#OSTIF
Ostif the scarecrow!

#Art #OC
April 22, 2026 at 3:41 AM
spooky season is up and Ostif made a little friend

#digitalart #oc #originalcharacter #halloween
October 20, 2024 at 5:52 PM
Thank you for this awesome Christmas gift @ostifofficial.bsky.social, and for all your work making Open Source more secure every day! 💕
December 3, 2024 at 3:23 AM
Inspektor Gadget has completed its first security audit. Three vulnerabilities fixed, six hardening recommendations addressed — coordinated by OSTIF and led by Shielder.
> https://www.inspektor-gadget.io/blog/2026/04/inspektor-gadget-security-audit
Results from the First Inspektor Gadget Security Audit | Inspektor Gadget
Inspektor Gadget completed its first independent security audit, conducted by Shielder and coordinated by OSTIF. The audit found three vulnerabilities — all now fixed — plus six hardening recommendati...
www.inspektor-gadget.io
May 15, 2026 at 8:21 PM
If you haven't met the OSTIF community and me, they have a special introduction for you.

Check out OSTIF's Meet the Community video to learn more about my professional experience and envisioned changes for the open source community.

Thanks to the OSTIF team for the great intro! shorturl.at/q9J8R
OSTIF Meet the Community- Adam Shostack
Meet Adam Shostack, founder and Executive Director of Shostack and Associates! ​Shostack helped create the CVE. Now, he's an Emeritus member of the Advisory Board, fixed Autorun for hundreds of…
youtu.be
December 1, 2025 at 6:39 PM
Want to learn more about our approach into auditing complex libraries and writing cool exploits?

🗓️: Dec 02

🕗: 20:00 CET

RSVP: luma.com/ostif-meetup...
November 25, 2025 at 9:15 AM
Joining the Open Policy Alliance enables OSTIF to contribute further to the ecosystem and increase the exposure and education of the general public to open source. https://opensource.org/blog/open-policy-alliance-welcomes-the-open-source-technology-improvement-fund-as-new-member
Open Policy Alliance Welcomes the Open Source Technology Improvement Fund as New Member
The Open Source Initiative (OSI) is pleased to welcome the Open Source Technology Improvement Fund (OSTIF) to the Open Policy Alliance. OSTIF is a nonprofit dedicated to securing Open Source apps.
opensource.org
January 8, 2026 at 3:00 PM
Publish your threat models!

Not convinced?

I'll be hosting a talk with OSTIF on Oct 29 @ 2pm CT for you to ask me questions.

Register now and have your questions, thoughts, and comments ready!

luma.com/6fvp6orm
Threat Modeling w/ Adam Shostack · Zoom · Luma
Description Publish your threat models! This talk will cover the idea of publishing threat models, the dangers associated with the idea, and why open source…
luma.com
October 13, 2025 at 7:56 PM
Our work with @sovereign.tech over the past two years resulted in 9 published audits with 6 more underway. OSTIF doesn't take lightly the responsibility we feel to help make a more resilient and secure open source ecosystem. Read more in our 2 year report: ostif.org/sovereigntec...
Sovereign Tech Agency and OSTIF Security Audit Report – OSTIF.org
ostif.org
February 23, 2026 at 5:10 PM
The FreeBSD Foundation has joined the Open Source Initiative (OSI), the Apereo Foundation, and the Open Source Technology Improvement Fund (OSTIF) in issuing a joint statement on age-attestation requirements for operating systems.

Read the full statement from OSI:
buff.ly/88u2Lgz
Open Source Organizations Weigh in on Age Attestation
The Open Source Initiative (OSI), Apereo Foundation, FreeBSD Foundation, and Open Source Technology Improvement Fund (OSTIF) issued the following statement on age attestation requirements for opera…
opensource.org
June 1, 2026 at 8:36 PM
OSTIF is proud to share the results of our security audit of Stork, an open source project developed by the Internet Systems Consortium (ISC) that acts as an administrative interface for monitoring, maintaining, and surveilling Kea servers.

ostif.org/stork-audit-...

#OSTIF #Stork #7ASecurity
March 3, 2026 at 3:28 PM
We are so excited to announce the publication of our audit of PHP core! This work was made possible through a collaboration between OSTIF, @thephpf.bsky.social, and @quarkslab.bsky.social with funding provided by @sovereign.tech. For the report and further links, check out ostif.org/php-audit-co...
April 10, 2025 at 7:12 PM
We are building tech you can trust.

