Emelia 👸🏻<p>This is a program that I've been championing within <span class="h-card" translate="no"><a href="https://hachyderm.io/@nivenly" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>nivenly</span></a></span> over the past year, after we noticed that security vulnerabilities weren't being disclosed responsibly, and not enough research was going into the security of Fediverse software.</p><p>You might remember my Pixelfed vulnerability from last year, where OAuth scopes weren't checked allowing for privilege escalation via the API (CVE-2024-25108), that was our very first test-case of this program. </p><p>I'm incredibly proud to be involved in launching the Fediverse Security Fund from Nivenly Foundation (a 501(c)4 not-for-profit cooperative)</p><p><a href="https://hachyderm.io/tags/fediverse" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>fediverse</span></a> <a href="https://hachyderm.io/tags/security" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>security</span></a> <a href="https://hachyderm.io/tags/nivenly" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>nivenly</span></a> <a href="https://hachyderm.io/tags/FediverseSecurityFund" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>FediverseSecurityFund</span></a></p><p>RE: <a href="https://hachyderm.io/@nivenly/114268491892140498" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">hachyderm.io/@nivenly/11426849</span><span class="invisible">1892140498</span></a></p>