Fetching the latest programs, projects, and workspace data.
Find open source projects actively accepting contributors. Search repositories, filter by program milestones, difficulty tags, or tech stack.
Use our Orbit AI Matcher to find out! Get instant matching scores based on your developer skills, preferred frameworks, and contribution experience.
Convert your selected open-source project into a winning GSoC, LFX, or Outreachy application using Proposal Studio.
This project addresses the challenge of distinguishing meaningful security knowledge from noisy or irrelevant changes in OWASP repositories. Currently, large volumes of repository updates include formatting changes, test files, and administrative edits, which dilute the quality of extracted knowledge and reduce the efficiency of downstream systems. To solve this, I propose building a two-stage intelligent filtering pipeline within the OpenCRE Scraper & Indexer framework. The first stage uses regex-based rule filtering to eliminate obvious noise (e.g., non-informative files and structural changes), ensuring low-cost, high-speed preprocessing. The second stage applies LLM-based semantic classification (via models like GPT-4o-mini or Gemini Flash) to determine whether a change introduces genuine security knowledge, such as new vulnerabilities, attack techniques, or mitigation strategies. This hybrid approach balances efficiency with deep contextual understanding. The system will be integrated into the OpenCRE pipeline, forwarding only relevant outputs into a knowledge queue for further processing. It will include structured logging, prompt optimization, cost-efficient API usage, and robust evaluation based on precision, recall, and accuracy. Deliverables include: 1. A production-ready two-stage filtering pipeline (regex + LLM) 2. Integration with the OpenCRE knowledge ingestion workflow 3. A labeled evaluation dataset and performance benchmarks (targeting high accuracy and recall) 4. Unit-tested, scalable, and well-documented codebase 5. Detailed documentation on prompt engineering, system design, and evaluation methodology This project will significantly improve the quality, reliability, and scalability of security knowledge extraction, enabling the OWASP community to focus on high-value insights while reducing noise in the ecosystem.
1. Adding Filters in the Matrix View: Updating the YAML file, and adding the tags title in task-description. After this, adding chip style filter system in the matrix view, that'll encompass the list of activities visible in the matrix view. 2. Adding Team-Based Assessment: Creating a node server that'll save the activity data of multiple teams on the local system. Adding a team selection menu, and creating an updated view of the team-based heatmap. 3. Comprehensive Activity View: Alongside the heatmap, details of activities need to be shown. This will be achieved by creating an overlay screen on the heatmap which can be opened on the selection of activity. This will display the activity detail from generated.yaml file. 4. Enhancement of Diagram in Documentation: Flow charts and a detailed summary of the project will be updated on the Usage page.
<p>Audio, video or data packets transmitted over a peer-connection can be lost, and experience varying amounts of network delay. Therefore, a web application like Jangouts, implementing WebRTC expects to monitor the performance of the underlying network and media pipeline. As a solution to this problem, I propose to integrate callstats.io into Jangouts. callstats.io is a SaaS service that helps WebRTC services detect and diagnose media and network quality issues. This project aims to give an option to companies and individuals deploying Jangouts to use this service in a user-friendly way. This task can be completed by sending WebRTC events and measurement data from the Jangouts application and the Janus media server in real-time to callstats.io. The idea is to integrate the callstats.io REST API with the WebRTC components in Jangouts and Janus. The Jangouts app will send endpoint stats and Janus will send the stats related to the WebRTC gateway.</p>
<p>1) Making an image for Raspberry Pi that could be flashed on a sd card that could automatically start a sugarizer server at boot and displays sugarizer client on the Pi. 2) Create one click deploy scripts, to deploy a full Sugarizer stack on popular providers such as Amazon AWS or Heroku.</p>
The Joplin desktop app currently uses native built-in PDF renderer of electron to display PDF attachments, this has multiple limitations like lack of ability to link to a specific page number, loss of scroll position state on re-rendering, annotations etc, not to mention the built-in renderer’s UI does not match with rest of the Joplin app. The aim of this project is to replace the built-in PDF renderer with a new 3rd party library and add multiple new pdf related features and improvements to the app.
