@ostifofficial.bsky.social
📤 61
📥 38
📝 109
Our Q2 2026 Community Spotlight is Antonela Conti! Antonela works for
#X41D-Sec
as a Project Manager and Admin. Read more about her work in open source in her own words:
ostif.org/q2-2026-comm...
5 days ago
0
0
0
We are proud to share the results of our security audit of PyTorch ExecuTorch. Thanks to
@trailofbits.bsky.social
and Alpha-Omega, this project underwent a custom engagement of security review and testing. Read more on our blog-
ostif.org/pytorch-exec...
#OSTIF
#PyTorch
#TrailofBits
#AlphaOmega
7 days ago
0
0
0
reposted by
Quarkslab
14 days ago
Cortex is a long-term, multi-tenant scalable open source storage for Prometheus and OpenTelemetry. Earlier this year we conducted a security audit sponsored by
@ostifofficial.bsky.social
Check our report here:
blog.quarkslab.com/cortex-secur...
loading . . .
Cortex Security Audit - Quarkslab's blog
At the request of the Open Source Technology Improvement Fund (OSTIF), Quarkslab performed a security audit of Cortex, evaluating the security of its multi-tenant design and the mechanisms protecting ...
https://blog.quarkslab.com/cortex-security-audit.html
0
1
1
We are proud to share the results of our security audit of
#Cortex
. Thanks to
@quarkslab.bsky.social
and the
@cncf.io
, Cortex received custom review and documentation for current and future security development. Read more about the work on our blog:
ostif.org/cortex-audit...
#OSTIF
#Quarkslab
#CNCF
14 days ago
0
1
0
We are proud to share the results of our security audit of
@symfony.com
Symfony-YAML. Thanks to @shielder.com and
@sovereign.tech
, this project received custom security review to further harden the project against risk. Read more on our blog:
ostif.org/symfony-yaml...
#symfony
#OSTIF
#shielder
20 days ago
0
0
0
#KEDA
is an open source project for scaling containers in Kubernetes. With the help of
#7ASecurity
and
@cncf.io
, this project underwent a pentest and whitebox security review and audit. Read more on our blog:
ostif.org/keda-audit-c...
21 days ago
0
0
0
We are proud to share the results of our security audit of Kubeflow. Thanks to ADA Logics and the
@cncf.io
, Kubeflow underwent a custom security engagement that audited 6 projects in the Kubeflow ecosystem. Read more on our blog:
ostif.org/kubeflow-aud...
#OSTIF
#Kubeflow
#CNCF
#Adalogics
26 days ago
0
1
0
reposted by
Quarkslab
about 1 month ago
BOLT is a static analysis tool, part of the LLVM compiler infrastructure, used to verify compiler security hardening options have been applied on a binary. Thanks to
@ostifofficial.bsky.social
we've worked since November 2025 to improve it. Check our progress here:
blog.quarkslab.com/extending-ll...
loading . . .
Extending LLVM's BOLT-based Binary Analyser to Validate Stack Variable Initialisation - Quarkslab's blog
The Open Source Technology Improvement Fund (OSTIF) commissioned Quarkslab to extend the BOLT-based static binary analyser in LLVM to support additional compiler flags for security hardening. This wor...
https://blog.quarkslab.com/extending-llvms-bolt-based-binary-analyser-to-validate-stack-variable-initialisation.html
0
4
1
Releasing today is OSTIF's work on LLVM's BOLT binary scanner. Completed thanks to
@quarkslab.bsky.social
and
@sovereign.tech
, the BOLT scanner received custom work to extend its coverage further. Read about the work and its implications at our blog:
ostif.org/bolt-securit...
#OSTIF
#llvm
#BOLT
about 1 month ago
0
1
0
reposted by
The Scala Programming Language
about 2 months ago
🎺 First phase of the Scala security audit is complete. ✅ No critical or major issues found ✅ All reported findings fixed ✅ Improvements shipped in Scala 3.3 LTS and upcoming 3.8 Huge thanks to
@ostifofficial.bsky.social
,
@quarkslab.bsky.social
&
@sovereign.tech
đź’ť
scala-lang.org/blog/2026/06...
loading . . .
