Security Engineer in Residence Program The Open Source Technology Improvement Fund (OSTIF) announced Project V-LAT, a Security Engineer in Residence (SEiR) program funded by Alpha-Omega, a Directed Fund of the Linux Foundation, to address a backlog of about 450 reported security issues in open source projects. The program employs six security researchers (three senior, three intermediate) to triage and fix vulnerabilities, aiming to break the cycle of reactive security funding and support maintainers overwhelmed by AI-driven vulnerability reports. Breaking the Cycle of Security Funding OSTIF has been advocating for open source security funding over the past decade. During that time when there was an exploit or devastating hack, there would be a bump in security investment that quickly waned as the industry moved on to the next development. This year, that pattern was broken wide open with the quick adoption of AI in open source development, management, and security. Project maintainers are drowning in vulnerability reports. With increased demand on maintainers to safely and quickly clear pipelined security reports, the need for sustained resources and programs to address this problem has become clear. The Mission of the SEiR Program Alpha-Omega https://openssf.org/community/alpha-omega/ , a Directed Fund of the Linux Foundation https://linuxfoundation.org , has responded to this flood of security disclosures in part with a program called SEiR Security Engineer in Residence https://alpha-omega.dev/blog/join-the-fight-building-a-team-of-open-source-security-engineers-in-residence/ . SEiR’s mission is to create a network of experienced security engineers who provide accessible security guidance, tooling, and documentation for open source maintainers and contributors. Leveraging open source tooling like Scrutineer https://github.com/alpha-omega-security/scrutineer and other sustainable security measures provides options that are lightweight on maintainer labor and offer actionable outcomes is a priority of the work. Offering respect to the time and brain drain of maintainers by performing security work on their behalf enables them to perform the critical work of upkeep on our digital infrastructure. Project V-LAT and Rapid Triage OSTIF is proud to be a part of the SEiR program with our own Project V-LAT. Project V-LAT, named after firefighting planes, aims to provide quick, mobile, and flexible triaging of identified vulnerabilities. The project currently consists of 6 security researchers 3 senior, 3 intermediate working full time to target edge cases and undersupported projects. Using custom skills and harnesses to capture a range of vulnerabilities across projects, OSTIF then verifies and triages entire project pipelines before disclosing and working with maintainers on practical fixes. Managing the Vulnerability Backlog As of the writing of this blog, there is a backlog of about 450 reported issues Project V-LAT is working on. Each issue is personally reviewed and confirmed as in or out of scope for each project, and any fixes submitted in the PR are reviewed and verified as well. Running a program like this allows OSTIF to work quickly and directly with maintainers, where capable hands take work off their plate, not add to it. Reports are submitted by security researchers, keeping the disclosure process between humans. As the queue of vulnerabilities grows, the jostling to get a vulnerability to the front of the line can result in maintainers turning off submissions or restricting who can submit. The SEiR program hopes to address this systemic rotting of maintainer’s time through providing sustainable security hardening and fixes for their entire backlog of verified issues. Scaling Security Across Ecosystems Frequently, we hear this kind of security work is exhausting and time consuming for maintainers also working on project development and upkeep. The SEiR work also funds engineers to help with the hardest parts of security maintenance. Currently engineers have been placed in the following programs: In addition to these embedded roles, Alpha-Omega also provided targeted funding to support critical security work within the Perl/CPAN https://alpha-omega.dev/blog/the-perl-and-raku-foundations-security-engineers-in-residence-april-task-force/ ecosystem and others not yet announced at this time. This work, and its funding, takes a village. Thanks to the efforts of many security engineers, organizations, projects, foundations, and maintainers is this work possible. Those not included in that list, and even those that are, can contribute to this effort. Help us, and so many others, in the work to secure open source faster than ever. Author Bio Helen Woeste joined OSTIF in 2023, coming from a decade of work experience in the restaurant and hospitality industries. With a passion and degree for writing and governance structures, Woeste quickly transitioned into an operations and communications role in technology.