OSS Fuzz is a google project that supports open source projects by fuzzing. It allows Google to find and report bugs, especially security bugs, to the project. I'm willing to work on writing fuzzers for ossec-hids and integrating with oss-fuzz, if this would be welcome by the maintainers. You would see me writing some fuzzing harnesses and making pull requests to merge them in to the project, and a few regression tests to make sure that the fuzzing harnesses are working properly. Then, you would get reports from google with anything the fuzzer finds.
Is this something that would be welcome for this project?
Sorry, should clearly say "p7zip" not "ossec-hids"... I'm making this offer to a few projects!