Scala Codebase Security Audit Complete
The first part of the security audit funded by the Sovereign Tech Fund is done, no critical issues were found.
https://scala-lang.org/blog/2026/06/01/first-part-security-audit.html
0
7
1
The Open Source Technology Improvement Fund is proud to share the results of our security audit of Scala, executed by a team of 3 auditors from Quarkslab. We want to thank our own Derek Zimmer of OSTIF for advocating for this audit for a long time!
#OSTIF
#Quarkslab
#SovereignTechAgency
#Scala
about 2 months ago
1
0
0
During a security audit of vLLM managed by
OSTIF.org
, a bug was discovered through manual analysis by a senior security expert at X41 D-Sec.
#OSTIF
#BadHost
#vLLM
#X41DSec
about 2 months ago
1
0
0
reposted by
Brian Benz
2 months ago
Good milestone for Inspektor Gadget: its first independent security audit is complete. Thanks to
@ostifofficial.bsky.social
,
@cncf.io
, and
@inspektor-gadget.io
for the transparency around the process and fixes.
techcommunity.microsoft.com/blog/Linuxan...
#Kubernetes
#eBPF
#OpenSource
#Security
loading . . .
Inspektor Gadget Completes First Independent Security Audit
CNCF's Inspektor Gadget passes its first independent security audit by Shielder and OSTIF, with all findings patched in v0.50.1. See what they found.
https://techcommunity.microsoft.com/blog/LinuxandOpenSourceBlog/inspektor-gadget-completes-its-first-independent-security-audit/4517895
0
4
2
reposted by
OpenSSF
2 months ago
The AI Cyber Challenge (AIxCC) results are in and the work continues through new
#OpenSSF
projects like OSS-CRS and FuzzingBrain. Read the blog by Helen Woeste (OSTIF):
openssf.org/blog/2026/05...
0
1
1
In 2023, DARPA announced a two-year long competition called the Artificial Intelligence Cyber Challenge (AIxCC), a massive undertaking by dozens of organizations with the goal to safeguard open source software used in critical infrastructure throughout America.
#OSTIF
#DARPA
#OpenSSF
#AI
2 months ago
1
0
0
Voila- the results of OSTIF's security audit of
#Paramiko
! Thanks to the contributions of
@quarkslab.bsky.social
and
@openssf.org
Alpha-Omega, this project received custom security work. Read about the Python implementation of the SSHv2 protocol at our blog:
ostif.org/paramiko-aud...
3 months ago
0
0
0
reposted by
Inspektor Gadget
3 months ago
Our external security audit with
@shielder.com
@ostifofficial.bsky.social
and
@cncf.io
is out! 3 CVEs were found, all of which have been addressed in v0.51.1. Thank you to everyone involved
inspektor-gadget.io/blog/2026/04...
loading . . .
Results from the First Inspektor Gadget Security Audit | Inspektor Gadget
Inspektor Gadget completed its first independent security audit, conducted by Shielder and coordinated by OSTIF. The audit found three vulnerabilities — all now fixed — plus six hardening recommendati...
https://inspektor-gadget.io/blog/2026/04/inspektor-gadget-security-audit
0
2
2
We're proud to share the results of our audit of
#LibVLC
, performed by
@trailofbits.bsky.social
with support from
@sovereign.tech
! LibVLC received scoped security work, custom tools and fixes, and documentation for future development. Read more about it on our blog:
ostif.org/libvlc-audit...
3 months ago
0
2
0
We're excited to announce the results of our audit of Inspektor Gadget! With the help of
@shielder.com
and the
@cncf.io
, this project received a security audit reviewing Inspektor Gadget’s core components. Read more about the work done on our blog:
ostif.org/inspektor-ga...
3 months ago
0
0
0
reposted by
Shielder
3 months ago
Can a hostile container sneak past your eBPF tracing? Sometimes, yes. With
@ostifofficial.bsky.social
&
@cncf.io
we audited Inspektor Gadget - 3 vulns (fixed), 6 hardenings, 6 bypasses (io_uring, openat2, jumbo frames…). Work by ndaprela &
@suidpit.sh
👏 🔗
www.shielder.com/blog/2026/04...
loading . . .
