Open-source security

Security review of the open-source code you depend on and the projects you run, from dependencies to release pipelines, plus help disclosing what you find.

We check the code you didn’t write, and the pipeline that ships the code you did.

What we test

Out of scope stays out. We ask first.

  • Dependencies

    Known vulnerabilities, abandoned packages, risky install scripts and look-alike names.

  • Supply chain

    Lockfiles, registries, pinning, and where a package could be swapped on the way to you.

  • Build and release

    CI workflows, secrets, token permissions, signing and provenance.

  • Project code

    Parsers, authentication, crypto and anything that touches untrusted input.

  • Repository settings

    Branch protection, maintainer access, deploy keys and tokens.

  • Disclosure

    A security policy, a private reporting channel and an advisory workflow.

How we test

  1. Inventory

    Everything you depend on, directly and through other packages.

  2. Automated review

    Semgrep and CodeQL on the code, advisory databases on the dependencies.

  3. Pipeline review

    CI workflows checked for untrusted input, broad tokens and unpinned actions.

  4. Manual review

    Code that touches untrusted input, read line by line.

  5. Disclosure help

    Bug in someone else’s project? We help you report it privately, coordinate the fix and request a CVE where it fits.

  6. Report and retest

    A prioritised plan, then a free retest.

A report your engineers can act on

  • A dependency inventory with the risky packages flagged.
  • Severity, evidence and a fix for every finding.
  • Concrete changes for your CI and release settings.
  • A security policy and advisory workflow for your repository, if you want one.
  • Draft disclosure reports for upstream maintainers, when a finding is theirs.

How a finding reads

V-051ExampleSeverity: High

CI runs pull request code with a write token

Weakness
CWE-829
Where
Release workflow in the project’s CI
Impact
An outside contributor could run code with permission to push to the repository.
Fix
Run untrusted pull requests without secrets, cut token permissions to read-only, and pin third-party actions.
Fixed · retested

Standards and tools

Findings mapped to
  • OWASP ASVS
  • NIST SP 800-115
Tools we use
  • Semgrep
  • CodeQL
We maintain an open-source project. Can you review it?

Yes. The code that matters most, the CI and release pipeline, and the repo settings. Then we help you set up private reporting.

How does disclosure to another project work?

We report privately to the maintainers, agree a deadline (often 90 days), help test the fix, and publish only once a fix ships or the deadline passes.

Will you publish what you find in our code?

No. Your findings are yours. Nothing is published without your written agreement.

What do you need from us?

Read access to the repositories and CI in scope, a list of what you ship and how, and a maintainer who can answer questions.

Tell us about your project

Send the scope and your deadline, and we’ll set up a call.