Cortex, the long-term storage layer for Prometheus and OpenTelemetry, just completed an independent security audit. Seven findings, all fixed. Read the results: https://www.cncf.io/blog/2026/08/03/cortex-completes-ostif-security-audit/ #Observability #CloudNative
@ostifofficial.bsky.social
Our Q2 2026 Community Spotlight is Antonela Conti! Antonela works for #X41D-Sec as a Project Manager and Admin. Read more about her work in open source in her own words: ostif.org/q2-2026-comm...
We are proud to share the results of our security audit of PyTorch ExecuTorch. Thanks to @trailofbits.bsky.social and Alpha-Omega, this project underwent a custom engagement of security review and testing. Read more on our blog- ostif.org/pytorch-exec... #OSTIF #PyTorch #TrailofBits #AlphaOmega
Cortex is a long-term, multi-tenant scalable open source storage for Prometheus and OpenTelemetry. Earlier this year we conducted a security audit sponsored by @ostifofficial.bsky.social Check our report here: blog.quarkslab.com/cortex-secur...
Cortex Security Audit - Quarkslab's blog
At the request of the Open Source Technology Improvement Fund (OSTIF), Quarkslab performed a security audit of Cortex, evaluating the security of its multi-tenant design and the mechanisms protecting ...
blog.quarkslab.com
We are proud to share the results of our security audit of #Cortex. Thanks to @quarkslab.bsky.social and the @cncf.io, Cortex received custom review and documentation for current and future security development. Read more about the work on our blog: ostif.org/cortex-audit... #OSTIF #Quarkslab #CNCF
We are proud to share the results of our security audit of @symfony.com Symfony-YAML. Thanks to @shielder.com and @sovereign.tech, this project received custom security review to further harden the project against risk. Read more on our blog: ostif.org/symfony-yaml... #symfony #OSTIF #shielder
#KEDA is an open source project for scaling containers in Kubernetes. With the help of #7ASecurity and @cncf.io, this project underwent a pentest and whitebox security review and audit. Read more on our blog: ostif.org/keda-audit-c...
We are proud to share the results of our security audit of Kubeflow. Thanks to ADA Logics and the @cncf.io, Kubeflow underwent a custom security engagement that audited 6 projects in the Kubeflow ecosystem. Read more on our blog: ostif.org/kubeflow-aud... #OSTIF #Kubeflow #CNCF #Adalogics
BOLT is a static analysis tool, part of the LLVM compiler infrastructure, used to verify compiler security hardening options have been applied on a binary. Thanks to @ostifofficial.bsky.social we've worked since November 2025 to improve it. Check our progress here: blog.quarkslab.com/extending-ll...
Extending LLVM's BOLT-based Binary Analyser to Validate Stack Variable Initialisation - Quarkslab's blog
The Open Source Technology Improvement Fund (OSTIF) commissioned Quarkslab to extend the BOLT-based static binary analyser in LLVM to support additional compiler flags for security hardening. This wor...
blog.quarkslab.com
Releasing today is OSTIF's work on LLVM's BOLT binary scanner. Completed thanks to @quarkslab.bsky.social and @sovereign.tech, the BOLT scanner received custom work to extend its coverage further. Read about the work and its implications at our blog: ostif.org/bolt-securit... #OSTIF #llvm #BOLT
🎺 First phase of the Scala security audit is complete. ✅ No critical or major issues found ✅ All reported findings fixed ✅ Improvements shipped in Scala 3.3 LTS and upcoming 3.8 Huge thanks to @ostifofficial.bsky.social, @quarkslab.bsky.social & @sovereign.tech 💝 scala-lang.org/blog/2026/06...
Scala Codebase Security Audit Complete
The first part of the security audit funded by the Sovereign Tech Fund is done, no critical issues were found.
scala-lang.org
The Open Source Technology Improvement Fund is proud to share the results of our security audit of Scala, executed by a team of 3 auditors from Quarkslab. We want to thank our own Derek Zimmer of OSTIF for advocating for this audit for a long time! #OSTIF #Quarkslab #SovereignTechAgency #Scala
Good milestone for Inspektor Gadget: its first independent security audit is complete. Thanks to @ostifofficial.bsky.social , @cncf.io , and @inspektor-gadget.io for the transparency around the process and fixes. techcommunity.microsoft.com/blog/Linuxan... #Kubernetes #eBPF #OpenSource #Security
Inspektor Gadget Completes First Independent Security Audit
CNCF's Inspektor Gadget passes its first independent security audit by Shielder and OSTIF, with all findings patched in v0.50.1. See what they found.
techcommunity.microsoft.com
The AI Cyber Challenge (AIxCC) results are in and the work continues through new #OpenSSF projects like OSS-CRS and FuzzingBrain. Read the blog by Helen Woeste (OSTIF): openssf.org/blog/2026/05...
