Visualização de leitura

OWASP OASIS is looking for AppSec validators; 10 minutes, real upstream impact

Quick context on why I'm posting this here: AI is making it a lot easier for attackers to find and exploit vulnerabilities in open source projects faster than most maintainer teams can keep up with. At the same time, AI can generate candidate fixes at scale. No one had figured out how to get trustworthy human eyes on those fixes before they went upstream.

That's what OASIS (Open Automated Security Initiative for Software) is for. It's a community-run project under OWASP: not a product, not owned by any one company. AppSec practitioners volunteer to validate AI-generated fixes for real open-source vulnerabilities, and the good ones get pushed upstream to maintainers.

OASIS is rolling out an alpha and looking for actual volunteers across a few roles: validators, regional community leads, open source liaisons, and more. Whatever your background, there's probably a way to plug in. There are already several hundred signed up.

There is plenty to do, sign up and help us out at: owasp-oasis.org

Happy to answer anything in the comments!

submitted by /u/Responsible_Rogue
[link] [comments]
❌