Thank you to @ostifofficial.bsky.social and 7A Security for their collaboration on the security audit for Thunderbird Send, our end-to-end encrypted file transfer service (coming to everyone soon, open source now).

blog.thunderbird.net/2025/12/thun...
Thunderbird Send Security Audit with OSTIF and 7ASecurity - The Thunderbird Blog
As we get ready for the Thunderbird Pro launch, we want every service we offer to be secure and worthy of the trust our community places in us. That means being honest about where we stand today and t...
blog.thunderbird.net
December 10, 2025 at 3:24 PM
Continued security improvements to CNCF projects with OSTIF audits www.cncf.io/blog/2024/12... #cncf via @CloudNativeFDN
Continued security improvements to CNCF projects with OSTIF audits
The Open Source Technology Improvement Fund, Inc (OSTIF) is thrilled to mark another successful year of helping CNCF projects with security audits. Since this partnership began in 2021, a total of 13…
www.cncf.io
December 13, 2024 at 11:29 AM
Video recording of yesterday's talk at @ostifofficial.bsky.social now available:
Meetup 009: High Assurance Cryptography and the Ethics of Disclosure w/ Nadim Kobeissi
YouTube video by Open Source Technology Improvement Fund (OSTIF)
www.youtube.com
February 26, 2026 at 3:26 PM
We are proud to announce our top 3 bugs of the year on our blog: ostif.org/bug-of-the-y...

#OSTIF #BOTY #7ASecurity
March 17, 2026 at 2:14 PM
"OSTIF Reaches 100th Audit Publication!" ostif.org/100th-audit-...
OSTIF Reaches 100th Audit Publication! – OSTIF.org
ostif.org
September 1, 2026 at 2:24 PM
2024 was an impactful and busy year for OSTIF, which included organizing security audits for 7 open source projects critical to infrastructure in partnership with @sovereign.tech. You can read the report and learn more about our collaboration's effects at ostif.org/2024-sovtech...
2024 Sovereign Tech Agency/OSTIF Audit Impact Report – OSTIF.org
ostif.org
January 8, 2025 at 3:30 PM
Sorry for the hiccup with our tag in the previous post! Our thanks again to @ostifofficial.bsky.social for their help with this important audit, which you can again read about in our blog post:

blog.thunderbird.net/2025/12/thun...
Thunderbird Send Security Audit with OSTIF and 7ASecurity - The Thunderbird Blog
As we get ready for the Thunderbird Pro launch, we want every service we offer to be secure and worthy of the trust our community places in us. That means being honest about where we stand today and t...
blog.thunderbird.net
December 10, 2025 at 5:06 PM
In partnership with @aswf.io, OSTIF and @shielder.com worked on audits of MaterialX and OpenEXR. Our deepest gratitude for this opportunity to work with incredible maintainers and cool projects such as these- read about them at our blogs: ostif.org/materialx-au..., ostif.org/openexr-audi...
July 31, 2025 at 4:03 PM
Node.js receives a Security Audit openjsf.org/blog/objecti... - The OpenJS Foundation has secured funds to sponsor a fuzz-test security audit on the Node.js code-base, resulting in updates and fixes to the OSS-Fuzz project in support for Node.js related code.
Enhancing Node.js Security: Highlights from the Recent Audit | OpenJS Foundation
The OpenJS Foundation is pleased to share the results of the recent Node.js security audit conducted by Ada Logics, in collaboration with the Open Source Technology Improvement Fund (OSTIF).
openjsf.org
January 30, 2025 at 4:00 PM
🔹 Keeping cloud-native security strong – dub.sh/cncf-securit...
🔹 Advancing performance, networking for cloud & edge: dub.sh/vyos
🔹 Building a quantum-safe future – dub.sh/quantum-thre...
OSTIF Announces Linkerd Security Audit Results
The Open Source Technology Improvement Fund (OSTIF) is proud to share the results of our security audit of Linkerd. Linkerd is an open source service mesh for Kubernetes which prioritizes reliability…
dub.sh
February 25, 2025 at 9:19 PM
🚨 New Open Source Audit Alert! 🚨

Shielder, with @ostifofficial.bsky.social & @cncf.io, audited karmada-io:
🔍 6 issues found (1 high, 1 medium, 2 low, 2 info)
✔️ Most fixed, others planned.
🗣️ to @suidpit.bsky.social and @thezero.org

Full details in the blog post!

www.shielder.com/blog/2025/01...
Shielder - Karmada Security Audit
Karmada Security Audit, sponsored by the CNCF (Cloud Native Computing Foundation), facilitated by Open Source Technology Improvement Fund (OSTIF) and performed by Shielder.
www.shielder.com
January 16, 2025 at 4:01 PM
Good milestone for Inspektor Gadget: its first independent security audit is complete. Thanks to @ostifofficial.bsky.social , @cncf.io , and @inspektor-gadget.io for the transparency around the process and fixes.
techcommunity.microsoft.com/blog/Linuxan...

#Kubernetes #eBPF #OpenSource #Security
Inspektor Gadget Completes First Independent Security Audit
CNCF's Inspektor Gadget passes its first independent security audit by Shielder and OSTIF, with all findings patched in v0.50.1. See what they found.
techcommunity.microsoft.com
May 12, 2026 at 6:47 PM