Bug bounties: finding and fixing security holes with European Commission funds

Free and open source software (FOSS) is about much more than driving costs down, in some cases even down to zero – it’s about giving control back to users, developers and even nations. With FOSS, everyone gains the freedom to study, improve and share the software – and to use it whenever and wherever they want, without being restricted by vendor lock-in strategies.

FOSS has been widely used amongst government bodies and public services, so thanks to the coordination of their recently formed Open Source Programme Office (OSPO), the European Commission has started a series of hackathon and “bug bounty” programmes to help selected projects find (and potentially fix) security issues.

The Commission’s OSPO has set aside €200,000 to reward developers and researchers who find critical security vulnerabilities in free software projects (such as LibreOffice and Mastodon).

Rewards go from €250 up to €5000 for security bug disclosures, with 20% added on top if the researchers provide also a fix for the bug.

This will surely help to further improve the security and reliability of FOSS tools, benefiting everyone from individual users to larger governmental and public bodies, and to make FOSS known to those that haven’t yet discovered how much it has to offer.

Paolo Vecchi, from The Document Foundation’s Board of Directors, which liaised with the European Commission’s OSPO, adds:

It is a real pleasure to see that the European Commission is following up their open source software strategy 2020-2023 with concrete actions. The creation of the OSPO, which is led by very knowledgeable and passionate people, was the first step required to then progress into other programmes, like this bug bounty, which will provide the needed support for an open source ecosystem that has become the foundation of all the platforms and software we use.

The Document Foundation and our community are grateful for the opportunity that has been provided with to make LibreOffice even more secure and ready to potentially become the preferred open source office suite also within European institutions.

We encourage all developers to head to the bug bounty page and help us to make open source even more secure for all.

To learn more about security in LibreOffice, see here. We’ll post more updates about this programme on this blog and our social media – stay tuned!

LibreOffice: The Klingons and Interslavs are already here

We happily report that Klingons have – at this point – not taken over control of the LibreOffice bug-tracker.

While Klingon language support still ranks somewhat low among issues thought not to be essential, the federation that is LibreOffice 7.3 will also bring Interslavic support to the mix when released come early February.

Since you were wondering, Interslavic is an artificial language meant to operate in the cross-section of Slavic interlingualism.

Targ-herders everywhere are reportedly mildly pleased. The synergy in KSL (Klingon as second language) regions is a potato harvest that we can all appreciate.

Undeterred by the confines of a monogalactic community of translators, LibreOffice numbers are growing. Hundreds of millions or earthlings alone now have powerful tools honed in their native languages.

Together we bring free and open source software to the Nekrit Expanse. We can go into space, and beyond. Use, inspect, improve and share freely — with all. Full tut ahead.

Thanks, Qapla’ and hvala!


Update: check out the Interslavic Spellchecker extension


And now, a bit more seriously…

Yes, initial language support for Klingon and Interslavic is coming to LibreOffice. But before you ask: “Why don’t you focus on X or Y instead?” Remember that LibreOffice is a volunteer-driven, community open source project. Individual developers (and companies in the ecosystem) work on what’s important for them, and not to the detriment of anything else. If someone wants to help with a Klingon translation, that doesn’t mean others in the project stop working on other important tasks!

And especially: even if Klingon and Interslavic support sounds like a novelty, it shows how versatile free and open source software is. As mentioned, LibreOffice is available in over 100 languages, and we’d like to expand that even further. The more languages the better, especially if we can help to boost IT skills in places which don’t otherwise have software in their native languages!

Join our localisation projects, and give us a hand!

LibreOffice 7.2.5 is now available

Berlin, January 6, 2022 – The Document Foundation announces LibreOffice 7.2.5 Community, the fifth minor release of the LibreOffice 7.2 family, which is available on the download page.

This version includes 90 bug fixes and improvements to document compatibility. The changelogs provide details of the fixes: changes in RC1 and changes in RC2.

For enterprise-class deployments, TDF strongly recommends the LibreOffice Enterprise family of applications from ecosystem partners, with long-term support options, professional assistance, custom features and Service Level Agreements: LibreOffice in Business.

LibreOffice Community and the LibreOffice Enterprise family of products are based on the LibreOffice Technology platform, the result of years of development efforts with the objective of providing a state of the art office suite, not only for the desktop but also for mobile and the cloud.

