[ 
https://issues.apache.org/jira/browse/WW-5291?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17697264#comment-17697264
 ] 

Lukasz Lenart commented on WW-5291:
-----------------------------------

[~schaich] thanks for preparing the initial setup. As far I understand, I 
should prepare a PR with assigning a reviewer to the project, I should add the 
email here [1]

[1] 
https://github.com/google/oss-fuzz/blob/master/projects/struts/project.yaml#L7

correct?

> Integrating struts2 into oss-fuzz
> ---------------------------------
>
>                 Key: WW-5291
>                 URL: https://issues.apache.org/jira/browse/WW-5291
>             Project: Struts 2
>          Issue Type: Improvement
>            Reporter: A. Schaich
>            Priority: Minor
>
> Hi all,
> we have prepared the [Initial 
> Integration|https://github.com/google/oss-fuzz/pull/9852] of struts2 into 
> [Google OSS-Fuzz|https://github.com/google/oss-fuzz] which will provide more 
> security for your project.
>  
> *Why do you need Fuzzing?*
> The Code Intelligence JVM fuzzer 
> [Jazzer|https://github.com/CodeIntelligenceTesting/jazzer] has already found 
> [hundreds of bugs|https://github.com/CodeIntelligenceTesting/jazzer#findings] 
> in open source projects including for example 
> [OpenJDK|https://nvd.nist.gov/vuln/detail/CVE-2022-21360], 
> [Protobuf|https://nvd.nist.gov/vuln/detail/CVE-2021-22569] or 
> [jsoup|https://github.com/jhy/jsoup/security/advisories/GHSA-m72m-mhq2-9p6c]. 
> Fuzzing proved to be very effective having no false positives. It provides a 
> crashing input which helps you to reproduce and debug any finding easily. The 
> integration of your project into the OSS-Fuzz platform will enable continuous 
> fuzzing of your project by 
> [Jazzer|https://github.com/CodeIntelligenceTesting/jazzer].
>  
> *What do you need to do?*
> The integration requires the maintainer or one established project commiter 
> to deal with the bug reports.
> You need to create or provide one email address that is associated with a 
> google account as per 
> [here|https://google.github.io/oss-fuzz/getting-started/accepting-new-projects/].
>  When a bug is found, you will receive an email that will provide you with 
> access to ClusterFuzz, crash reports, code coverage reports and fuzzer 
> statistics. More than 1 person can be included.
>  
> *How Code Intelligence can support?*
> We will continue to add more fuzz targets to improve code coverage over time. 
> Furthermore, we are permanently enhancing fuzzing technologies by developing 
> new fuzzers and more bug detectors.
>  
> Please let me know if you have any questions regarding fuzzing or the 
> OSS-Fuzz integration.



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to