Zoom Ā· Luma
Description Publish your threat models! This talk will cover the idea of publishing threat models, the dangers associated with the idea, and why open sourceā¦
https://luma.com/6fvp6orm
22 days ago
0
0
0
reposted by
Adam Shostack
22 days ago
Should we publish our threat models? I explore a different lens with OSTIF for how transparency can benefit everyone. Oct 29, 14:00 CT š
luma.com/6fvp6orm
loading . . .
Threat Modeling w/ Adam Shostack Ā· Zoom Ā· Luma
Description Publish your threat models! This talk will cover the idea of publishing threat models, the dangers associated with the idea, and why open sourceā¦
https://luma.com/6fvp6orm
0
2
1
On November 6th at 13:00 CST, we are hosting "Reflections on 10 Years with OSTIF." Not just a reflection, this is a summation of our past, present, and future. RSVP to tell us your OSTIF experience, join in the celebration, or just to see what special guests we have joining:
luma.com/nudnh5sv
loading . . .
Reflections on 10 Years w/ OSTIF Ā· Luma
Description The Open Source Technology Improvement Fund is celebrating its 10th year, and we're spilling our secrets to the community! Come learn about ourā¦
https://luma.com/nudnh5sv
about 1 month ago
0
0
0
This week's blog is "OSTIF's Strategy Plan". No holds barred, it's complete transparency of what our goals for the next 3-5 years are. If you've got 5 minutes to spare on this autumn Friday, you'll be caught up:
ostif.org/ostifs-strat...
loading . . .
OSTIFās Strategy Plan ā OSTIF.org
https://ostif.org/ostifs-strategy-plan/
about 1 month ago
0
0
0
reposted by
OpenSSF
about 1 month ago
The
@ostifofficial.bsky.social
recently completed a security audit of
#OpenSSFScorecard
. With support from the OpenSSF, this audit covered five core repositories and included threat modelling, manual code review, and fuzz testing. . Read to learn more:š
openssf.org/blog/2025/10...
0
2
1
reposted by
Adam Shostack
about 1 month ago
Publish your threat models! Not convinced? I'll be hosting a talk with OSTIF on Oct 29 @ 2pm CT for you to ask me questions. Register now and have your questions, thoughts, and comments ready!
luma.com/6fvp6orm
loading . . .
Threat Modeling w/ Adam Shostack Ā· Zoom Ā· Luma
Description Publish your threat models! This talk will cover the idea of publishing threat models, the dangers associated with the idea, and why open sourceā¦
https://luma.com/6fvp6orm
0
16
9
Join us October 29th at 14:00 CST for a meetup with
@adamshostack.bsky.social
! RSVP here:
luma.com/6fvp6orm
First Adam will present on threat models (he literally wrote *the* book on the subject) and a Q&A portion will follow. We look forward to him and our community connecting!
loading . . .
Threat Modeling w/ Adam Shostack Ā· Zoom Ā· Luma
Description Publish your threat models! This talk will cover the idea of publishing threat models, the dangers associated with the idea, and why open sourceā¦
https://luma.com/6fvp6orm
about 1 month ago
0
1
1
reposted by
The Linux Foundation
about 2 months ago
š š Cybersecurity isnāt just for CISOsāevery leader must frame cyber risk as business risk. LFās Executive Education equips senior leaders to: š¹ Turn risk into advantage š¹ Build resilient teams š¹ Leverage emerging tech apply now š
training.linuxfoundation.org/training/lfe...
#CyberRisk
loading . . .
Cybersecurity Strategy & Risk Management for Executives
This series helps leaders turn cyber risks into business strategy, driving growth, innovation, and resilience.
https://training.linuxfoundation.org/training/lfexecutive-ed-cybersecurity/
0
8
2
Duck, duck...goose (eggs)! OSTIF is honored to be a five time recipient of DuckDuckGo's Charitable Donations Program. Read about this donation and its impact on us at our blog:
ostif.org/five-years-d...
loading . . .
