ossf / ossf/tac

Source Code Security Audit Sprints for OpenSSF TI Repositories

Open
#643 1 comment 0 reactions 2 assignees View on GitHub

@Naomi-Wash is already working on this.

Since Aug 5, 2026.

administration For Review TI Funding Request
Dominant language
No language data
Stars
152
Forks
86
Avg merge
5d 14h
Merged PRs (30d)
9

Description

Technical Initiative

Repository Security, Software Supply Chain, SBOM Tools, Developer Best Practices, or a specific OpenSSF project that wants audited repositories.

Lifecycle Phase

Sandbox

Funding amount

45000

Problem Statement

OpenSSF Technical Initiatives and open-source maintainers are increasingly expected to provide evidence of secure development, dependency hygiene, vulnerability management, SBOM readiness, secrets protection, and software supply-chain assurance. However, many maintainers lack the time, tooling, and specialist support needed to perform structured source-code security audits across SAST, SCA, secrets, IaC, containers, SBOM, and license governance. This creates a practical gap between ecosystem security expectations and maintainer capacity. Projects may have scattered security tools, incomplete triage, limited SBOM evidence, or no consistent way to convert findings into a prioritised remediation backlog. The result is increased risk for projects, downstream users, adopters, and organisations that depend on open-source software.

Who does this affect?

This affects maintainers of participating OpenSSF Technical Initiative repositories, downstream users of those projects, enterprise adopters, public-sector users, software suppliers, and the broader open-source ecosystem. The proposed work is for maintainers who need actionable code-security findings and reusable assurance evidence without creating additional operational burden. It also benefits security reviewers, contributors, and adopters by improving visibility into dependency risk, secrets exposure, code-level vulnerabilities, IaC/container risks where applicable, SBOM quality, and remediation priorities.

Have there been previous attempts to resolve the problem?

Many open-source projects already use individual tools such as GitHub security features, Dependabot, Scorecard, CodeQL, SBOM generators, or ad hoc scans. These efforts are valuable, but they are often fragmented, tool-specific, and not always converted into a maintainer-ready audit report with prioritised remediation guidance and evidence outputs. This initiative is different because it proposes a structured audit sprint model. Nucleus Systems will use the Paxley Code Security Platform as the automated evidence layer, then add expert validation, deduplication, prioritisation, maintainer review, and a reusable reporting approach. The focus is not only finding issues, but helping maintainers understand what matters, what can be fixed, what should be accepted as residual risk, and what evidence should be retained for future assurance.

Why should it be tackled now and by this TI?

This is timely because software supply-chain security, SBOM adoption, secure development practices, and AI-generated code risks are now central concerns for open-source ecosystems. Regulatory and procurement expectations around secure software development and SBOM evidence are increasing, while maintainers continue to face limited time and security capacity. This TI is an appropriate place to sponsor the work because the proposed audit model directly supports OpenSSF’s mission of improving open-source software security. OpenSSF states that funding examples include audits, and the TAC review considers technical alignment, OpenSSF mission alignment, TI standing, and funding amount against lifecycle stage

Give an idea of what is required to make the funding initiative happen

The initiative requires a sponsoring OpenSSF Technical Initiative, agreement on 3–5 repositories for the pilot, maintainer contacts for each repository, and permission to run code-security analysis using Paxley and supporting open-source engines. The initiative will also require agreement on vulnerability disclosure handling, including which findings remain private until remediated and which outputs can be shared publicly.

Nucleus Systems will configure audit profiles, run Paxley scans, validate priority findings, generate SBOM and software assurance outputs, conduct maintainer review sessions, and deliver final audit packs. The participating TI will help coordinate repository selection, maintainer availability, feedback on false positives, remediation prioritisation, and acceptance of final outputs.

What is going to be needed to deliver this funding initiative?

Delivery will require:

  • Repository access or authorised scan access for 3–5 selected repositories.
  • Maintainer coordination for scoping, triage review, and remediation planning.
  • Paxley scan configuration for SAST, SCA, secrets, IaC/container checks where applicable, license policy review, and SBOM generation.
  • Expert validation by Nucleus Systems to reduce false positives and focus on material findings.
  • A defined vulnerability disclosure approach aligned with OpenSSF and project expectations.
  • Final audit packs, including prioritised remediation backlogs, SBOM outputs, risk summaries, and reusable audit templates.

Nucleus Systems will provide the delivery team, Paxley Code Security Platform (open-source version) configuration, audit methodology, reporting templates, and remediation guidance.

Are there tools or tech that still need to be produced to facilitate the funding initiative?

No major new tool needs to be built for the pilot. Paxley already provides the core scanning and evidence layer for code security, dependency analysis, secrets review, IaC/container checks where applicable, SBOM generation, and governance outputs.

Minor project-specific configuration may be required, including repository onboarding, scan profile tuning, SBOM export formatting, vulnerability triage rules, and final report packaging. If the TI wants public-facing outputs, a lightweight anonymised lessons-learned template may also be produced.

