The makers of OpenSSL unveiled a new development roadmap this week, saying the open source project needs to change because it “is increasingly perceived as slow-moving and insular.”
The inner workings of the poorly funded OpenSSL project came under scrutiny after the discovery of Heartbleed, a security flaw in the cryptography library that put much of the Web’s encrypted communications at risk. Tech giants eventually agreed to give the project money, enough to hire two full-time developers and perform a third-party security audit.
The new OpenSSL Project Roadmap, unveiled Monday and updated yesterday, sets out a list of goals for its new staff.
The project has numerous problems, the roadmap says. These include a backlog of bug reports, incomplete and incorrect documentation, code complexity that causes maintenance problems, inconsistent coding style, a lack of code review, and having no clear release plan, platform strategy, or security strategy.
The plan is to fix all these problems. For example, bug reports should receive “an initial response within four working days.” That goal can be met now, the roadmap says, but others will take longer. Defining a clear coding standard for the project is expected to take about three months. “Review[ing] and revis[ing] the public API with a view to reducing complexity” will take about a year.


Loading comments...