google / oss-fuzz

OSS-Fuzz - continuous fuzzing for open source software.
https://google.github.io/oss-fuzz
Apache License 2.0
10.13k stars 2.15k forks source link

Add Gavin Howard's bc/dc as bc-gh #12078

Closed gavinhoward closed 2 weeks ago

gavinhoward commented 2 weeks ago

The FAQ says that projects can be accepted if they "have a critical impact on infrastructure and user security," with the following two explicit criteria:

This bc/dc is locked down, and the exposure to remote attacks should be extremely low. So I understand if this project is not accepted.

However, it is shipped by default in Android, FreeBSD, and macOS, so it is critical to other projects that are used widely.

It is already set up for fuzzing, but as a single maintainer, I do not have the resources to fuzz it all of the time and ask for Google's help since Google ships this bc/dc in Android.

google-cla[bot] commented 2 weeks ago

Thanks for your pull request! It looks like this may be your first contribution to a Google open source project. Before we can look at your pull request, you'll need to sign a Contributor License Agreement (CLA).

View this failed invocation of the CLA check for more information.

For the most up to date status, view the checks section at the bottom of the pull request.

github-actions[bot] commented 2 weeks ago

gavinhoward is integrating a new project:
- Main repo: https://github.com/gavinhoward/bc
- Criticality score: 0.54528

jonathanmetzman commented 2 weeks ago

We accept this project. Make sure to apply for the integration rewards once youve completed this work. I won't say it will be a lot, but it might be nice support.