Happy to announce our #fuzzing work on #LLVM focused on continuous fuzzing by way of OSS-Fuzz -- LLVM is now the project with most lines covered of all OSS-Fuzz projects! Thanks to collaborators @OSTIFofficial and @sovtechfund Full report is available in adalogics.com/blog/llvm-fuzz…
Holistic security audit of @kyverno : Supply Chain Security with #SLSA, #Fuzzing with OSS-Fuzz, Manual code review and Threat modelling! Full details in the report. Great collaboration with @kyverno maintainers, @OSTIFofficial and @CloudNativeFdn
We made a video introducing a recent OSS-Fuzz Visual Studio Code extension! Exciting new extension to help writing fuzzing harnesses for open source projects easier
OSS-Fuzz Visual Studio Code Extension Introduction! New extension that can significantly improve #fuzz dev experience. I made a demo in which I increase cJSON code coverage from 43% to 73% using convenient features from the extension: youtube.com/watch?v=7bvRbE…
See our security work on @argoproj -- 26 security issues. 9 CVEs. 1 critical and 4 high, and extensive #fuzzing extensions. Thanks to @AdamKorcz4 for leading the auditing team and @OSTIFofficial and @CloudNativeFdn for collaboration. Thanks to all of the @argoproj as well!
We have published our work with @ADALogics and @CloudNativeFdn on Argo! We made a lot of progress together on this project and Argo is now patched against multiple serious issues and has improved testing!
ostif.org/our-audit-of-a…