qemu-devel.nongnu.org archive mirror
 help / color / mirror / Atom feed
* Possible reward for fuzzer bug fixes? Secure Open Source Rewards Program
@ 2021-10-28 14:48 Alexander Bulekov
  2021-10-29  8:53 ` Qiuhao Li
  2021-11-23 14:56 ` Thomas Huth
  0 siblings, 2 replies; 4+ messages in thread
From: Alexander Bulekov @ 2021-10-28 14:48 UTC (permalink / raw)
  To: qemu-devel
  Cc: Thomas Huth, Qiuhao Li, Darren Kenny, Bandan Das, Stefan Hajnoczi,
	Paolo Bonzini

Recently a pilot for the Secure Open Source Rewards program was
announced [1]. Currently this program is run by the Linux Foundation and
sponsored by the Google Open Source Security Team.

The page mentions that patches for issues discovered by OSS-Fuzz may be
eligible for rewards. This seems like it could be a good incentive for
fixing fuzzer bugs.

A couple notes:
 * The program also rewards contributions besides fuzzer-bug fixes.
   Check out the page for full details.
 * It seems that QEMU would qualify for this program. The page mentions
   that the project should have a greater than 0.6 OpenSSF Criticality
   Score [2]. This score factors in statistics collected from github
   (sic!). QEMU's score is currently 0.81078
 * Not limited to individual contributors. Vendors can also qualify for
   rewards.
 * Work completed before Oct 1, 2021 does not qualify.
 * Individuals in some sanctioned countries are not eligible.
 * The process seems to be:
    1. Send a fix upstream
    2. Get it accepted
    3. Fill out a form to apply for a reward

Any thoughts about this? Should this be something we document/advertise
somewhere, so developers are aware of this opportunity?

[1] https://sos.dev/
[2] https://github.com/ossf/criticality_score

-Alex


^ permalink raw reply	[flat|nested] 4+ messages in thread

end of thread, other threads:[~2021-11-23 14:58 UTC | newest]

Thread overview: 4+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2021-10-28 14:48 Possible reward for fuzzer bug fixes? Secure Open Source Rewards Program Alexander Bulekov
2021-10-29  8:53 ` Qiuhao Li
2021-11-01 16:01   ` Alexander Bulekov
2021-11-23 14:56 ` Thomas Huth

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).