OSTIF Recieves a Fifth Yearly Donation from DuckDuckGo! ā OSTIF.org
https://ostif.org/five-years-duckduckgo/
about 2 months ago
0
1
0
We've got a GNU audit for you! GNU libmicrohttpd2 was audited thanks to
@sovereign.tech
and ADA Logics. The library underwent a threat modeling practice, fuzzing improvements, and a small cryptography review. Read about it on our blog:
ostif.org/gnu-libmicro...
loading . . .
GNU libmicrohttpd2 Audit Complete! ā OSTIF.org
https://ostif.org/gnu-libmicrohttpd2-audit-complete/
about 2 months ago
0
1
0
We're baaaccckkkkk... and this time, we have
@adamshostack.bsky.social
! Join us next month, Oct 29th 14:00 CST, for a meetup on threat modeling: developing them, using them, and publishing them. RSVP to attend:
luma.com/6fvp6orm
loading . . .
Threat Modeling w/ Adam Shostack Ā· Zoom Ā· Luma
Description Publish your threat models! This talk will cover the idea of publishing threat models, the dangers associated with the idea, and why open sourceā¦
https://luma.com/6fvp6orm
about 2 months ago
0
1
1
reposted by
Quarkslab
about 2 months ago
RTFM they say but if you read the manual and copy code examples from it you may inadvertently introduce vulns in your code š In April we audited the PHP code. Now we followed up with a review of the code snippets in PHP documentation and found 81 issues š
blog.quarkslab.com/security-rev...
loading . . .
Security review of PHP documentation - Quarkslab's blog
The Open Source Technology Improvement Fund, Inc., engaged with Quarkslab to perform a security audit of the code snippets in the English version of PHP documentation, focused on some specific pages.
https://blog.quarkslab.com/security-review-of-php-documentation.html
0
6
5
Join us in celebrating our first Community Spotlight honorees, David Korczynski and Adam Korczynski! Learn more about these brothers and business partners in our Community Spotlight post:
ostif.org/001-2025-com...
2 months ago
0
0
0
Start your workweek with a bit of rumination and OSTIF's latest blog post: "Open Source Summit and OpenSSF Community Day EU 2025 Reflection"
ostif.org/ossummit-com...
loading . . .
Open Source Summit and OpenSSF Community Days EU 2025 Reflection ā OSTIF.org
https://ostif.org/ossummit-commday-reflection/
2 months ago
0
0
0
@openssf.org
Community Day aka the big day for us! Amir will participating in a tabletop exercise at 15:40 and Helen will be speaking on our audit of RSTUF at 10:50. Check out the rest of the schedule here:
events.linuxfoundation.org/openssf-comm...
loading . . .
Schedule | LF Events
View the SOSS Community Day North America 2024 Schedule & Speakers.
https://events.linuxfoundation.org/openssf-community-day-europe/program/schedule/
3 months ago
0
1
0
Bridging the gap between open source project security and foundations- its what we do. "The Bridge to Improving Security: How OSTIF Helps Foundations" is live now on our blog:
ostif.org/ostif-helps-...
loading . . .
The Bridge to Improving Security: How OSTIF Helps Foundations ā OSTIF.org
https://ostif.org/ostif-helps-foundations/
3 months ago
0
0
0
thank you to the
@openssf.org
for the opportunity to chat about our work and mission on "What's in the SOSS?" Listen on your preferred podcasting app:
openssf.org/podcast/2025...
loading . . .
Whatās in the SOSS? Podcast #37 ā S2E14 Open Source Security: OSTIFās 10-Year Journey of Collaborative Audits ā Open Source Security Foundation
https://openssf.org/podcast/2025/08/12/whats-in-the-soss-podcast-37-s2e14-open-source-security-ostifs-10-year-journey-of-collaborative-audits/?utm_content=342784617&utm_medium=social&utm_source=linkedin&hss_channel=lcp-76521837
3 months ago
0
0
0
reposted by
Least Authority
3 months ago
Our team recently completed three security audits of Permuto for
@chia.net
. You can read the full report, including our findings, here:
leastauthority.com/blog/audit-o...
loading . . .
