tech

Patch the Planet: a Daybreak initiative to support open source maintainers

We are introducing Patch the Planet, a Daybreak initiative built with Trail of Bits to help maintainers strengthen the critical open-source software the world relies on. We’re pairing AI-assisted security research using our most cyber-capable models with expert human review to not only identify vulnerabilities, but help patch them.

Patch the Planet: a Daybreak initiative to support open source maintainers

TL;DR

  • Patch the Planet is a Daybreak initiative, partnered with Trail of Bits, to enhance open-source software security.
  • It combines AI-driven vulnerability discovery with expert human review to identify and patch security issues.
  • The initiative aims to support maintainers by reducing their workload related to security reports and patches.
  • Trail of Bits provides dedicated security engineers and AI models for research, patch development, and testing.
  • Partnerships with HackerOne and Calif enhance vulnerability triage and coordinated disclosure.
  • Initial projects benefiting from Patch the Planet include cURL, NATS Server, pyca/cryptography, Sigstore, aiohttp, the Go project, freenginx, Python, and python.org.
  • AI-assisted workflows have been developed for tasks like fuzzing, historical CVE analysis, and differential testing, significantly reducing the time required for these processes.
  • The program has already identified hundreds of security issues and merged dozens of patches in its initial phase.
  • Specific examples of AI's impact include rapid development of fuzzing labs, a pipeline for finding vulnerability variants, and accelerated differential testing.
  • The initiative also focuses on testing software against specifications, developing threat models, and improving CI/CD and supply chain security.
  • Security engineers manually review all findings before they reach maintainers to filter out false positives and prioritize confirmed issues.
  • Maintainers retain control over patch deployment and disclosure.
  • Early highlights include identifying vulnerabilities in Linux Kernel, OpenBSD, FreeBSD, dnsmasq, HTTP/2 implementations, Chrome, Safari, and Firefox.
  • The initiative plans to publish deeper technical reports as more disclosures conclude.
  • Maintainers interested in participating can apply to join Patch the Planet.