Skip to main content

It's Time to Audit Open Source: Success Stories with OSTIF

UB5.132 | Day 1 | 17:00 - 17:25 | Speakers: Amir Montazery

It's Time to Audit Open Source: Success Stories with OSTIF
A picture of a devroom at FOSDEM 2024
Open in browser

Notes

Abstract

Achieving improved security in the open source ecosystem is more than a theoretical goal but a plausible reality as shown by the track record of nonprofit Open Source Technology Improvement Fund, Inc. Following a best practice of independent code review with a process specifically tailored to open source projects and communities, OSTIF has worked on over 100 security audits of projects ranging from git, cURL, kubernetes, php, sigstore, and has audit reports and numerous vulnerability fixings to demonstrate effectiveness.


Notice: The placeholder video image is licensed under CC BY-SA 4.0. The original image can be found hereChanges made to the image are: Cropped the image to a new ratio, part of the image was cut off.