Chia Network - Permuto - Least Authority
Chia Network has requested that Least Authority perform security audits of Permuto.
https://leastauthority.com/blog/audit-of-chia-permuto/
0
0
1
reposted by
All Things Open
3 months ago
We're thrilled to have Amir Montazery, Managing Director for
@ostifofficial.bsky.social
, presenting "Success Stories in Open Source: Third Party Security Audits" at
#AllThingsOpen
!
2025.allthingsopen.org/sessions/2-f...
0
4
2
We thought it would be timely to make a statement about our involvement with and position re: @OpenForumEurope EU-STF report. Get our thoughts at the blog:
ostif.org/eu-stf-and-o...
loading . . .
EU-STF and OSTIF ā OSTIF.org
https://ostif.org/eu-stf-and-ostif/
3 months ago
0
0
0
Our Managing Director Amir will be speaking at the
@aswf.io
Open Source Days on Sunday! RSVP at
sched.co/25j6n
to hear about why "Security Audits Aren't Scary", and how renewable security efforts help projects, foundations, and the open source community!
loading . . .
Open Source Days 2025: Security Audits are Not Scary - Applying...
View more about this event at Open Source Days 2025
https://sched.co/25j6n
4 months ago
0
0
0
In partnership with
@aswf.io
, OSTIF and
@shielder.com
worked on audits of MaterialX and OpenEXR. Our deepest gratitude for this opportunity to work with incredible maintainers and cool projects such as these- read about them at our blogs:
ostif.org/materialx-au...
,
ostif.org/openexr-audi...
4 months ago
0
3
2
reposted by
Shielder
4 months ago
šØ New Open Source Audit Alert! šØ Shielder, with
@ostifofficial.bsky.social
& ASWF audited OpenEXR and MaterialX: š 11 issues found (1 critical, 3 still to be published) āļø Most fixed, others planned š£ļø ndaprela
@smaury.bsky.social
@suidpit.bsky.social
@thezero.org
Full details in the blog post ā¬ļøš§µ
1
4
5
It's possible- our audit of PowSyBl is complete! Completed with auditing by Ada Logics and funding provided by
@lfenergy.bsky.social
, the work resulted in multiple holistic improvements to project security. Details at our blog:
ostif.org/powsybl-audi...
loading . . .
PowSyBl Audit Complete! ā OSTIF.org
https://ostif.org/powsybl-audit-complete/
4 months ago
0
0
0
OSTIF, RSTUF, and X-41 D-Sec are presenting on the audit of RSTUF next month in Amsterdam at
@openssf.org
Community Day! RSVP to add our talk to your schedule at
sched.co/25dGk
loading . . .
OpenSSF Community Day Europe 2025: Securing RSTUF To Secure Your Supply Cha...
View more about this event at OpenSSF Community Day Europe 2025
https://sched.co/25dGk
4 months ago
0
1
0
We ācondaā believe it! In collaboration with 7ASecurity and
@sovereign.tech
, we carried out an audit of conda-forge. Read the details at our blog:
ostif.org/conda-forge-...
loading . . .
conda-forge Audit Complete! ā OSTIF.org
https://ostif.org/conda-forge-audit-complete/
4 months ago
0
5
3
Happy Anniversary to our audit of CycloneDDS! Released last year, this work was a collab with Alpha Omega, Eclipse Foundation, X41 D-Sec, and CycloneDDS maintainers with OSTIF to create security outcomes. Read the report and visith shareholder blogs at our own blog:
ostif.org/cyclndds-aud...
loading . . .
