
Sovereign Tech Resilience takes a preventative approach to vulnerabilities in critical open digital infrastructure. The application on this page is for FOSS projects seeking participation in a program that combines direct technical contributions, bug and fix bounties, and security code audits; individual vulnerability research takes place through the linked YesWeHack bounty programs.
Neighbourhoodie Software contributes directly to participating projects to address known issues, improve documentation, and reduce technical debt. This work is intended to make software easier to maintain, reduce opportunities for vulnerabilities, and improve the quality of external contributions.
YesWeHack provides selected FOSS projects with access to security researchers and supports the triage and verification of submitted vulnerability reports. Participating bounty programs include:
Through the Open Source Technology Improvement Fund, the Sovereign Tech Agency provides security reviews for widely used software components. The reviews are intended to identify high-impact and high-risk vulnerabilities, improve testing and code coverage, and help maintainers address issues before exploitation.
Participating projects listed by the program include cURL, Jackson, and LLVM.
Mention ETHStars when you apply. It shows the hiring team you’re connected to the Ethereum ecosystem.