Google has launched the Secure Open Source (SOS) initiative, which will provide rewards for efforts to enhance the security of critical open source software. An initial million dollars has been allocated for these rewards, and if the initiative is deemed successful, further investment in the project will continue.
The following rewards are available:
- $10,000 and above — for making complex, significant, and long-term improvements that protect against serious vulnerabilities in the code or infrastructure of open projects.
- $5,000-$10,000 — for medium complexity improvements that have a positive impact on security.
- $1,000-$5,000 — for moderate complexity improvements that enhance security.
- $505 — for minor improvements that enhance security.
Applications for rewards are accepted only for changes made to projects with a criticality rating of no less than 0.6 on the OpenSSF Criticality Score or those listed as requiring special security review. The nature of the proposed changes should be related to improving security in areas such as enhancing the protection of infrastructure elements (e.g., continuous integration and release deployment processes), implementing verification systems with digital signatures for software product components, and increasing product security (code reviews, branch protection, fuzz testing, and dependency attack protection).
Source: opennet.ru
