Skip to main content

Meeting Notes

OpenSSF Cyber Reasoning Systems Special Interest Group

2026-07-13


Agenda

After running a bug-finding campaign both inside and outside of OSS-CRS, I would like to share some thoughts.


OSS-CRS Deployment Workflow

h:500


Agentic Bug-Finding

For security researchers, they tend to look for a particular bug across multiple projects.

h:440


Agentic Bug-Finding

Internally, the agent searches for code that looks buggy (according to vulnerable patterns), then tries to create a proof-of-concept to prove the vulnerability.

h:440


Gaps for OSS-CRS

Compared to running an agent that checks out many projects searching for domain specific bugs, OSS-CRS lacks:

  • cross-project knowledge
  • resumable context and campaigns
  • automatic target selection

Proposal: Rich Bug-Candidate Interface

GH Issue 310

h:520


Proposal: Rich Bug-Candidate Interface

h:560


h:560


OSS-CRS: Report Generation

h:520


OSS-CRS: Report Generation Workflow

h:520


OSS-CRS: Report Generation Artifacts

h:520


OSS-CRS: Report Generation Artifacts

Open question on whether it's in scope of OSS-CRS.

h:520


Q&A / Discussion

Refer to Cyber Reasoning Systems bi-weekly meeting notes.