Shielder - Inspektor Gadget Security Audit
Security audit of Inspektor Gadget, an eBPF-based observability framework for Linux and Kubernetes. Sponsored by the CNCF (Cloud Native Computing Foundation), facilitated by Open Source Technology Imp...
https://www.shielder.com/blog/2026/04/inspektor-gadget-security-audit/
0
9
8
reposted by
Sovereign Tech Agency
3 months ago
NEWS 📣 The Sovereign Tech Agency is launching the Sovereign Tech Standards network today, a new program designed to bring open source maintainers directly into global standards development.
www.sovereign.tech/news/join-so...
1
24
22
Our security audit of PyPI projects Requests, CacheControl, and urllib3 was executed by
@7asecurity.bsky.social
with funding provided from
@openssf.org
Alpha-Omega. Read more about this engagement on our blog:
ostif.org/requests-cac...
3 months ago
0
0
0
The Open Source Technology Improvement Fund is proud to share the results of our security engagement on Developing ECH for OpenSSL (“DEfO”).
ostif.org/defo-audit-c...
#OSTIF
#DEfO
#AdaLogics
#7ASecurity
#SovereignTechAgency
loading . . .
DEfO Audit Complete! – OSTIF.org
https://ostif.org/defo-audit-complete/
3 months ago
1
1
0
reposted by
Shielder
4 months ago
#KubeCon
EU starts today and guess what? Our very own
@suidpit.sh
will be on stage with a panel about the
@kubernetes.io
Security Audit we performed during 2025 with the support of
@ostifofficial.bsky.social
! 🗓️ March 25 - 16:45 CET 📍 Hall 8 | Room F
1
5
6
reposted by
The Linux Foundation
4 months ago
The Linux Foundation Announces $12.5 Million in Grant Funding (via Alpha-Omega and
@openssf.org
) Anthropic, AmazonWebServices, GitHub, Google, GoogleDeepMind, Microsoft, OpenAI to Invest in Sustainable Security Solutions for
#OpenSource
loading . . .
Linux Foundation Announces $12.5 Million in Grant Funding from Leading Organizations to Advance Open Source Security
Linux Foundation announces launch of the React Foundation
https://bit.ly/4uCk12g
3
22
4
We are proud to announce our top 3 bugs of the year on our blog:
ostif.org/bug-of-the-y...
#OSTIF
#BOTY
#7ASecurity
4 months ago
0
2
1
Miss our last OSTIF meetup? You can catch the recording here of Robin David, Software Security Researcher and Research Lead at Quarkslab, presenting "Bitcoin Core Audit: From Static Review to Fuzzing — Inside Bitcoin’s Testing Infrastructure".
www.youtube.com/watch?v=J1Y1...
#OSTIF
#bitcoin
loading . . .
Meetup 010: Bitcoin Core Audit: From Static Review to Fuzzing w/ Robin David
YouTube video by Open Source Technology Improvement Fund (OSTIF)
https://www.youtube.com/watch?v=J1Y1EJmtX_Q
4 months ago
0
0
0
reposted by
Internet Systems Consortium (ISC)
5 months ago
ISC is pleased to announce the results of code audits for our Kea DHCP and Stork graphical management software projects! Thank you to
@ostifofficial.bsky.social
and the ICANN Grant Program for their support and assistance. Read more about the audits at
www.isc.org/blogs/2026-t...
loading . . .
Kea and Stork Projects Audited
In mid-2025 ISC contracted with OSTIF to identify an external organization to audit our Kea and Stork code for security issues.
https://www.isc.org/blogs/2026-two-code-audits/
0
1
1
Don't miss tomorrow's OSTIF meetup with Robin David, Software Security Researcher and Research Lead at Quarkslab, presenting "Bitcoin Core Audit: From Static Review to Fuzzing — Inside Bitcoin’s Testing Infrastructure".
luma.com/gjnorzq0
#OSTIF
#OpenSource
#bitcoin
loading . . .
Bitcoin Core Audit: From Static Review to Fuzzing — Inside Bitcoin’s Testing Infrastructure w/ Robin David · Luma
Description This talk explores the internals of the Bitcoin protocol and its reference implementation, Bitcoin Core, whose first version was written by Satoshi…
https://luma.com/gjnorzq0
5 months ago
0
1
0
OSTIF is proud to share the results of our security audit of Stork, an open source project developed by the Internet Systems Consortium (ISC) that acts as an administrative interface for monitoring, maintaining, and surveilling Kea servers.
ostif.org/stork-audit-...
