<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://weblogs.asp.net/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Ravikanth's Blog  : OSS</title><link>http://weblogs.asp.net/dvravikanth/archive/tags/OSS/default.aspx</link><description>Tags: OSS</description><dc:language>en</dc:language><generator>CommunityServer 2007 SP1 (Build: 20510.895)</generator><item><title>Determine the security risk of using Open source projects</title><link>http://weblogs.asp.net/dvravikanth/archive/2008/11/11/determine-the-security-risk-of-using-open-source-projects.aspx</link><pubDate>Tue, 11 Nov 2008 08:04:00 GMT</pubDate><guid isPermaLink="false">c06e2b9d-981a-45b4-a55f-ab0d8bbfdc1c:6729100</guid><dc:creator>dvravikanth</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://weblogs.asp.net/dvravikanth/rsscomments.aspx?PostID=6729100</wfw:commentRss><comments>http://weblogs.asp.net/dvravikanth/archive/2008/11/11/determine-the-security-risk-of-using-open-source-projects.aspx#comments</comments><description>&lt;P mce_keep="true"&gt;Visit the &lt;A class="" title="Java open review" href="https://opensource.fortify.com/" target=_blank mce_href="https://opensource.fortify.com/"&gt;Java Open Review&lt;/A&gt;, an open source project sponsored by Fortify Software which uses Fortify SCA tools and Findbugs to look for defects in software – as a service. It publishes aggregated statistics but has a "responsible disclosure policy", which means details of bugs found are fed back only to the authors.&lt;/P&gt;
&lt;P mce_keep="true"&gt;The project on going basis analyses some common open source projects and other applications, including Hibernate, Struts, Spring, Apache frameworks and Tomcat then publishes list of defect free projects from quality &amp;amp; security perspective.&lt;/P&gt;
&lt;P mce_keep="true"&gt;Using Defect free project list, consumers can gauge the level of risk involved in different open source components.&lt;/P&gt;&lt;img src="http://weblogs.asp.net/aggbug.aspx?PostID=6729100" width="1" height="1"&gt;</description><category domain="http://weblogs.asp.net/dvravikanth/archive/tags/Application+Security/default.aspx">Application Security</category><category domain="http://weblogs.asp.net/dvravikanth/archive/tags/OSS/default.aspx">OSS</category><category domain="http://weblogs.asp.net/dvravikanth/archive/tags/Open+source+software+security+risk/default.aspx">Open source software security risk</category><category domain="http://weblogs.asp.net/dvravikanth/archive/tags/Application+Security+Risk+determination/default.aspx">Application Security Risk determination</category></item></channel></rss>