OWASP’s OASIS combines AI-generated patches with human AppSec validation to help open-source maintainers fix vulnerabilities across the long tail of libraries and applications.
OWASP has launched the Open Automated Security Initiative for Software (OASIS), a global community effort aimed at turning open-source vulnerability remediation from a “find and report” process into a “find, validate and fix” workflow.
Announced on August 26, 2026, in San Francisco, OASIS uses AI to generate candidate fixes, which are then reviewed by application security (AppSec) professionals and agents for correctness and safety before vetted patches are submitted upstream to maintainers.
The initiative addresses a major open-source security bottleneck. Open-source software underpins roughly 98% of commercial codebases, according to the Black Duck 2026 Open Source Security and Risk Analysis Report, while maintainers are often overwhelmed by scanners that identify vulnerabilities without providing practical remediation.
OASIS targets the long tail of open-source libraries and applications through a three-stage process: AI-driven repository scanning and patch generation, human and agent validation, and upstream submission of vetted fixes. A single validated upstream fix can potentially protect thousands of downstream applications.
Hundreds of AppSec professionals have joined since early sign-ups opened. Founding sponsors include AppSecAI, Intigriti, and DryRun Security.
Chris Holt, Strategic Engagement and Community Architect at Intigriti, said, “open source underpins the majority of the information economy, making unremediated vulnerabilities a systemic risk, and that OASIS lets the AppSec and open source communities cooperatively deliver secure software together.”
Unlike initiatives focused on high-priority infrastructure, OASIS uses a vendor-neutral community model to address open-source dependencies at scale, with roles spanning vulnerability validation, repository management, maintainer liaison and automation.
















































































