security

DO NOT USE IN PRODUCTION

Wednesday, August 28, 2024 - 00:41 by Marta Rybczynska
Do you have a demo or examples in a specific repository? Or perhaps you have a functionality that needs time to mature, and you publish it in the open source spirit, but nobody should use it (yet) in a production setup? If you have such a code, mark it clearly...

Using GitHub Private Vulnerability Reporting by Eclipse Foundation Projects

Thursday, August 8, 2024 - 14:31 by Marta Rybczynska
Eclipse Foundation projects can request to use GitHub Private Vulnerability Reporting . This feature allows committers of projects hosted on GitHub to receive potential vulnerability reports in a confidential way. When you are working on an existing vulnerability report, you might see the “Request CVE” button. Please do not use...

Update to vulnerability description - CVSS 4.0

Friday, July 26, 2024 - 02:56 by Marta Rybczynska
A vulnerability description includes several fields, like the title and description. However, one is causing difficulties for people writing CVE (Common Vulnerability Enumeration) entries: the CVSS (Common Vulnerability Scoring System) vector. CVSS is an important field because it answers a fundamental question about the vulnerability: "How serious is it?" A...

Eclipse CycloneDDS Security Audit Has Been Completed

Monday, June 24, 2024 - 08:21 by Marta Rybczynska
Today, the Eclipse Foundation released the results of our security audit for Eclipse CycloneDDS . Findings from the audit have been addressed in the latest versioned source code of Eclipse CycloneDDS, available at https://github.com/eclipse-cyclonedds/cyclonedds . Eclipse CycloneDDS is an implementation of the Data Distribution Service (DDS) specification published by the...

Join the Conversation: The 2024 IoT & Embedded Developer Survey is Now Open!

Tuesday, May 28, 2024 - 12:41 by Clark Roundy
Exciting news - the 2024 IoT & Embedded Developer Survey is now open! This comprehensive survey provides developers and industry professionals with a unique opportunity to shape the future of IoT and embedded systems by sharing their insights and experiences. Since 2015, we've been at the forefront of exploring the...

Eclipse Kuksa Security Audit Has Been Completed

Tuesday, May 21, 2024 - 03:39 by Marta Rybczynska
Today, the Eclipse Foundation released the results of our security audit for the Eclipse Kuksa project . Findings from the audit have been addressed in the latest version source code of Kuksa available from https://github.com/eclipse-kuksa/kuksa-databroker . Please note that the repository has changed locations recently, so update your links. One...

OCX 2024: Celebrating Community, Code and Collaboration

Thursday, April 11, 2024 - 14:25 by Clark Roundy
TL;DR - Don't miss the opportunity to participate in Open Community Experience 2024, a new conference for our vibrant community of communities. At the Eclipse Foundation, our ethos is anchored in three pivotal Cs: Community, Code, and Collaboration. These principles are so integral to our mission that when we re-envisioned...

202404-01 Eclipse Foundation Security Advisory

Thursday, April 4, 2024 - 00:21 by Marta Rybczynska
The Eclipse Foundation Security Team has been made aware of the vulnerability VU#421644 affecting multiple HTTP/2 implementations, that could cause an out-of-memory crash. The crash could happen if there is an insufficient limit on insufficient limitation of the number of CONTINUATION frames in one stream. The description of the issue...