Skip to content

Conversation

@GeauxJD
Copy link
Contributor

@GeauxJD GeauxJD commented Jan 5, 2026

OSS-CRS (Open Source Software Cyber Reasoning System) provides a standardized infrastructure for building, running, and evaluating Cyber Reasoning Systems (CRS) that perform automated vulnerability discovery and remediation in open source software.

Features include:

  • Unified CLI interface (oss-bugfind-crs / oss-patch-crs run) for any CRS implementation
  • Docker Compose-based orchestration for reproducible multi-container deployments
  • Resource management with configurable CPU, memory, and LLM budget allocation
  • LiteLLM integration for standardized LLM access across different CRS implementations
  • OSS-Fuzz compatibility to leverage Google's existing fuzzing infrastructure
  • Ensemble support for combining multiple CRS approaches

Signed-off-by: Jeff Diecks <55294502+GeauxJD@users.noreply.github.com>
@GeauxJD GeauxJD requested a review from a team as a code owner January 5, 2026 17:12
@mihaimaruseac
Copy link
Contributor

Looking forward to seeing this accepted as a sandbox application

Copy link
Contributor

@marcelamelara marcelamelara left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I'm supportive of OSS-CRS joining as a sandbox project! Very excited to see how this project continues to grow.

- **Resource management**: YAML-based configuration for CPU cores, memory limits, LLM budgets
- **LiteLLM integration**: Automated proxy deployment for LLM access control

### Roadmap
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Not a blocker, but I think it'd be helpful to get a sense for when the project plans to start/complete these different roadmap milestones.

Copy link
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The group presented an update on the roadmap in the most recent Cyber Reasoning Systems SIG meeting. Slides are here https://docs.google.com/presentation/d/1R9XAF6VOVimdlXL346CnNrMkOzJFVyFhJF9lrYtHnZI/edit?slide=id.g3b67cb90a0c_0_0#slide=id.g3b67cb90a0c_0_0

@marcelamelara marcelamelara added the Major / New TI Changes to Charter/Technical Strategy/TI Lifecycle process, new TI. Needs 7 approvals, 15d review. label Jan 15, 2026
Copy link
Member

@steiza steiza left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks! Minor question about one of the links.

Copy link
Contributor

@gkunz gkunz left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Very supportive of this.

Comment on lines +3 to +16
## List of project maintainers (alphabetic order)

* Andrew Chin, Georgia Institute of Technology, @azchin
* Cen Zhang, Georgia Institute of Technology, @occia
* Dongkwan Kim, Georgia Institute of Technology, @0xdkay
* Fabian Fleischer, Georgia Institute of Technology, @fab1ano
* Hanqing Zhao, Georgia Institute of Technology, @hq1995
* Jiho Kim, Georgia Institute of Technology, @jhkimx2
* Taesoo Kim, Georgia Institute of Technology & Microsoft, @tsgates
* Younggi Park, Independent Researcher, @grill66
* Youngjoon Kim, Georgia Institute of Technology, @acorn421
* Yu-Fu Fu, Georgia Institute of Technology, @fuyu0425

Note: Maintainers may be updated in the future (some can become inactive or other AIxCC team members may join).
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Our criteria is: "Projects must have a minimum of three maintainers with a minimum of two different organization affiliations." This really looks borderline...

Copy link
Contributor

@lehors lehors left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I'm concerned that about all of the maintainers seem to be students who will likely move on to other projects and leave this unattended.

@bobcallaway
Copy link
Contributor

I'm concerned that about all of the maintainers seem to be students who will likely move on to other projects and leave this unattended.

+1, but I think given the convergence strategy discussed at the TAC meeting it seems like we will likely be archiving some of them and maintainers swarm onto one/two approaches?

Copy link
Contributor

@lehors lehors left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I approve based on the stated expectation (communicated on the TAC call) that maintainers from other organizations are planning to join the project.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Major / New TI Changes to Charter/Technical Strategy/TI Lifecycle process, new TI. Needs 7 approvals, 15d review.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

8 participants