CycloneDDS Audit Complete! ā OSTIF.org
https://ostif.org/cyclndds-audit-complete/
5 months ago
0
0
0
Party on, OSTIF! We toasted in our 10 year anniversary this weekend with a new employee, new merch, and fresh eyes on the next 10 years ahead (also: cheesecake pie). See some pics of the party and read about the rest of our anniversary plans at our blog:
ostif.org/10yr-party/
5 months ago
0
0
0
We are erupting with excitement to share our audit of Volcano! This work was completed with support from
@cncf.io
and auditing done by Ada Logics. It resulted in improvements to fuzz testing and secure by design processes- read about those results and more at
ostif.org/volcano-audi...
5 months ago
0
0
0
OSTIF is proud to share the results of our audit of Ruby on Rails. Completed with auditing by X41 D-Sec and engineering support provided by
@gitlab.com
, this work was possible with funding by the
@sovereign.tech
. Read more about this audit at our blog:
ostif.org/ruby-on-rail...
5 months ago
0
0
0
log4cxx and log4net are audited! Done in collaboration with the
@sovereign.tech
and carried out by ADA Logics, this security work on two Apache Software Foundation projects was carried out late last year. Read more at
ostif.org/log4cxx-log4...
loading . . .
Log4CXX and Log4Net Audits Complete! ā OSTIF.org
https://ostif.org/log4cxx-log4net-audits-complete/
6 months ago
0
2
1
As OSTIF grows our presence in communities and offers an open platform for people through our meetups, it became more pressing to us as a team to create a Code of Conduct to set the expectation of behavior for those we interact with. Read more about the Code:
ostif.org/ostif-code-o...
6 months ago
0
0
0
We're pleased to announce the publication of our audits of nghttp3 and ngtcp2! Carried out by X41 D-Sec with funding by
@sovereign.tech
, the details are available at our blog:
ostif.org/nghttp3-ngtc...
6 months ago
0
1
0
Call for meetup proposals! We're looking for 20-30 minute lightning talks with accompanying deck for visual guidance. Simply fill out the form at this Calendly link (
calendly.com/helen-ostif/...
) pick your date & time, and speak directly to the OSTIF community!
loading . . .
OSTIF Meetup - OSTIF Meetup
Speak with OSTIF and our community via an online meetup! We're offering the opportunity to present on security research, audits, vulnerabilities/bugs, or other open source topics. The event will consi...
https://calendly.com/helen-ostif/submit
7 months ago
0
0
0
ICYMI:
@nadim.computer
's meetup from last week about Cure53's Coinbase cryptographic library audit is available to watch on Youtube
youtu.be/2wR25jFgPSo?...
share with your friends, your mom, and your mom's friends who are into crypto (cash or -graphy)
loading . . .
005 Guarding the Gates: Lessons from the Coinbase CB-MPC Cryptography Audit with Nadim Kobeissi
YouTube video by Open Source Technology Improvement Fund (OSTIF)
https://youtu.be/2wR25jFgPSo?si=xsdlh1TF_f36kR23
7 months ago
0
3
2
Starting in 25 minutes!
add a skeleton here at some point
7 months ago
0
0
0
reposted by
Nadim Kobeissi
7 months ago
REMINDER: Real World Cryptography Paris Meetup 4 is happening NEXT WEEK at @Ledger HQ! Great talks on ZK, high assurance crypto and more. Make sure to register on time so we know how much baguette and fromage to get from the caterer:
lu.ma/75ykn6t2
loading . . .
Real World Cryptography Paris Meetup 4 Ā· Luma
Welcome to the Real World Cryptography Paris (RWC Paris) Meetups! Our goal is to bring together enthusiasts, professionals, and academics to discuss the latestā¦
https://lu.ma/75ykn6t2
0
3
2
Wednesday- you, Nadim Kobeissi (
@nadim.computer
), and OSTIF's community meeting about Lessons from the Coinbase CB-MPC Cryptographic Library Audit. RSVP here
lu.ma/ymr9db3z
loading . . .
