Skip to content

project

Akrites

Linux Foundation and OpenSSF coalition launched at the end of June 2026 to coordinate AI-enabled vulnerability reports to upstream open-source maintainers, operating a shared SIRT and a standardized coordinated disclosure process.

Known aliases

  • Akrites initiative

Relationships

No evidence-backed relationships are recorded.

Current stories

security1 publisherOne report

Chainguard discloses 14 Java bugs that were fixed upstream but never got a CVE

Chainguard disclosed 14 Java vulnerabilities that were fixed upstream but never assigned a CVE, one rated critical and one high. Teams still on the affected versions got no scanner alert, some for years, because nobody announced the fixes when they landed at HEAD.

Publishers:chainguard.dev

Reality

Evidence40
Adoption25
Hype gap+10
Incentives75
Confidence45