LibreOffice Technology-based products for Android and iOS are listed on this page, while products for App Stores and ChromeOS are listed here.

Get help, and support us

Individual users are assisted by a global community of volunteers, via our community help pages. On the website and the wiki there are guides, manuals, tutorials and HowTos. Donations help us to make all of these resources available.

LibreOffice users are invited to join the community at Ask LibreOffice, where they can get and provide user-to-user support. People willing to contribute their time and professional skills to the project can visit the dedicated website at What Can I Do For LibreOffice.

LibreOffice users, free software advocates and community members can provide financial support to The Document Foundation with a donation via PayPal, credit card, bank transfer, cryptocurrencies and other methods on this page.

LibreOffice 7.2.5 is built with document conversion libraries from the Document Liberation Project.

Download LibreOffice 7.2.5

Best Wishes from TDF

Dear community members, TDF members, Advisory board members, team members, membership committee and board!

Another year marked by the global pandemic is coming to an end these days. In addition to all the depressing news and circumstances that affect us all, there are also pleasing and uplifting developments.

Apart from the painfully missed opportunity to meet in person, be it in the local communities or at our annual conference, we have nevertheless achieved so much together, worked together and brought our foundation forward, so that we can already say that it was one of the most successful years for and with our project.

I would like to thank all of you on behalf of our project. Everyone has contributed to the success story in different ways. All the contributions intertwine, and without these individual parts the whole thing would not be possible and so successful. Especially in these times. Thank you very much again for this.

And it is precisely this commitment, this proof of the resilience of our project during this time, that allows me to look to the future with good cheer. Please continue to support our community in so many ways in the coming year, every contribution is needed.

After two very intensive and busy years, I myself will say goodbye to the board, but after a short phase of rest, I will continue to work with you in the project in one or two different places again. I wish the newly elected board all the best!

I wish you and your beloved ones a few days of recreation at the end of this year and a stable good health for the next one.

Thanks again and hope to see you all with your contributions in the new year again,

yours
Lothar Becker
as chairman of the board

PRELIMINARY results of the elections for the next Board of Directors at The Document Foundation

TDF Membership Committee announces the PRELIMINARY results of the elections for the next Board of Directors at The Document Foundation.

The number of TDF Members who voted is 120, from a total amount of 211 eligible voters. This means that 91 TDF Members did not vote. The Membership Committee would like to thanks all the voters, as the elections are the most significant time of the year for TDF Members, because they can decide about the project’s governance.

Based on the PRELIMINARY results, the following candidates are elected as members of TDF Board of Directors, in order of preference:

Full Members:

  1. Thorsten Behrens
  2. Paolo Vecchi
  3. Jan ‘Kendy’ Holešovský
  4. Emiliano Vavassori
  5. Caolán McNamara
  6. Cor Nouws
  7. László Németh

Deputies:

  1. Gábor Kelemen
  2. Ayhan Yalçınsoy
  3. Gabriel Masei

Results were calculated using the same tooling and rules of previous elections, based on the single transferable vote (STV) voting system and the Meek algorithm (https://en.wikipedia.org/wiki/Counting_single_transferable_votes). The software used is OpenSTV (https://github.com/Conservatory/openstv).

The Membership Committee agreed on the ranking of the first six candidates, but is still discussing about the last four candidates.

Unfortunately, given that there are 10 candidates and 10 seats, OpenSTV 1.7 does not provide more than one round to rank all candidates that have not reached the threshold, and considers all candidates as elected. For more details, see: https://elections.documentfoundation.org/results.php?election_id=14. The Membership Committee will investigate this further, and will update TDF Members and the general public as soon as possible.

Before the results can be considered as final, we have the challenge phase from Wednesday, December 15, to Monday, December 20, at midnight CET (UTC+1).

TDF Members are invited to check their votes as explained after the voting, by using the anonymous token received at that time (each voter has received a different token, and is the sole owner of that token). Election results to verify are available here: https://elections.documentfoundation.org/votes.php?election_id=14.

If you have any questions or if you think that there were irregularities during the vote, please get in touch with the Membership Committee AS SOON AS POSSIBLE, and in any case no later than Monday, December 20, at midnight CET (UTC+1), using the email address elections@documentfoundation.org.

For reference, details of the whole election process have been outlined in the first announcement: https://listarchives.tdf.io/i/tFJzSYUUGcSjf0c0NtNiEOou.