The aim is to shift omegaUp from reactive to proactive operations by building a complete monitoring and alerting system across the PHP frontend, Go services, MySQL, and Kubernetes. The project will add missing instrumentation (latency histograms, business context attributes, backend tracing), pipe Prometheus metrics into New Relic for unified alerting, and build Grafana dashboards with recording rules and longer retention. It will then define alerting policies, SLI/SLO targets, and runbooks, delivering actionable notifications and a clear operational view during contests without changing user‑facing behaviour.
<p>To create an open, community-powered Book Genome Project which enables deeper, faster and more holistic understanding of a book's unique characteristics.</p>
Radio-Browser is a community-driven database that provides as many internet radio and TV stations as possible for end-users to quickly lookup. Per https://www.radio-browser.info/users, there are plenty of apps using these API services. By implementing this project into the VLC player, users can easily find and listen to online radio on the VLC player. Inspired by https://wiki.videolan.org/SoC_2024/#Radio-Browser_integation.
FinBot CTF has no defensive layer, players can exploit agentic AI vulnerabilities but can't learn to stop them. This project fixes that gap. I'll build a GuardrailEngine that intercepts agent actions before execution, convert 4 existing challenges into paired red/blue scenarios with OWASP Agentic Top 10 and MITRE ATLAS mappings, and develop a stateful MaliciousToolServer that simulates real supply-chain attacks. Deliverables: GuardrailEngine with 4 built-in policies, defense-enabled scenarios for Puppet Master, Invoice Trust Override, Fine Print, and RCE via SystemUtils, two new supply-chain challenges (Shadow Protocol + Trojan Invoice), and full CI/CD with contributor documentation. The result is a complete attack-and-defend environment, the only hands-on platform purpose-built for agentic AI security.
<p>Knative eventing is a system that is designed to address a common need for cloud-native development and provides composable primitives to enable late-binding event sources and event consumers.</p> <p>The project aims to implement the control-plane and the data-plane of core components of Knative Eventing: Brokers and Triggers.</p> <p>The control-plane is composed of reconciliation loops interacting with the Kubernetes API for scheduling data-plane components.</p> <p>The data-plane leverages Apache Kafka for delivering events following the cloudevents specification to enhance interoperability between systems.</p>
<p>This project aims to build an algorithm flow visualizer, with the following features in focus</p> <ul> <li>Flow control Visualisation, less of a focus on variables.</li> <li>Focus on visualizing the recursion stack.</li> <li>Step by step output.</li> <li>Interactive web version (or just an output format)</li> <li>Visualisation of data structures like trees.</li> <li>A Runtime based Flow Chart </li> <li>Choosing variables to debug separately.</li> </ul>
Most Joplin users are researchers or workers in different fields. It's usually the university or company dealing with them via email, whether it's assignments, essays, or reports, so I built a plugin to add the ability to fetch email messages (including attachments) and convert them to Joplin notes in various formats, either by monitoring any new or unread messages from a specific email address or a specific mailbox by using IMAP or by uploading downloaded email messages to the plugin without having to be logged in.
<p>Develop a service(set of classes within the project) for searching and sorting to output advanced nested results by prioritising tags and power tags which fulfils the general search requirement of the users and detailed analysed searching of admins and directors in the system.</p>
Build an interactive 3D WebGL orbital transfer trajectory tool for computing Hohmann and bi-elliptic transfer orbit energy profiles.
This proposal focuses on automating the generation of print-ready PDFs for OWASP Cornucopia by replacing the current InDesign-dependent workflow with a fully open-source, Scribus-based pipeline. It introduces a Python converter that reuses the existing YAML parsing logic to populate Scribus .sla templates, followed by automated PDF/X-1a:2001 export using Scribus in headless mode. The solution integrates seamlessly into the existing CI/CD pipeline, enabling every release to automatically produce print-ready outputs alongside current artifacts. By removing manual steps and proprietary dependencies, this approach makes the process more reliable, reproducible, and accessible, while also laying the foundation for future enhancements like customization and vendor-specific outputs.
