Improving software supply chain security with tamper-proof builds

Understanding the Impact of Apache Log4j Vulnerability

The Secure Open Source Pilot Program

An update on Memory Safety in Chrome

Google Online Security Blog: An update on Memory Safety in Chrome

Linux Kernel Security Done Right

AllStar: Continuous Security Policy Enforcement for GitHub Projects

A New Chapter for Google’s Vulnerability Reward Program

Verifiable Supply Chain Metadata for Tekton

Measuring Security Risks in Open Source

SLSA, an End-to-End Framework for Supply Chain Integrity

Rust/C++ interop in the Android Platform

Google's unified vulnerability schema for open source supports Rust on launch

Half-Double: New hammering technique for DRAM Rowhammer bug

Google banned almost 120k spam developer accounts in 2020 for the play store

Making the Internet more secure one signed container at a time

Integrating Rust into the Android Open Source Project

A New Standard for Mobile App Security

FFmpeg and a Thousand Fixes (2014)

Rust in the Linux kernel

Rust in the Android Platform

Fuzzing Java in OSS-Fuzz

Continuing to Raise the Bar for Verifiable Security on Pixel

A Spectre proof-of-concept for a Spectre-proof web

Google will provide fundings for rewriting popular open source projects in Rust

Know, Prevent, Fix: A framework for shifting the discussion around vulnerabilities in open source

Privacy-preserving features in the Mobile Driving License

Towards native security defenses for the web ecosystem

System Hardening in Android 11

Protecting users from insecure downloads in Google Chrome

More →