Call for Tenders: Sovereign Tech Resilience Program

The Impact of Resilience In September 2022, the German Parliament allocated funds in its federal budget for a bug bounty program — marking the starting point of the initiative.Building on feedback from security experts, FOSS infrastructure projects, and established best practices, the Sovereign Tech Agency went on to design and launch a holistic, preventive approach aimed at strengthening the resilience of FOSS projects against potential vulnerabilities in 2023. Several critical open source components, including systemd, Log4j, and Sequoia PGP, have benefited from these different services simultaneously.Through a partnership with the Open Source Technology Improvement Fund (OSTIF), the Sovereign Tech Resilience Program has funded security audits of projects including Ruby on Rails, conda-forge, zlib, cURL, and LLVM, delivering expert code reviews. Through a partnership with Neighbourhoodie Software, the program has delivered hands-on engineering to projects like systemd, where over 10,000 lines of new test code increased function coverage, and Yocto, where the team triaged 221 CVEs dating back to 1998.On the bug and fix bounty side, six programs are active on YesWeHack, a leading Bug Bounty & Vulnerability management platform, covering projects from GNOME to Apache Log4j. That includes 3 vulnerabilities with a critical severity CVSS rating, and 19 high severity ones.Through this holistic combination of preventative and responsive measures, the Sovereign Tech Resilience Program creates meaningfully better conditions for discovering, fixing, and preventing severe vulnerabilities in digital infrastructure. Supporting projects in transitioning towards memory-safe practices is a high-leverage investment in long-term resilience and is a step towards eradicating this class of vulnerabilities, allowing maintainers to focus their efforts on other maintenance tasks.Post-quantum encryption readiness Our digital world relies on encryption to secure everything from online banking and medical records to software updates and communications. Open source cryptographic libraries sit at the foundation of this infrastructure and critical digital infrastructure projects need support to begin this migration now.Compliance with the Cyber Resilience Act (CRA) responds to the new regulatory reality facing open source software in Europe.

This article was collected and archived by Digital Sovereignty Watch from an institutional or public source relevant to digital sovereignty, technology policy, cybersecurity, cloud services, artificial intelligence or European regulation.

Read original source