ABCDEFGHIJ
1
This is the proposed project list for the Open Source Technology Improvement Fund's 2021-2022 Managed Audit Program (MAP)
2
Projects are selected from a large number of criteria including Google's Criticality Score Project, the joint Census project with the Linux Foundation and Harvard University, and the Underproduction paper from the University of Washington. The larger list is then narrowed and prioritized. Links to sources below and in "Directory".
3
Funding StatusFunded ByProjectShort DescriptionSiteGithub / GitlabMaintaining OrganizationMonetizationLanguagesLicense
4
FundedGoogle Open Source Security TeamGitVersion Controlhttps://git-scm.com/https://github.com/git/git (mirror)Software Freedom ConservancyDonationC, ShellGPLv2
5
PendingGoogle Open Source Security TeamlodashJS utility libraryhttps://lodash.com/https://github.com/lodash/lodashNoneNoneJSMIT License
6
PendingOpen Source Security Foundation (OpenSSF)php symfonyPHP application frameworkhttps://symfony.com/https://github.com/symfony/symfonySensio LabsPHPMIT License
7
PendingPendingElectronCross-platform apps developmenthttps://www.electronjs.org/https://github.com/electron/electronOpenJS FoundationDonationC++, TypeScriptMIT License
8
PendingPendingsystemdSystem and Service Managerhttps://systemd.io/https://github.com/systemd/systemdNone (Red Hat Developers)NoneCGPLv2
9
PendingPendingrailsDatabase backed web application frameworkhttps://rubyonrails.org/https://github.com/rails/railsBasecamp / Shopify?RubyMIT License
10
FundedGoogle Open Source Security Teamjackson-coreJSON for Java, Streaming API + moreNonehttps://github.com/FasterXML/jackson-coreNoneDonation (TideLift)JavaApache-2.0
11
FundedGoogle Open Source Security Teamjackson-databindJSON for Java, Data binding packageNonehttps://github.com/FasterXML/jackson-databindNoneDonation (TideLift)JavaApache-2.0
12
FundedGoogle Open Source Security Teamhttpcomponents-coreCore components of Apache httpcomponentsNonehttps://github.com/apache/httpcomponents-clientApache FoundationDonationJavaApache-2.0
13
FundedGoogle Open Source Security Teamhttpcomponents-clientClient components of Apache httpcomponentsNonehttps://github.com/apache/httpcomponents-coreApache FoundationDonationJavaApache-2.0
14
FundedGoogle Open Source Security TeamlaravelPHP Web App Frameworkhttps://laravel.com/https://github.com/laravel/laravelNoneDonationPHP, BladeMIT License
15
FundedGoogle Open Source Security Teamslf4jLogging Facade for Javahttp://www.slf4j.org/https://github.com/qos-ch/slf4jNoneEnterprise Support ModelJava, HTMLMIT License
16
PendingPendinglogback-coreLogging framework for Javahttp://logback.qos.ch/https://github.com/qos-ch/logbackNoneEnterprise Support ModelJava, HTMLGPLv2.1, Eclipse PL
17
PendingPendingdrupalContent Management Systemhttps://www.drupal.org/homehttps://git.drupalcode.org/project/drupalDrupal.orgReferral / NonePHP, JSGPLv2, GPLv3
18
PendingPendingjoomlaContent Management Systemhttps://www.joomla.org/https://github.com/joomla/joomla-cmsJoomla FoundationDonation / ReferralPHP, JSGPLv3, LGPL
19
PendingPendingwebpackMulti-language Asset Bundlerhttps://webpack.js.org/https://github.com/webpack/webpackOpenJS FoundationJavaScript
20
PendingPendingrepreproPackage Manager RepoNonehttps://salsa.debian.org/brlink/repreproNoneNoneCGPLv2
21
PendingPendingcephobject, block and file storage platformhttps://ceph.io/https://github.com/ceph/cephLinux Foundation (ceph foundation)MembershipC++, PythonLGPL2.1, LGPL3
22
PendingPendingreact nativeFramework for Mobile App Developmenthttps://reactnative.dev/https://github.com/facebook/react-nativeFacebookCorporate SupportJS, Java, C++, MoreMIT License
23
PendingPendingsalt (saltstack)IT Automation Platformhttps://docs.saltproject.io/en/latest/https://github.com/saltstack/saltVMWareCorporate SupportPythonApache-2.0
24
PendingPendinggatsbyFast React Frameworkhttps://www.gatsbyjs.com/https://github.com/gatsbyjs/gatsbygatsbyjs.comSAASJS, TypeScriptMIT License
25
PendingPendingangularApplication Frameworkhttps://angular.io/https://github.com/angular/angularGoogleCorporate SupportTypeScript, JSMIT License
26
PendingPendingansibleIT Automation Platformhttps://www.ansible.com/https://github.com/ansible/ansibleRed HatCorporate SupportPython, PowershellGPLv3
27
PendingPendingguavaJava Framework
https://opensource.google/projects/guava
https://github.com/google/guavaGoogleCorporate SupportJavaApache-2.0
28
PendingPendingnode.jsJavascript Runtime Environmenthttps://nodejs.org/en/https://github.com/nodejs/nodeOpenJS FoundationNoneJS, C++, PythonMIT License
29
30
Google's Criticality Score Project - https://docs.google.com/spreadsheets/d/1uahUIUa82J6WetAqtxCM_qgH-YJOagH84AFniIhlAbg
31
Linux Foundation and Harvard's Census II Project - https://www.coreinfrastructure.org/wp-content/uploads/sites/6/2020/02/census_ii_vulnerabilities_in_the_core.pdf
32
University of Washington Underproduction Paper - https://arxiv.org/pdf/2103.00352.pdf
33
Link to detailed proposal regarding the Managed Audit Program:
34
https://docs.google.com/document/d/1yNybIZxKq_V0In3pvOCD6mrttRBrslIeMURXP8bcDyo/edit
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100