Marta Rybczynska's blog

    The Eclipse Foundation offers a free security training for all Committers and Contributors

    Monday, October 21, 2024 - 11:39 by Marta Rybczynska
    You know that security is important but just have no time to spend digging into numerous tutorials and guides to figure out what’s relevant to you. To support fellow developers, the Eclipse Foundation is offering free security training for all Committers and Contributors. The complete training contains three parts: the...

    Per-Project Security Teams FAQ

    Wednesday, September 4, 2024 - 04:57 by Marta Rybczynska
    In response to requests from various projects and after discussions between the Eclipse Foundation Security Team and the Architecture Council, we announced the creation of Project Security Teams (see the discussion at https://github.com/orgs/eclipse-csi/discussions/4 ) This blog post gives an overview of various questions that we have received in the last...

    DO NOT USE IN PRODUCTION

    Wednesday, August 28, 2024 - 00:41 by Marta Rybczynska
    Do you have a demo or examples in a specific repository? Or perhaps you have a functionality that needs time to mature, and you publish it in the open source spirit, but nobody should use it (yet) in a production setup? If you have such a code, mark it clearly...

    Using GitHub Private Vulnerability Reporting by Eclipse Foundation Projects

    Thursday, August 8, 2024 - 14:31 by Marta Rybczynska
    Eclipse Foundation projects can request to use GitHub Private Vulnerability Reporting . This feature allows committers of projects hosted on GitHub to receive potential vulnerability reports in a confidential way. When you are working on an existing vulnerability report, you might see the “Request CVE” button. Please do not use...

    Update to vulnerability description - CVSS 4.0

    Friday, July 26, 2024 - 02:56 by Marta Rybczynska
    A vulnerability description includes several fields, like the title and description. However, one is causing difficulties for people writing CVE (Common Vulnerability Enumeration) entries: the CVSS (Common Vulnerability Scoring System) vector. CVSS is an important field because it answers a fundamental question about the vulnerability: "How serious is it?" A...

    Eclipse CycloneDDS Security Audit Has Been Completed

    Monday, June 24, 2024 - 08:21 by Marta Rybczynska
    Today, the Eclipse Foundation released the results of our security audit for Eclipse CycloneDDS . Findings from the audit have been addressed in the latest versioned source code of Eclipse CycloneDDS, available at https://github.com/eclipse-cyclonedds/cyclonedds . Eclipse CycloneDDS is an implementation of the Data Distribution Service (DDS) specification published by the...

    Eclipse Kuksa Security Audit Has Been Completed

    Tuesday, May 21, 2024 - 03:39 by Marta Rybczynska
    Today, the Eclipse Foundation released the results of our security audit for the Eclipse Kuksa project . Findings from the audit have been addressed in the latest version source code of Kuksa available from https://github.com/eclipse-kuksa/kuksa-databroker . Please note that the repository has changed locations recently, so update your links. One...

    202404-01 Eclipse Foundation Security Advisory

    Thursday, April 4, 2024 - 00:21 by Marta Rybczynska
    The Eclipse Foundation Security Team has been made aware of the vulnerability VU#421644 affecting multiple HTTP/2 implementations, that could cause an out-of-memory crash. The crash could happen if there is an insufficient limit on insufficient limitation of the number of CONTINUATION frames in one stream. The description of the issue...