ossf / alpha-omega

Our mission is to catalyze sustainable improvements to critical open source software projects and ecosystems.
https://alpha-omega.dev
Apache License 2.0
79 stars 49 forks source link

GRANT RECIPIENTS: Unclear description for OpenSSL #350

Open Chealer opened 5 months ago

Chealer commented 5 months ago

The entry for OpenSSL in the Alpha grant recipients for 2023 reads:

OpenSSL is a globally distributed cryptography library touching nearly every industry in the world.

In 2023 OpenSSL was granted $127,000 for the purpose of assessments that will be performed by teams of Trail of Bits security consultants for a total of eight engineer-weeks of effort. The secure code review, including fuzzing enhancements, will be performed over a four calendar-week period, for a total of eight engineer-weeks.

This is largely unclear. In particular, please clarify:

  1. What does "globally distributed" mean?
  2. What type of dollars does "$" designate?
  3. What will the scope be? Is it a review (assessments), or does it actually include enhancements?