Public proof

Evidence you can inspect. Misses included.

Our open-source security work on the software the world runs on, published in full with the evidence behind every finding.

The public roster

Our open-source security work.

Every card here is public — a merged fix, a public pull request, or a public issue you can open — from security work we did on the open-source software the world runs on, and reported upstream. We count a finding as ours when it was fixed after we reported it, whoever the fix is credited to. Open a card to read that project’s findings and their evidence.

The public register lists every finding across engagements, entry by entry. Open the public register →

Some of these fixes landed as the vendor’s own pull requests; some carry a CVE credited to us by name, as on rsync; some a credit that went elsewhere. We claim them the same way regardless: reported first, fixed after. Unpatched reports with nothing public yet, and anything we reported privately, are not shown here.

01 · Read the labels

The public dashboard is a seeded showcase.

The open entries on the public dashboard are seeded. The showcase branch carries demonstration defects next to the real history, and each one says so on its own page. The campaign's real findings sit under Fixed. If you open the dashboard expecting a live defect queue, read the labels first.

02 · The bar

Public methodology

The bar this work is judged against is published, and it is written to survive a hostile reading. It is not restated here, because a summary of a bar is not a bar.

  • The clauses

    What a promise has to satisfy before anything is judged against it, and the check that enforces each clause.

  • Who checks the checker

    What machines decide, what a person decides, and where that line is written down so you can move it.

  • What happens after a fix

    Why the reproducer stays in the suite, and what the record claims once the fix is verified.

03 · Standing offer

Apply for an open-source audit

One open-source pre-release audit each quarter, self-funded, coordinated with the maintainers and run on their schedule. No invoice, and no commercial follow-up.

This ledger has to earn the right to be believed, and open source is the only place it can. A client's requirements corpus describes their product in enough detail that publishing it would publish the product, and no permission fixes that. So the public record grows one self-funded open-source audit at a time, and paying our own way keeps the entries free of anyone's release marketing.

Maintainers, apply with the repository and what worries you most about it. If a release is coming, say when.

  • The map of the promises we recover, joined to the code that carries them and the tests that check them.
  • The findings, each one validated by a person before it reaches you.
  • Each finding carries a test you can run, and the record carries the command that runs it. Run them yourself. Keep them in your suite.

A person validates every finding before it reaches you.