Give a summary of the requirements that contextualize the costs of the funding initiative

The requested $45,000 covers an 8–10-week pilot audit sprint for 3–5 repositories. The cost reflects technical onboarding, scan configuration, automated analysis, expert validation, false-positive reduction, maintainer review, remediation guidance, reporting, SBOM generation, and final delivery of reusable audit artefacts.

The work includes both automated tooling and human security expertise. This is important because raw scanner output alone is not sufficient for maintainers. The value comes from turning findings into actionable, prioritised, and evidence-backed remediation guidance that maintainers can realistically use.

Who is responsible for doing the work of this funding initiative?

Godfrey H. Kutumela, CEO and Lead Cybersecurity Practitioner, Nucleus Systems Email: godfrey.kutumela@nucleus-systems.com Godfrey will be responsible for delivery oversight, audit methodology, maintainer engagement, and final assurance outputs.

Who is accountable for doing the work of this funding initiative?

An eligible OpenSSF Technical Initiative requesting funding for source-code security audit services, delivered by Nucleus Systems using its custom developed Paxley Code Security Platform.”

If the responsible or accountable parties are no longer available, what is the backup contact or plan?

Nucleus Systems will maintain shared project documentation, repository scope, scan configuration records, issue logs, and draft reports so that another authorised Nucleus Systems practitioner or TI representative can continue coordination without loss of context.

What license is this funding initiative being used under?

Audit outputs and reusable templates: Creative Commons Attribution 4.0 International, unless the sponsoring TI requires another OpenSSF-approved documentation license. Any reusable scripts, configuration examples, or CI/CD workflow templates produced for public use: Apache License 2.0, unless otherwise agreed with the sponsoring TI. Sensitive vulnerability details: Not publicly licensed until disclosure and remediation handling are agreed with maintainers.

Code of Conduct
  • I agree to follow the OpenSSF's Code of Conduct
List the major milestones by date and identify the overall timeline within which the technical initiative plans to accomplish their goals. Any payments for services, sponsorships, etc., will require LF Legal and Financial review.

Milestones and approximate costs

Overall timeline: 8–10 weeks from funding approval and contracting completion.

Milestone 1 — Scoping and audit design, weeks 1–2 — $7,500
Confirm sponsoring TI, repository list, maintainer contacts, vulnerability disclosure process, audit scope, scan profiles, reporting format, and public/private output boundaries.

Milestone 2 — Paxley onboarding and baseline scans, weeks 2–4 — $10,000
Configure Paxley for selected repositories and run baseline SAST, SCA, secrets, IaC/container checks where applicable, license review, and SBOM generation.

Milestone 3 — Expert validation and triage, weeks 4–6 — $12,500
Validate critical and high findings, remove duplicates, reduce false positives, prioritise issues, map findings to remediation themes, and prepare maintainer review packs.

Milestone 4 — Maintainer remediation workshops, weeks 6–8 — $7,500
Conduct review sessions with maintainers, agree remediation priorities, document accepted risks, and provide CI/CD or developer workflow improvement recommendations.

Milestone 5 — Final audit pack and reusable OpenSSF materials, weeks 8–10 — $7,500
Deliver final project audit packs, SBOM outputs, prioritised remediation backlog, public-safe lessons learned, reusable audit checklist, and proposed repeatable model for future TI audits.

Total funding request: $45,000 USD

If this is a request for funding to issue a contract, then OpenSSF will issue that contract. Please provide a Statement of Work (SOW) that we may review. Any contracting action will take 4-6 weeks to issue.

Statement of Work

Statement of Work: Source Code Security Audit Sprints for OpenSSF Technical Initiative Repositories

  1. Objective
    Nucleus Systems will deliver a structured source-code security audit sprint for 3–5 repositories selected by the sponsoring OpenSSF Technical Initiative. The work will use the Paxley Code Security Platform to produce actionable, maintainer-ready security findings and evidence across code security, dependency risk, secrets exposure, IaC/container risks where applicable, license governance, and SBOM readiness.

  2. Scope of services
    Nucleus Systems will perform repository onboarding, scan configuration, SAST analysis, SCA analysis, secrets scanning, IaC and container analysis where applicable, license policy review, SBOM generation in CycloneDX and/or SPDX format, expert validation of priority findings, maintainer triage sessions, and final reporting.

  3. Deliverables
    Deliverables will include a repository-level audit report, prioritised remediation backlog, SBOM outputs, dependency and license risk summary, secrets exposure summary, IaC/container findings where applicable, CI/CD security recommendations, maintainer workshop notes, and a reusable audit checklist for future OpenSSF TI use.

  4. Out of scope
    The pilot does not include full penetration testing, exploit development, continuous monitoring beyond the audit window, full remediation implementation by Nucleus Systems, formal certification, or public disclosure of sensitive vulnerability details before maintainer approval.

  5. Vulnerability handling
    Sensitive findings will be shared privately with the sponsoring TI and project maintainers. Public outputs will be limited to non-sensitive summaries unless maintainers approve disclosure after remediation or risk acceptance.

  6. Timeline
    The work will run for 8–10 weeks after funding approval, contracting completion, and repository access confirmation.

  7. Funding requested
    The total requested amount is $45,000 USD, allocated across five milestones.

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.