Public proof
Evidence you can inspect. Misses included.
Our open-source security work on the software the world runs on, published in full with the evidence behind every finding.
The public roster
Our open-source security work.
Every card here is public — a merged fix, a public pull request, or a public issue you can open — from security work we did on the open-source software the world runs on, and reported upstream. We count a finding as ours when it was fixed after we reported it, whoever the fix is credited to. Open a card to read that project’s findings and their evidence.
The public register lists every finding across engagements, entry by entry. Open the public register →
Some of these fixes landed as the vendor’s own pull requests; some carry a CVE credited to us by name, as on rsync; some a credit that went elsewhere. We claim them the same way regardless: reported first, fixed after. Unpatched reports with nothing public yet, and anything we reported privately, are not shown here.
The public register, entry by entry →Walk the jsonparser evidence →
01 · Read the labels
The public dashboard is a seeded showcase.
The open entries on the public dashboard are seeded. The showcase branch carries demonstration defects next to the real history, and each one says so on its own page. The campaign's real findings sit under Fixed. If you open the dashboard expecting a live defect queue, read the labels first.
02 · The bar
Public methodology
The bar this work is judged against is published, and it is written to survive a hostile reading. It is not restated here, because a summary of a bar is not a bar.
-
The clauses
What a promise has to satisfy before anything is judged against it, and the check that enforces each clause.
-
Who checks the checker
What machines decide, what a person decides, and where that line is written down so you can move it.
-
What happens after a fix
Why the reproducer stays in the suite, and what the record claims once the fix is verified.
03 · Standing offer
Apply for an open-source audit
One open-source pre-release audit each quarter, self-funded, coordinated with the maintainers and run on their schedule. No invoice, and no commercial follow-up.
This ledger has to earn the right to be believed, and open source is the only place it can. A client's requirements corpus describes their product in enough detail that publishing it would publish the product, and no permission fixes that. So the public record grows one self-funded open-source audit at a time, and paying our own way keeps the entries free of anyone's release marketing.
Maintainers, apply with the repository and what worries you most about it. If a release is coming, say when.
- The map of the promises we recover, joined to the code that carries them and the tests that check them.
- The findings, each one validated by a person before it reaches you.
- Each finding carries a test you can run, and the record carries the command that runs it. Run them yourself. Keep them in your suite.
A person validates every finding before it reaches you.