Security

Security Incident Review: API Endpoint Exposure on accounts.eclipse.org

Thursday, April 10, 2025 - 03:43 by Natalia Loungou

In late March 2025, a security researcher in our community reported a security concern about a publicly accessible API endpoint containing user information on accounts.eclipse.org. After reviewing the issue, we determined this API endpoint was unnecessary and have since disabled it.

We looked through our access logs for the past few months and confirmed that the only requests were from the security researcher and the Eclipse Foundation staff who verified the report.


 

Eclipse Foundation Security Statement: JARsigner Abuse by Malicious Actors

Friday, February 21, 2025 - 04:41 by Natalia Loungou

As the Head of Security at the Eclipse Foundation, I want to clarify the situation, explain DLL side-loading, and reaffirm our commitment to security and collaboration with the community. My goal is to provide a clear understanding of both the technical aspects of this misuse and our approach to maintaining a secure ecosystem.

Per-Project Security Teams FAQ

Wednesday, September 4, 2024 - 05:02 by Marta Rybczynska

In response to requests from various projects and after discussions between the Eclipse Foundation Security Team and the Architecture Council, we recently announced the creation of Project Security Teams.

Exploring the Future of Open Source Security at OCX 2024

Wednesday, August 21, 2024 - 05:00 by Natalia Loungou

The security track at OCX 2024 is packed with sessions that address the most pressing challenges and opportunities in open source security. Check this blog for a sneak peek at what the security track has in store.

Reviewing the CVE process and the CNA rules 4.0

Tuesday, August 20, 2024 - 03:49 by Marta Rybczynska

The Eclipse Foundation is a CNA (CVE Numbering Authority), responsible for assigning vulnerability identification numbers, known as CVE (Common Vulnerability Enumerations), to our projects. This August, a new set of rules for CNAs comes into force.

Securing the Future: 2FA Now Mandatory for Eclipse Foundation Committers

Friday, June 7, 2024 - 11:46 by Jacob Harris

This initiative, aimed at bolstering the security of our source code repositories, mandates that all users with write access to an Eclipse Project repository (commonly known as committers) on GitHub and the Eclipse Foundation GitLab instance must use 2FA.