AI-generated fixes will undergo human review before open-source maintainers decide whether to accept, change, or reject them.
The Open Worldwide Application Security Project (OWASP) launched a new initiative designed to close the gap between identifying vulnerabilities in open-source software and finding and deploying the fixes. Open-source components are used in a wide range of software, from commercial applications to systems that support critical infrastructure. In its launch announcement, OWASP cited a 2026 Black Duck report finding that open-source code appeared in 98% of the commercial codebases examined.
This means a vulnerability in one widely used component can create risks for many businesses. The problem is growing as automated security tools and AI make it possible to find more flaws, while open-source maintainers must still develop and test the fixes.
The Open Automated Security Initiative for Software, or OASIS, will use AI to generate proposed fixes and application-security professionals to review them. Fixes that pass that review will be submitted to the affected open-source projects, whose maintainers will decide whether to use them.
Rather than creating another tool that identifies problems, OASIS aims to turn vulnerability reports into fixes that open-source maintainers can evaluate and deploy.
AI will generate fixes for human review
OASIS will use automated tools to scan widely used open-source software for vulnerabilities and generate proposed code changes to address them.
Security specialists from companies and other organizations who volunteer through OASIS will review each proposed fix. They will assess whether the reported vulnerability is genuine, whether the change addresses it correctly, and whether the fix could create other security or operational problems.
A fix that clears this review will be considered credible enough for the affected project to evaluate. The project’s maintainers will still test the fix and decide whether to accept, modify, or reject it.
OASIS has not named its first projects
OWASP said hundreds of software-security specialists registered to participate before OASIS formally launched. AppSecAI, Intigriti, and DryRun Security are its founding industry members.
OWASP has not identified the first open-source projects OASIS will examine or said when it expects to submit its first proposed fixes. The initiative plans to track how many fixes open-source maintainers ultimately accept as one measure of whether its approach works.

