2025 Annual Report

2025 marked the 10th year of OSTIF. This year, we published 24 audits, worked on behalf of almost 50 projects, and partnered with 10 different funding bodies to create security outcomes for open source projects. As a result, 231 findings with security impact have been reported and over 98% of…

Continue Reading2025 Annual Report

CRI-O Audit Complete!

The Open Source Technology Improvement Fund is proud to share the results of our security audit of CRI-O. CRI-O is an implementation of the Kubernetes Container Runtime Interface (CRI) that is OCI-compliant (-O) that provides the backend between OCI-format container images and the Kubernetes control plane. With the help of…

Continue ReadingCRI-O Audit Complete!

The Open Source AI Series: A security health check of 25 popular open source AI/LLM projects: Findings and lessons learned

By Adam Korczynski and David Korczynski of Ada Logics In late 2024, Alpha-Omega partnered with Ada Logics and the Open Source Technology Improvement Fund (OSTIF) to audit 25 widely used open source projects in the AI and large language model (LLM) ecosystem. This initiative aimed at evaluating the overall security…

Continue ReadingThe Open Source AI Series: A security health check of 25 popular open source AI/LLM projects: Findings and lessons learned

OpenSSF Scorecard Audit is Complete!

The Open Source Technology Improvement Fund is proud to share the results of our security audit of OpenSSF Scorecard. OpenSSF Scorecard is an open source automated testing resource to help projects continually assess security risks. With the help of ADA Logics and the OpenSSF, this project can continue to provide…

Continue ReadingOpenSSF Scorecard Audit is Complete!

GNU libmicrohttpd2 Audit Complete!

The Open Source Technology Improvement Fund is proud to share the results of our security audit of GNU libmicrohttpd2. GNU libmicrohttpd2 is an open source library that “embeds a HTTP or HTTPS daemon into host applications.”* With the help of ADA Logics and the Sovereign Tech Agency, this project has…

Continue ReadingGNU libmicrohttpd2 Audit Complete!

The Bridge to Improving Security: How OSTIF Helps Foundations

Over the duration of multiple programs with funders, we’ve heard firsthand their needs. Executives know they have the budget and desire to fund security, but need help with how to start generating outcomes. To create and sustain open source security programs requires dedicated administration work, experience with the open source…

Continue ReadingThe Bridge to Improving Security: How OSTIF Helps Foundations