OWASP OASIS Launches as Official OWASP Community Project to Fight Open Source Vulnerabilities with AI and Human Expertise

On August 26, 2026, the OWASP Open Automated Security Initiative for Software (OASIS) launched as an official OWASP community project. This global initiative combines AI-powered fix automation with human expert validation to remediate open source vulnerabilities at scale. OASIS addresses the critical bottleneck of remediation by generating candidate fixes through automated pipelines, having AppSec professionals validate them for correctness and safety, and then submitting vetted patches to open source maintainers. The project has attracted hundreds of security professionals and founding sponsors AppSecAI, Intigriti, and DryRun Security. Designed to complement other industry initiatives like OpenAI's Patch the Planet and the Linux Foundation's Akrites, OASIS offers a vendor-neutral, community-driven approach that empowers application security professionals to collectively defend against AI-driven exploits and "vibe hacking" threats. The initiative invites participants to contribute as vulnerability validators, community managers, maintainer liaisons, or automation operators. 

https://www.owasp-oasis.org/news/launch

Comments

Popular posts from this blog

Prompt Engineering Demands Rigorous Evaluation

OWASP ASVS 5.0 Released - Key Updates and What You Need to Know

Open-SPDD proposes an open framework for Spec-Driven Development workflows