#OSTIF
#Stork
#7ASecurity
5 months ago
0
2
0
We, like everyone else, couldn't look away from the Veritasium video on the XZ vulnerability. Watch the video here
www.youtube.com/watch?v=aoag...
to learn more details about this incredible story of open source security and community.
#OSTIF
#Veritasium
#XZ
loading . . .
The Internet Was Weeks Away From Disaster and No One Knew
YouTube video by Veritasium
https://www.youtube.com/watch?v=aoag03mSuXQ
5 months ago
1
1
0
For the past 4 years, OSTIF has run a Managed Audit Program for the CNCF. We’ve audited 33 projects in that time, working with maintainers all over the world to reinforce the security health of cloud native open source for billions of end users. Read the full report here:
ostif.org/cncfmanagedp...
5 months ago
0
0
0
Miss yesterday's amazing audit meetup "High Assurance Cryptography and the Ethics of Disclosure" w/
@nadim.computer
? Catch the video here
www.youtube.com/watch?v=TdOX...
Make sure you're subscribed for notifications of any new meetups!
luma.com/ostif-meetups
#OSTIF
#meetup
#audit
loading . . .
Meetup 009: High Assurance Cryptography and the Ethics of Disclosure w/ Nadim Kobeissi
YouTube video by Open Source Technology Improvement Fund (OSTIF)
https://www.youtube.com/watch?v=TdOXza1-M_4
5 months ago
0
1
0
Join us next Wednesday for an OSTIF meetup with Robin David, Software Security Researcher and Research Lead at Quarkslab, presenting "Bitcoin Core Audit: From Static Review to Fuzzing — Inside Bitcoin’s Testing Infrastructure".
luma.com/gjnorzq0
#OSTIF
#OpenSource
#bitcoin
loading . . .
Bitcoin Core Audit: From Static Review to Fuzzing — Inside Bitcoin’s Testing Infrastructure w/ Robin David · Luma
Description This talk explores the internals of the Bitcoin protocol and its reference implementation, Bitcoin Core, whose first version was written by Satoshi…
https://luma.com/gjnorzq0
5 months ago
0
1
0
reposted by
Sovereign Tech Agency
5 months ago
Reminder: The Sovereign Tech Agency is gathering feedback from open source maintainers and contributors working with technology standards to inform the Agency's future work and new initiatives. ➡️
survey.sovereigntechfund.de/999999?lang=...
loading . . .
Powered by LimeSurvey – The Freshest Online Survey Tool
Create surveys in seconds with LimeSurvey. Easy to use, secure, and trusted by professionals worldwide. Get started free and unlock fresh insights today!
https://survey.sovereigntechfund.de/999999?lang=en&newtest=Y
1
1
2
reposted by
Nadim Kobeissi
5 months ago
TODAY: Join my livestreamed talk on my Cryspen findings and ask me questions! 5:00pm Paris time, coordinated with
@ostifofficial.bsky.social
. Register here:
luma.com/xc4yuezb?tk=...
loading . . .
High Assurance Cryptography and the Ethics of Disclosure w/ Nadim Kobeissi · Luma
Description Formally verified cryptographic libraries are increasingly deployed in critical systems, marketed as providing the highest level of assurance…
https://luma.com/xc4yuezb?tk=zWi01m
1
1
2
Our work with
@sovereign.tech
over the past two years resulted in 9 published audits with 6 more underway. OSTIF doesn't take lightly the responsibility we feel to help make a more resilient and secure open source ecosystem. Read more in our 2 year report:
ostif.org/sovereigntec...
loading . . .
Sovereign Tech Agency and OSTIF Security Audit Report – OSTIF.org
https://ostif.org/sovereigntechagencyostifreport2025/
5 months ago
0
3
0
RSVP fornext week's OSTIF meetup with Nadim Kobeissi, Senior Applied Cryptography Auditor at Cure53 presenting "High Assurance Cryptography and the Ethics of Disclosure". RSVPing adds the event to your calendar and lets us know you're coming!
luma.com/xc4yuezb
#OSTIF
#OpenSource
#disclosure
loading . . .
