eclipse-tractusx / eclipse-tractusx/sig-security

Mystios is available for Security Team of Eclipse Foundation, lets add tractusx to the list

Open
#90 1 comment 0 reactions 0 assignees View on GitHub
Dominant language
No language data
Stars
0
Forks
6
PR merge metrics
No merged PRs in 30d

Description

https://gitlab.eclipse.org/eclipsefdn/security/ai-scan-enrollment

Email from eclipse foundation:

Dear Committers,

I am pleased to announce that the Eclipse Foundation is now officially part of Anthropic's Project Glasswing. Through this partnership, the Eclipse Foundation Security Team has access to Claude Mythos 5, which we are using to strengthen the security of Eclipse projects.

Some background: thanks to our partnership with Alpha-Omega, the Security Team has had access to Mythos in its preview version since Glasswing's debut. Over the last quarter, we used it to scan all Eclipse Foundation projects, and many of you have already received reports from us through the standard vulnerability-reporting process.

We are now taking this work to the next stage with a new campaign with Mythos 5 running through the end of October 2026.

What this means for your project:
Reviews combine automated and AI-assisted analysis with human validation by the Security Team.
All Eclipse Foundation projects will eventually be reviewed, whether or not they enroll. Enrollment is a prioritization mechanism, not a permission or opt-out mechanism.
If we validate a credible finding, a private vulnerability report will normally be your first notification that a review has taken place. The finding is then handled through the Eclipse Foundation's coordinated vulnerability-management process, and we work with you on validation, remediation, release, and disclosure.
If a review produces no credible findings, we will notify the project once the review is complete.
Get prioritized

We cannot offer Glasswing seats to the community, but we would like to prioritize projects that are ready to engage more closely with us throughout the process. If your project team is prepared to collaborate on validation and remediation, your repositories are actively maintained, and your project security team includes active Committers who can act on reports, we encourage you to enroll.

To enroll, follow [these instructions](https://gitlab.eclipse.org/eclipsefdn/security/ai-scan-enrollment/-/blob/main/README.md#how-to-enroll) and open a merge request in:
https://gitlab.eclipse.org/eclipsefdn/security/ai-scan-enrollment

Enrollment is not first come, first served and does not guarantee a particular review date. Scheduling depends on program priorities and available capacity. Please note that the enrollment repository and its merge requests are public: do not use them to report vulnerabilities or include sensitive information.

Questions about the program can be sent to [security@eclipse-foundation.org](mailto:security@eclipse-foundation.org) or discussed publicly in the Eclipse CSI GitHub Discussions: https://github.com/orgs/eclipse-csi/discussions

Thank you for your continued commitment to the security of the Eclipse ecosystem.

Kind regards,

Mikaël Barbero
Head of Security | Eclipse Foundation
🔗 [Eclipse Foundation Security Homepage](https://www.eclipse.org/security/)
💬 [Discuss at GitHub](https://github.com/orgs/eclipse-csi/discussions)

Contributor guide

Open the contributing guide

Research direction

Start with the linked Eclipse Foundation AI scan enrollment repository and read the README section on how to enroll. Inspect the existing project entries and determine how Tractus-X should be added. Done means a merge request has enrolled Tractus-X in the project list and follows the repository's stated process.

Written by the indexing model from the issue text.

Assessment

Domain
security
Issue type
Feature
Difficulty
2/5
Estimated time
1-3 hours
Activity status
Active
Clarity
Mostly clear
Newbie friendliness
48/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.