apache / apache/cassandra-gocql-driver

Integrating gocql into OSS-fuzz

Open
#1,471 2 comments 1 reaction 0 assignees View on GitHub
Dominant language
Go
Stars
2.7k
Forks
658
PR merge metrics
No merged PRs in 30d

Description

Dear maintainers of gocql

This is an offer to integrate gocql into Googles [OSS-fuzz](https://github.com/google/oss-fuzz) project. I have tested the existing fuzzer on the OSS-fuzz platform, as since I have all the build scripts available, I will be happy to finish the integration. All I need are the email addresses of the maintainers to whom bug reports should be sent. These email addresses will be publicly available and can be changed anytime.

OSS-fuzz is a project by Google that offers free CPU power to run fuzzers for open source projects. On top of the hardware is a platform that schedules fuzz runs and provides access to an in-depth dashboard with statistics of runs and bugs.

If a bug is found, a link to a detailed report is sent to all maintainers on the contact list, and the bug is subject to a 90 days disclosure policy.

While OSS-fuzz is a free service, it is required by maintainers to fix the bugs, so that the resources spent of fuzzing open source software result in better security for the open source landscape.

ADA Logics is a contributor to security of open source software, and we have integrated dozens of projects into OSS-fuzz some of which are Prometheus, fasthttp, fastjson, grpc-gateway, TiDB, Dragonfly, Vitess, and other large Go projects are already integrated as well like Kubernetes and Coredns.

Kind regards
Adam

Contributor guide

Open the contributing guide

Research direction

Review the existing fuzzer and the available build scripts, then check the OSS-Fuzz integration requirements described in the issue. Confirm the maintainers' public email addresses and complete the integration so OSS-Fuzz can run the fuzzer and route bug reports to the listed contacts.

Written by the indexing model from the issue text.

Assessment

Tech stack
go
Domain
databases, security
Issue type
Feature
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.