High Assurance Cryptography and the Ethics of Disclosure w/ Nadim Kobeissi · Luma
Description Formally verified cryptographic libraries are increasingly deployed in critical systems, marketed as providing the highest level of assurance…
https://luma.com/xc4yuezb
5 months ago
0
1
0
The Open Source Technology Improvement Fund is proud to share the results of our security audit of zlib. Thanks to the efforts of 7ASecurity and the Sovereign Tech Fund, this project underwent a holistic security review. See 🧵 below 👇
#OSTIF
#7ASecurity
#audit
#zlib
5 months ago
1
0
0
Join us in 2 weeks on Wednesday, February 25th, for an OSTIF meetup with Nadim Kobeissi, Senior Applied Cryptography Auditor at Cure53 presenting "High Assurance Cryptography and the Ethics of Disclosure".
#OSTIF
#OpenSource
#disclosure
5 months ago
1
1
0
reposted by
Nadim Kobeissi
5 months ago
I'm giving a talk soon about my Cryspen findings, in collaboration with
@ostifofficial.bsky.social
. Happening online, will be live-streamed. Register here:
luma.com/xc4yuezb?tk=...
loading . . .
High Assurance Cryptography and the Ethics of Disclosure w/ Nadim Kobeissi · Luma
Description Formally verified cryptographic libraries are increasingly deployed in critical systems, marketed as providing the highest level of assurance…
https://luma.com/xc4yuezb?tk=zWi01m
0
1
1
This month's Community Spotlight shines on Peter Hunt, Principal Software Engineer at Red Hat who has contributed to both of OSTIF's audits of CRI-O (
cri-o.io
). Come check out our interview!
ostif.org/feb-2026-com...
#OSTIF
#Spotlight
#RedHat
5 months ago
0
0
0
reposted by
The Linux Foundation
5 months ago
🆓 🎉 It's Free Open Source Software Month! Learn open source skills for FREE! From Linux fundamentals to Kubernetes, secure software, and emerging tech, check out Linux Foundation Education’s free learning library today:
training.linuxfoundation.org/resources/
#OSS
#CloudNative
#Linux
#Kubernetes
loading . . .
0
19
13
We couldn't have done it without:
@sovereign.tech
@cncf.io
@lfenergy.bsky.social
@aswf.io
@quarkslab.bsky.social
@shielder.com
@trailofbits.bsky.social
@openssf.org
@opensource.org
@puerco.mx
@funnelfiasco.bsky.social
@nadim.computer
@adamshostack.bsky.social
@openforumeurope.org
and so many more!
add a skeleton here at some point
6 months ago
0
5
1
Presenting our 2025 annual report! In our report, you’ll see that OSTIF's story and mission are intertwined. OSTIF will continue to fight for open source infrastructure and the privacy rights of users for as many decades as you’ll let us. Our statement and report link:
ostif.org/2025-annual-...
loading . . .
2025 Annual Report – OSTIF.org
https://ostif.org/2025-annual-report/
6 months ago
0
3
3
Congratulations to the Scala team for securing investment in open source infrastructure with the
@sovereign.tech
! We're proud to contribute to this effort, and look forward to the future of Scala and this endowment's positive impact:
scala-lang.org/blog/2026/01...
loading . . .
The Sovereign Tech Fund invests in Scala
https://scala-lang.org/blog/2026/01/27/sta-invests-in-scala.html
6 months ago
0
1
1
@lfenergy.bsky.social
EVerest underwent a security engagement facilitated by us with auditing by
@quarkslab.bsky.social
. This holistic security work impacts millions of EV charging stations worldwide. Read more at our blog:
ostif.org/everest-secu...
6 months ago
0
1
1
reposted by
Quarkslab
6 months ago
We conducted the first public third-party security assessment of EVerest, an open-source firmware stack for electric vehicle charging stations, deployed in hundreds of thousands of charging points worldwide. The audit was mandated by
@ostifofficial.bsky.social
🙏
blog.quarkslab.com/everest-secu...
0
2
2
Having previously undergone an OSTIF security audit in 2022, Cloud Native Computing Foundation (CNCF) project CRI-O received another review in late 2025. Security auditing was performed by X41 D-Sec GmbH, and their report is available to read on our blog:
ostif.org/cri-o-audit-...
6 months ago
0
1
0
Releasing today is our security audit of Internet Systems Consortium's Kea project. The project received holistic security improvements and recommendations from Ada Logics. Read more about the work performed and results to the project at our blog:
ostif.org/kea-security...
6 months ago
0
1
0
Load more
feeds!
log in