Guarding the Gates w/ Nadim Kobeissi Ā· Zoom Ā· Luma
Description In the fast-paced world of cryptocurrencies, secure multi-party computation (MPC) and zero-knowledge proofs (ZKPs) form the bedrock of secureā¦
https://lu.ma/ymr9db3z
7 months ago
0
1
2
reposted by
7 months ago
Istio's ambient mode was built for security from the ground up. So, it's not surprising that ztunnel has sailed through its first security audit, thanks to Trail of Bits,
@ostifofficial.bsky.social
and
@cncf.io
. Read more:
istio.io/latest/blog/...
add a skeleton here at some point
0
2
1
We are proud to share the results of our audit of NATS! The work was done in collaboration with
@trailofbits.bsky.social
,
@synadia.bsky.social
, and the
@cncf.io
- read more details at
ostif.org/nats-audit-c...
7 months ago
0
2
1
OSTIF is proud to announce the publication of our audit of
@istio.io
's ztunnel implementation. This work was done with the Istio product security working group,
@trailofbits.bsky.social
and the
@cncf.io
. Read about the results in our blog
ostif.org/istio-ztunne...
7 months ago
0
0
1
reposted by
Join us next Wednesday, April 23rd, for an OSTIF
#meetup
with
@nadim.computer
, Senior Applied Cryptography Auditor at Cure53, presenting "Guarding the Gates: Lessons from the Coinbase CB-MPC Cryptography Library Audit". RSVP here to have the meetup added to your calendar-
lu.ma/ymr9db3z
loading . . .
Luma Ā· Delightful Events Start Here
From beautiful event pages to effortless invites and ticketing, Luma is all you need to host a memorable event.
https://lu.ma
7 months ago
0
1
2
Join us next Wednesday, April 23rd, for an OSTIF
#meetup
with
@nadim.computer
, Senior Applied Cryptography Auditor at Cure53, presenting "Guarding the Gates: Lessons from the Coinbase CB-MPC Cryptography Library Audit". RSVP here to have the meetup added to your calendar-
lu.ma/ymr9db3z
loading . . .
Luma Ā· Delightful Events Start Here
From beautiful event pages to effortless invites and ticketing, Luma is all you need to host a memorable event.
https://lu.ma
7 months ago
0
1
2
reposted by
The PHP Foundation
7 months ago
We are pleased to announce the completion of security audit of PHP core! Executed by
@quarkslab.bsky.social
in partnership with
@ostifofficial.bsky.social
and commissioned by the
@sovereign.tech
. Learn more:
thephp.foundation/blog/2025/04...
loading . . .
PHP Core Security Audit Results
The PHP Foundation ā Supporting, Advancing, and Developing the PHP Language
https://thephp.foundation/blog/2025/04/10/php-core-security-audit-results/
0
19
11
reposted by
Quarkslab
7 months ago
Quarkslab audited PHP-SRC, the open source interpreter of PHP. The security audit, sponsored by
@ostifofficial.bsky.social
with funding from
@sovereign.tech
, aimed at strengthening the project's security ahead of the upcoming PHP 8.4 release. Here's what we found:
blog.quarkslab.com/security-aud...
loading . . .
Security audit of PHP-SRC
The Open Source Technology Improvement Fund, Inc, thanks to funding provided by Sovereign Tech Fund, engaged with Quarkslab to perform a security audit of PHP-SRC, the interpreter of the PHP language.
https://blog.quarkslab.com/security-audit-of-php-src.html
0
6
3
We are so excited to announce the publication of our audit of PHP core! This work was made possible through a collaboration between OSTIF,
@thephpf.bsky.social
, and
@quarkslab.bsky.social
with funding provided by
@sovereign.tech
. For the report and further links, check out
ostif.org/php-audit-co...
7 months ago
0
5
3
Load more
feeds!
log in