started · updated
OWASP launches OASIS to automate open-source vulnerability patching
OWASP has launched the Open Automated Security Initiative for Software (OASIS), a global community effort designed to bridge the gap between discovering open-source vulnerabilities and implementing fixes. Announced on August 26, 2026, in San Francisco, the initiative aims to move beyond simple vulnerability reporting toward a “find, validate and fix” workflow.
OASIS utilizes a three-stage process to address the security bottleneck facing open-source maintainers. First, automated tools scan repositories to generate candidate fixes using AI. Second, a community of application security (AppSec) professionals and agents reviews these candidates for safety and correctness. Finally, the vetted patches are submitted upstream to maintainers.
This initiative targets the massive scale of open-source software, which supports approximately 98% of commercial codebases. By providing ready-to-use patches rather than just lists of flaws, OASIS seeks to reduce the systemic risk posed by unremediated vulnerabilities. The project is supported by founding sponsors AppSecAI, Intigriti, and DryRun Security, and has already attracted hundreds of security professionals.