Dapr september 2023 security audit report
consuming packages from mirrors instead of the main and intended packages. These are known attack vectors; recently researchers found 1,652 malicious packages disguised as legitimate packages8. SLSA compliance security audit 2023 This type of risk applies to all open source projects that use other open source packages in their dependency trees. The Scorecard project11 aims to mitigate that risk by formalizing a set0 码力 | 47 页 | 1.05 MB | 1 年前3Dapr june 2023 fuzzing audit report
securing the so�ware in the CNCF landscape. Demonstrating and ensuring the security of these so�ware packages is vital for the CNCF ecosystem and the CNCF continues to use state of the art techniques to secure the Dapr fuzzers are the two key so�ware packages that OSS-Fuzz uses to fuzz Dapr. The following figure gives an overview of how OSS-Fuzz uses these two packages and what happens when an issue is found/fixed0 码力 | 19 页 | 690.59 KB | 1 年前3Dapr february 2021 security audit report
cure53.de · mario@cure53.de way to rectify past security mistakes. In effect, three work packages (WPs) were delineated: • WP1: Thorough source code audit of the latest Dapr version • WP2: Penetration0 码力 | 9 页 | 161.25 KB | 1 年前3Dapr july 2020 security audit report
stood at twenty person-days. To best address the objectives expressed by the Dapr team, two work packages (WPs) were outlined. In WP1, Cure53 performed both a broad and thorough source code audit of the0 码力 | 19 页 | 267.84 KB | 1 年前3
共 4 条
- 1