This proposal has been approved and the Eclipse Steady project has been created.
Visit the project page for the latest information and development.

Eclipse Steady

Thursday, July 4, 2019 - 06:21 by Henrik Plate
This proposal is in the Project Proposal Phase (as defined in the Eclipse Development Process) and is written to declare its intent and scope. We solicit additional participation and input from the community. Please login and add your feedback in the comments section.
Project
Parent Project
Proposal State
Created
Background

The project addresses the OWASP Top 10 security risk A9, Using Components with Known Vulnerabilities, which is often the root cause of data breaches. It supports software development organizations in regards to the secure use of open-source components during application development.

Scope

Eclipse Steady analyses Java and Python applications to identify, assess and mitigate the use of open-source dependencies with known vulnerabilities.

Description

Analyses your Java and Python applications for open-source dependencies with known vulnerabilities, collects evidence regarding the execution of vulnerable code in a given application context (through the combination of static and dynamic analysis techniques), and supports developers in the mitigation of such dependencies.

Why Here?

The Eclipse Foundation hosts a significant number of Java projects, which makes it a natural fit for the Java-focussed project at hand.

Future Work

Functionalities:

  • Authentication and authorization checks
  • Support of Node.js
  • UI redesign

Communication/dissemination:

  • Several meetings are scheduled with commercial development organizations
  • Several presentations are scheduled (or proposed) at developer and open source events, e.g., Heise devSec(), LinuxFoundation Open Source Summit, EclipseCon

 

Project Leads
Committers
Henrik Plate (This committer does not have an Eclipse Account)
Interested Parties

University of Trento, Sogeti, University of Paderborn

Initial Contribution

The large majority of copyrights are hold by SAP, whose employees develop the tool until today.

Few contributions exist from the University of Paderborn, their contributions were managed using the https://cla-assistant.io/.

 

 

Source Repository Type

Great project and tool. The world need such tools !!!

Working as System Security Manager for many years at ADTRAN Inc. also responsible for Vulnerabilty Monitoring in our development. Such tool for java and python is great. Especially for Java with the many classes the monitoring is the best inside a develper tools at the source. 

Best regards

Tobias