Google will fund a security audit of 8 important open-source projects.

The OSTIF (Open Source Technology Improvement Fund), established to enhance the security of open projects, has announced a partnership with Google, which has expressed its willingness to fund an independent security audit of 8 open projects. The funds received from Google will be used to audit Git, the JavaScript library Lodash, the PHP framework Laravel, the Java framework Slf4j, the JSON libraries Jackson (Jackson-core and Jackson-databind), and the Java components of Apache Httpcomponents (Httpcomponents-core and Httpcomponents-client).

Earlier, with funds obtained through donations, the OSTIF already conducted audits of the OpenSSL, VeraCrypt, OpenVPN, Monero, Unbound DNS, and QRL projects. The community has also raised funds for the audit of the PHP framework Symfony. If additional funding is secured for audits, projects such as Systemd, Electron, Rails, Drupal, Joomla, WebPack, Reprepro, Ceph, React Native, Salt, Ansible, Angular, Gatsby, and Guava are also planned.

The selection was made empirically based on assessing the security impact of projects on the open source ecosystem and the potential benefits for the community from enhancing the security of the projects under consideration. For approximately 100,000 projects on GitHub, a coefficient was calculated that considers factors such as popularity in dependency usage, demand in infrastructures, number of developers, development activity, number of closed and open bug reports, number of organizations supporting the project, frequency of updates, vulnerability disclosure history, and more.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster