eclipse-ee4j / eclipse-ee4j/jersey

Integration of jersey into OSS-Fuzz

Open
#5,049 3 comments 0 reactions 0 assignees View on GitHub
Dominant language
Java
Stars
730
Forks
382
PR merge metrics
No merged PRs in 30d

Description

Hi all,

I have prepared the initial integration https://github.com/CodeIntelligenceTesting/oss-fuzz/commit/8cbf0fbfe26188b6a4927f681377a85bd882ef6b of jersey into [google oss-fuzz](https://github.com/google/oss-fuzz). This will enable continuous fuzzing of this project, which will be conducted by Google. Bugs that will be found by fuzzing will be reported to you. After the initial integration of this project into oss-fuzz, I will continue to add additional fuzz tests to improve the code coverage over time.

The integration requires a primary contact, someone to deal with the bug reports submitted by oss-fuzz. The email address needs to belong to an established project committer and be associated with a Google account as per [here](https://google.github.io/oss-fuzz/getting-started/accepting-new-projects/). When a bug is found, you will receive an email that will provide you with access to ClusterFuzz, crash reports, and fuzzer statistics. More than 1 person can be included. Please let me know who I should include, if anyone.

[Jazzer](https://github.com/CodeIntelligenceTesting/jazzer) is used for fuzzing Java applications. Jazzer is a coverage-guided, in-process fuzzer for the JVM platform developed by Code Intelligence. It is based on libFuzzer and brings many of its instrumentation-powered mutation features to the JVM. Jazzer has already found several bugs in JVM applications: [Jazzer Findings](https://github.com/CodeIntelligenceTesting/jazzer#findings)

Please let me know if you have any questions regarding fuzzing or the oss-fuzz integration.

Contributor guide

Open the contributing guide

Research direction

Review the linked OSS-Fuzz integration commit and the OSS-Fuzz accepting-new-projects requirements first. The issue names no Jersey files or tests; completion depends on identifying an established project committer with a Google account as the primary contact and confirming the integration path with the maintainers.

Written by the indexing model from the issue text.

Assessment

Tech stack
java
Domain
security, testing-qa
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
15/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.