<p>The objective is to build a web-based Honeypot project by identifying the emerging attacks against web applications and report them to the community, in order to facilitate protection against targeted attacks. With the help of ModSecurity, we lay HoneyTraps by adding more network ports that will accept HTTP request traffic.</p>
<p>Due to the release of PHP 7+, which lead to some PHP functions/code being deprecated, there is a need to ensure that all web applications that are running on older versions of PHP are compatible with the latest version of PHP, AChecker is a web accessibility checker that runs on PHP 5+, in other to make it compatible with more recent version of PHP, there is a need for an upgrade, and also upgrading and modifying some of the libraries used by AChecker, The aim of this project is to upgrade AChecker and it various libraries to be compatible with PHP 7.0 .</p>
<p>OpenLibrary.org is the world’s best-kept library secret: Let’s make it easier for book lovers to discover and get started with Open Library.</p>
<p>The proposed tool aims to collect, process, and analyze data from various Bug Tracking Systems. The outcomes by this processed data are easily readable reports in various formats, like PDF, DOC, and CSV files, that contain release notes and issue trackers based on detected bugs. The platform can generate these reports automatically, on-demand by the actor, or even when an event is triggered and detected by the platform.</p>
Navigating archived pages on the Wayback Machine requires significant manual effort. This project builds an experimental Chrome extension that uses Chrome's built-in Prompt API with Gemini Nano to automatically summarize archived pages and detect broken or soft-404 captures, all processed locally on the user's device for privacy. Deliverables include a working MV3 extension with page summarization, two-layer soft-404 detection using DOM signals and the CDX API, a lightweight overlay UI, and a public evaluation report.
<p>I've been using different technologies over the past few years such as PHP (Laravel), Nodejs, VueJS, React, and React Native. Also, I've been using GraphQL for over a year and I made a couple of full-stack/backend applications such as: -- a basic twitter clone using React Native ( using react-apollo), and nodejs (using Appollo. server).</p> <p>-- I made microservice e-commerce using NestJS alongside GraphQL. <a href="https://github.com/secmohammed/microservices-e-commerce-nest-api" target="_blank">Link</a></p> <p>-- slack clone using React ( with Typescript), and NestJS <a href="https://github.com/secmohammed/slack-clone" target="_blank">Link</a></p> <p>-- meetups clone API using (Golang and gqlgen) <a href="https://github.com/secmohammed/golang-graphql-meetups" target="_blank">Link</a></p> <p>-- ideas API clone using NestJS and GraphQL <a href="https://github.com/secmohammed/ideas-api" target="_blank">Link</a></p> <p>I've been working with GraphiQL to test my endpoint especially when not having the frontend built yet. and I'm keen on participating in this project to help with what I could to improve it.</p>
The problem here is to migrate from gitbook to some other tool which provides us with the feature of generating website from some easy to use markup language like markdown in which the current gitbook is hosted. So, I propose to solve this using antora for website and using asciidoc as markup language for it as it fulfills the main requirments of having a website and ebook(epub). It also have option to customise the UI which could be used to make antora website look more attracting and I have listed why I used this in my proposal.
The VLC interface is quite outdated on Linux and Windows. It has a lot of features, but some are not properly exposed. The interface is currently being reworked. The new designs shared on the mailing list are to be used and parts of those are to be developed, using *QML*. The new interface is simpler, more user-friendly, and has a better "media center" feel to it. It requires integration with the media library and with the current interface. *QML* is needed for the UI/UX.
Security teams and open-source organizations often struggle with managing vulnerability reports, bug bounties, and contributor performance efficiently. The current organization dashboard lacks advanced filtering, real-time analytics, and collaboration tools, making it difficult to track and resolve security issues effectively. This project aims to redesign and enhance the dashboard to provide a more intuitive, data-driven, and collaborative experience. Using Django Templates/HTMX and Tailwind CSS, the new dashboard will introduce advanced filtering, interactive analytics, and role-based collaboration tools to streamline vulnerability management. Key Deliverables: 1. Redesigned Dashboard UI for seamless navigation. 2. Advanced Filtering & Search for security reports. 3. Real-time Analytics & Insights for better decision-making. 4. Collaboration Features (issue assignment, commenting, notifications). 5. Optimized Backend with secure API endpoints and role-based access. 6. Comprehensive Testing & Documentation for future maintainability.