Hello OpenSSF security-reviews maintainers/community,
I maintain Rava, a draft Rust reference implementation for action-native agent authorization, and I am looking for zero-budget FOSS/community security review or guidance on the right place to request it.
Repository: https://github.com/syndicalt/rava\nTracking issue: https://github.com/syndicalt/rava/issues/87\n\nFrozen review target:
- Tag:
v0-review-candidate-2026-05-18-r4
- Commit:
b1b65fb6263b4f9143bdac8a5b46fbce6fdc532d
Please start with these review-packet artifacts:
Requested review focus: whether the V0 draft fails closed for attacker-controlled protocol inputs, and whether the documentation clearly separates implemented guarantees from caller assumptions, production requirements, and non-goals.
Useful findings should include severity, affected boundary, reproduction or exploit story, affected files/modules/docs, remediation recommendation, and verification note. Please do not post undisclosed third-party vulnerabilities here. If this repository is not the right place to ask for community review, I would appreciate a pointer to the appropriate OpenSSF channel.
Important boundary: Rava V0 is not production-ready security software. This request is not an audit claim, certification claim, reviewer approval claim, or production-readiness claim.
Hello OpenSSF security-reviews maintainers/community,
I maintain Rava, a draft Rust reference implementation for action-native agent authorization, and I am looking for zero-budget FOSS/community security review or guidance on the right place to request it.
Repository: https://github.com/syndicalt/rava\nTracking issue: https://github.com/syndicalt/rava/issues/87\n\nFrozen review target:
v0-review-candidate-2026-05-18-r4b1b65fb6263b4f9143bdac8a5b46fbce6fdc532dPlease start with these review-packet artifacts:
Requested review focus: whether the V0 draft fails closed for attacker-controlled protocol inputs, and whether the documentation clearly separates implemented guarantees from caller assumptions, production requirements, and non-goals.
Useful findings should include severity, affected boundary, reproduction or exploit story, affected files/modules/docs, remediation recommendation, and verification note. Please do not post undisclosed third-party vulnerabilities here. If this repository is not the right place to ask for community review, I would appreciate a pointer to the appropriate OpenSSF channel.
Important boundary: Rava V0 is not production-ready security software. This request is not an audit claim, certification claim, reviewer approval claim, or production-readiness claim.