Security

Eclipse Open VSX Registry Security Advisory

Wednesday, July 2, 2025 - 12:07 by Natalia Loungou

A vulnerability in the Eclipse Open VSX Registry’s automated publishing system could have allowed unauthorized extension uploads. It did not affect existing extensions or admin functions.

The issue was reported on May 4, 2025, fully fixed by June 24, and followed by a complete audit. No evidence of compromise was found, but 81 extensions were proactively deactivated as a precaution.

2025 State of Automotive Software Development: Growing Contribution to Open Source Software and Increasing Confidence in Its Security and Safety

Tuesday, April 22, 2025 - 04:38 by Natalia Loungou

Perforce Software, in partnership with the Eclipse Foundation, has released the findings of the 2025 State of Automotive Software Development Survey. The report provides key insights into the current practices and emerging trends within the automotive software industry, including the use of open source software. The survey, conducted in Q4 2024, gathered responses from more than 650 automotive development professionals worldwide.

Security Incident Review: API Endpoint Exposure on accounts.eclipse.org

Thursday, April 10, 2025 - 03:43 by Natalia Loungou

In late March 2025, a security researcher in our community reported a security concern about a publicly accessible API endpoint containing user information on accounts.eclipse.org. After reviewing the issue, we determined this API endpoint was unnecessary and have since disabled it.

We looked through our access logs for the past few months and confirmed that the only requests were from the security researcher and the Eclipse Foundation staff who verified the report.


 

Eclipse Foundation Security Statement: JARsigner Abuse by Malicious Actors

Friday, February 21, 2025 - 04:41 by Natalia Loungou

As the Head of Security at the Eclipse Foundation, I want to clarify the situation, explain DLL side-loading, and reaffirm our commitment to security and collaboration with the community. My goal is to provide a clear understanding of both the technical aspects of this misuse and our approach to maintaining a secure ecosystem.

Per-Project Security Teams FAQ

Wednesday, September 4, 2024 - 05:02 by Marta Rybczynska

In response to requests from various projects and after discussions between the Eclipse Foundation Security Team and the Architecture Council, we recently announced the creation of Project Security Teams.