The OpenSSF 2024 Annual Report is out! https://hubs.la/Q034JbJs0 This year was experimental for us (OpenRefactory, Inc.), as well as for Alpha Omega. We mainly took two approaches to combat the threats in open-source software. First, we focused on finding bugs at scale using static analysis (it works great, you just need the right tools). Secondly, we focused on three most popular and important open-source projects to find and fix their supply chain security. We're building "Project Clean Beach" on that idea, focusing on the most important part of your software-- the software you didn't write (eg. dependencies). Find more at https://lnkd.in/gzWcBSSX Munawar Hafiz Mushfique Manzoor Charlie Bedard
OpenRefactory, Inc.
计算机和网络安全
Milpitas,CA - California 1,322 位关注者
We Protect You from the Catastrophic Risks of Software Failure!
关于我们
We are developing power tools that allow developers to automatically fix security problems in their software. Currently, we are offering solutions for Java and C developers. 1. Program Transformations to Fix Security Problems * Memory Corruption * Resource/Memory Leak * Buffer Overflow (C) * Bad Pointer Arithmetic (C) * SQL Injection (Java) * Integer Handling Issues * Concurrency Issues 2. Automatic Compliance to Secure Coding Standards * CERT Secure Coding Standard for Java * CERT Secure Coding Standard for C * MISRA Standard 3. Correct and Complex Refactoring for C and Java 4. Custom Refactoring for Fixing Security and Performance Issues We’ve done the hard work of creating tools that identify and repair security bugs. Now your developers can work hard on what’s really important: writing great code and completing projects on time.
- 网站
-
http://www.openrefactory.com/
OpenRefactory, Inc.的外部链接
- 所属行业
- 计算机和网络安全
- 规模
- 11-50 人
- 总部
- Milpitas,CA - California
- 类型
- 私人持股
- 创立
- 2016
- 领域
- Program Tranformation、Security、Refactoring、Program Analysis、Developer Tools、DevOps、DevSecOps、BugDetection、SAST、Fixer和Java
产品
Intelligent Code Repair (iCR) for Java
静态应用安全测试 (SAST) 软件
iCR for Java automatically FIXes 71 types of Security Vulnerability, Reliability and Compliance bugs in your codebase written in Java and Spring, Springboot, Android and JavaEE frameworks. Some of the major 71 types of FIXers are API Usage Issues Arithmetic Issues Bad Control Flow Concurrency Issues Improper Access Control Improper Method Call Null Pointer Issues Object Visibility Security Misconfiguration Issues Sensitive Data Exposure Cross Site Request Forgery Issues Weak Cryptography Issues The detailed list of FIXers are available in the below link https://www.openrefactory.com/wp-content/uploads/2020/12/iCR-for-Java-2.0-Fixer-Summary.pdf
地点
OpenRefactory, Inc.员工
动态
-
How good is DeepSeek in driving an AI agent? We tested DeepSeek with three other flagship LLM models to compare the capability to drive an agent that attempts to build an open source package from scratch. To our surprise, DeepSeek's MoE architecture did much better than the others. It was able to build 14 of the 15 packages under test. The next best was 11. https://lnkd.in/gFF2Szei #deepseek #openai #gemini #comparison #agenticai #llm
-
Our CEO, Dr. Munawar Hafiz is attending #FOSDEM this weekend. Let's meet to protect you from catastrophic risk of software failure.
I am traveling to FOSDEM for my talk on the Apache Airflow work with Jarek Potiuk and Michael Winser. I am risking a chance to catch Covid/Flu/Both and am looking forward to engaging in great conversations over the weekend. I will be mostly hanging around the SBOM, Security and Rust rooms. Let us connect. https://lnkd.in/gU72zwzE
-
Here is a note from an OSS maintainer that we received recently. "First off, thank you very much for creating an issue. I rarely have people investigating security or performance issues for me, and seeing as you (or the tool you're using) is going to such depth, I can't help but feel very thankful." Project Clean Beach (https://lnkd.in/gYu-qcw2) is finding previously undetected security, reliability and performance issues is open source code and working with open source maintainers to fix the problems. #opensource #supplychain #sca
-
Dr. Munawar Hafiz will be speaking on "Our SAST Tools have Failed Us" at The Elephant in AppSec Conference on 7th Nov 2024. Register at https://lnkd.in/gf3tCM6r #SAST #appsec #appsecurity #applicationsecurity #projectcleanbeach
Be there, will be wild !
-
-
ERA Infotech Limited, a leading IT services company developing business solutions and services for banks, non-bank financial institutions (NBFIs), corporations as well as the Government Sector, focusing on innovation, quality and scalability has selected OpenRefactory's Managed Security Audit Service to protect itself from catastrophic risks of software failure. Our gratitude to Muhammad Mabud and Tauhidul Hoque for having confidence on us! #iCR #ManagedSecurityAudit #security #appsecurity #appsec #sourcecodesecurity
-
-
OpenRefactory, is introducing Project Clean Beach at the #OWASPGlobalAppSec2024 in San Francisco this week. We are cleaning the vast compendium of Open Source libraries that everyone uses but which carry undetected and dangerous security flaws. We think of the public world of Open Source like a public beach that we all share but we also wish it were safe and clean. And we're cleaning it up with support from major players like Amazon, Microsoft and Google through their support of the Alpha-Omega (https://alpha-omega.dev/) project. At OpenRefactory's Booth S512 security professionals will be able to learn more about how to protect themselves from security attacks through Project Clean Beach. Visit us at Booth S512 for Project Clean Beach.
-
-
Michael Winser and Dr. Munawar Hafiz will be presenting Project Clean Beach today at the Open Source Summit Europe 2024
Michael Winser and I will be presenting at the Open Source Summit on Tuesday. Project Clean Beach attempts to fix the reactive approach of Supply Chain Security with a pro-active approach to detect and fix unknown bugs in open source dependencies at scale. https://lnkd.in/gJRe9GiV
-
We are excited to partner with Jarek Potiuk and Michael Winser in this project. This keynote will be starting the Airflow Summit. It will be a blast! Apache Airflow
Independent Open-Source Contributor and Advisor, Committer and PMC member of Apache Airflow, Member of the Apache Software Foundation, member of ASF Security Committee
My first-ever keynote at a conference! Together with Michael Winser from Alpha Omega at Airflow Summit we will talk about innovative "Airflow Beach Cleaning" project - about securing the whole Apache Airflow software supply chain - united effort of Python Software Foundation The Apache Software Foundation Apache Airflow PMC and Alpha Omega Dev. It's also Apache Airflow's 10th anniversary and we will talk a lot about Airflow 3 that is a major step-up for Airflow and we are working on it! Let's meet in San Francisco this week!
-
Test Driving SonarCloud on Kubernetes to understand the bugs it reports in Golang applications. https://lnkd.in/gm7WyNen * SonarCloud found 16,244 bugs with 16,244 false warnings/WONTFIX issues (100%). * Not a single serious bug is found. * SonarCloud missed one known high severity data race bug (https://lnkd.in/gVaxbNK2). * Triaging cost 2,707 hours ($351,910). * No improvement in quality. #sast #testdrive #sonarcloud #golang #opensource #sonarqube
Test Drive Your Bug Detection And Fixing Tools - SonarCloud on Kubernetes
https://www.youtube.com/