Voila- the results of OSTIF's security audit of #Paramiko! Thanks to the contributions of @quarkslab.bsky.social and @openssf.org Alpha-Omega, this project received custom security work. Read about the Python implementation of the SSHv2 protocol at our blog: ostif.org/paramiko-aud...
Our external security audit with @shielder.com @ostifofficial.bsky.social and @cncf.io is out! 3 CVEs were found, all of which have been addressed in v0.51.1. Thank you to everyone involved inspektor-gadget.io/blog/2026/04...
Results from the First Inspektor Gadget Security Audit | Inspektor Gadget
Inspektor Gadget completed its first independent security audit, conducted by Shielder and coordinated by OSTIF. The audit found three vulnerabilities — all now fixed — plus six hardening recommendati...
inspektor-gadget.io
We're proud to share the results of our audit of #LibVLC, performed by @trailofbits.bsky.social with support from @sovereign.tech! LibVLC received scoped security work, custom tools and fixes, and documentation for future development. Read more about it on our blog: ostif.org/libvlc-audit...
We're excited to announce the results of our audit of Inspektor Gadget! With the help of @shielder.com and the @cncf.io, this project received a security audit reviewing Inspektor Gadget’s core components. Read more about the work done on our blog: ostif.org/inspektor-ga...
Can a hostile container sneak past your eBPF tracing? Sometimes, yes. With @ostifofficial.bsky.social & @cncf.io we audited Inspektor Gadget - 3 vulns (fixed), 6 hardenings, 6 bypasses (io_uring, openat2, jumbo frames…). Work by ndaprela & @suidpit.sh👏 🔗 www.shielder.com/blog/2026/04...
Shielder - Inspektor Gadget Security Audit
Security audit of Inspektor Gadget, an eBPF-based observability framework for Linux and Kubernetes. Sponsored by the CNCF (Cloud Native Computing Foundation), facilitated by Open Source Technology Imp...
shielder.com
NEWS 📣 The Sovereign Tech Agency is launching the Sovereign Tech Standards network today, a new program designed to bring open source maintainers directly into global standards development. www.sovereign.tech/news/join-so...
Our security audit of PyPI projects Requests, CacheControl, and urllib3 was executed by @7asecurity.bsky.social with funding provided from @openssf.org Alpha-Omega. Read more about this engagement on our blog: ostif.org/requests-cac...
The Open Source Technology Improvement Fund is proud to share the results of our security engagement on Developing ECH for OpenSSL (“DEfO”). ostif.org/defo-audit-c... #OSTIF #DEfO #AdaLogics #7ASecurity #SovereignTechAgency
DEfO Audit Complete! – OSTIF.org
ostif.org
#KubeCon EU starts today and guess what? Our very own @suidpit.sh will be on stage with a panel about the @kubernetes.io Security Audit we performed during 2025 with the support of @ostifofficial.bsky.social! 🗓️ March 25 - 16:45 CET 📍 Hall 8 | Room F
The Linux Foundation Announces $12.5 Million in Grant Funding (via Alpha-Omega and @openssf.org) Anthropic, AmazonWebServices, GitHub, Google, GoogleDeepMind, Microsoft, OpenAI to Invest in Sustainable Security Solutions for #OpenSource
Linux Foundation Announces $12.5 Million in Grant Funding from Leading Organizations to Advance Open Source Security
Linux Foundation announces launch of the React Foundation
bit.ly
We are proud to announce our top 3 bugs of the year on our blog: ostif.org/bug-of-the-y... #OSTIF #BOTY #7ASecurity
Miss our last OSTIF meetup? You can catch the recording here of Robin David, Software Security Researcher and Research Lead at Quarkslab, presenting "Bitcoin Core Audit: From Static Review to Fuzzing — Inside Bitcoin’s Testing Infrastructure". www.youtube.com/watch?v=J1Y1... #OSTIF #bitcoin
Meetup 010: Bitcoin Core Audit: From Static Review to Fuzzing w/ Robin David
YouTube video by Open Source Technology Improvement Fund (OSTIF)
youtube.com
ISC is pleased to announce the results of code audits for our Kea DHCP and Stork graphical management software projects! Thank you to @ostifofficial.bsky.social and the ICANN Grant Program for their support and assistance. Read more about the audits at www.isc.org/blogs/2026-t...
Kea and Stork Projects Audited
In mid-2025 ISC contracted with OSTIF to identify an external organization to audit our Kea and Stork code for security issues.
isc.org
Don't miss tomorrow's OSTIF meetup with Robin David, Software Security Researcher and Research Lead at Quarkslab, presenting "Bitcoin Core Audit: From Static Review to Fuzzing — Inside Bitcoin’s Testing Infrastructure". luma.com/gjnorzq0 #OSTIF #OpenSource #bitcoin
Bitcoin Core Audit: From Static Review to Fuzzing — Inside Bitcoin’s Testing Infrastructure w/ Robin David · Luma
Description This talk explores the internals of the Bitcoin protocol and its reference implementation, Bitcoin Core, whose first version was written by Satoshi…
luma.com