None
EN
Securing open-source infrastructure with OSTIF
['Trail Of Bits']
The Trail of Bits Blog
Some of our more popular offerings include secure code review powered by bespoke fuzzing harness and fuzz test development, our custom static analysis rulesets, and targeted manual review; threat modeling exercises involving architectural review, systems thinking, and threat scenario development; CI/CD pipeline hardening; and fix reviews. When we follow threat modeling work with secure code review, our code review can start from the design-level findings that our threat modeling work resulted in. Working with the JKube maintainers between March and May of 2023, we conducted a lightweight threat model, a secure code review, and a fix review evaluating changes made to JKube after our secure code review.