home.social

#ostif — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #ostif, aggregated by home.social.

  1. RE: mastodon.social/@FreeBSDFounda

    2026 Open Source Security and Risk Analysis Report – Software Governance in the AI Era – Black Duck Software, Inc.

    blackduck.com/content/dam/blac

    ― a direct link to the freely-available report that's mentioned in the joint statement from Apereo Foundation, Open Source Initiative (OSI), Open Source Technology Improvement Fund (OSTIF), and FreeBSD Foundation.

    "The “Open Source Security and Risk Analysis” (OSSRA) report has been the industry’s definitive look at the state of open source code for a decade. Each year, we analyze anonymized findings from commercial codebases audited by the Black Duck Audit Services team, and this provides an unmatched, real-world view of how open source is used—and sometimes misused—across every major industry. This year’s findings document a pivotal moment: The explosion of AI-assisted development has fundamentally altered the risk landscape for software and the baseline for compliance with new regulatory initiatives such as the EU Cyber Resilience Act (CRA) and the Digital Operational Resilience Act (DORA). …"

    #AI #CRA #DORA #OSI #OSTIF #FreeBSD #OSSRA

  2. RE: mastodon.social/@FreeBSDFounda

    2026 Open Source Security and Risk Analysis Report – Software Governance in the AI Era – Black Duck Software, Inc.

    blackduck.com/content/dam/blac

    ― a direct link to the freely-available report that's mentioned in the joint statement from Apereo Foundation, Open Source Initiative (OSI), Open Source Technology Improvement Fund (OSTIF), and FreeBSD Foundation.

    "The “Open Source Security and Risk Analysis” (OSSRA) report has been the industry’s definitive look at the state of open source code for a decade. Each year, we analyze anonymized findings from commercial codebases audited by the Black Duck Audit Services team, and this provides an unmatched, real-world view of how open source is used—and sometimes misused—across every major industry. This year’s findings document a pivotal moment: The explosion of AI-assisted development has fundamentally altered the risk landscape for software and the baseline for compliance with new regulatory initiatives such as the EU Cyber Resilience Act (CRA) and the Digital Operational Resilience Act (DORA). …"

    #AI #CRA #DORA #OSI #OSTIF #FreeBSD #OSSRA

  3. @cybervegan in fairness to the four signatories, the statement is suitably:

    ― terse
    ― professional
    ― non-aggressive.

    I'm not the target audience, but I can see how the statement might grab the attention of individuals and groups who are targeted.

    There is, amongst other things, an element of xkcd.com/2347/ (xkcd: Dependency) – without explicitly stating "Don't fuck this up.".

    Cc @jay_chi @FreeBSDFoundation

    #OSI #OSTIF #Apero #FreeBSD #ageattestation

  4. @cybervegan in fairness to the four signatories, the statement is suitably:

    ― terse
    ― professional
    ― non-aggressive.

    I'm not the target audience, but I can see how the statement might grab the attention of individuals and groups who are targeted.

    There is, amongst other things, an element of xkcd.com/2347/ (xkcd: Dependency) – without explicitly stating "Don't fuck this up.".

    Cc @jay_chi @FreeBSDFoundation

    #OSI #OSTIF #Apero #FreeBSD #ageattestation

  5. We are excited to announce that has concluded its 2023 security audit after a 3 month long joint collaboration with ADA Logics, the and . The full report and findings are available publicly here.

    cncf.io/blog/2023/09/06/dapr-c

  6. We are excited to announce that #Dapr has concluded its 2023 security audit after a 3 month long joint collaboration with ADA Logics, the #CNCF and #OSTIF. The full report and findings are available publicly here.

    cncf.io/blog/2023/09/06/dapr-c

  7. #AWS Teams with #OSTIF on #OpenSource #Security Audits

    "Last year, AWS committed to investing $10 million over three years alongside the Open Source Security Foundation (OpenSSF) to fund supply chain security. AWS will be directly funding $500,000 to OSTIF as a portion of our ongoing initiative with OpenSSF."

    aws.amazon.com/blogs/opensourc

  8. #AWS Teams with #OSTIF on #OpenSource #Security Audits

    "Last year, AWS committed to investing $10 million over three years alongside the Open Source Security Foundation (OpenSSF) to fund supply chain security. AWS will be directly funding $500,000 to OSTIF as a portion of our ongoing initiative with OpenSSF."

    aws.amazon.com/blogs/opensourc

  9. The OSTIF-sponsored git source code audit by X41+Gitlab is refreshingly brief without losing necessary technical detail. It's also quite aesthetically pleasing, which I've found helpful with my ADHD attention span.

    I'm inspired. What are your favorite reports and whitepapers? I'll take both eloquent and eye-catching.

  10. #Git patched two critical severity security #vulnerabilities that could allow attackers to execute arbitrary code (#RCE) after exploiting heap-based #bufferoverflow weakness. X41 & GitLab found the vulnerabilities as part of an audit sponsored by #OSTIF
    bit.ly/3Xoalrc

  11. #Git patched two critical severity security #vulnerabilities that could allow attackers to execute arbitrary code (#RCE) after exploiting heap-based #bufferoverflow weakness. X41 & GitLab found the vulnerabilities as part of an audit sponsored by #OSTIF
    bit.ly/3Xoalrc