We build our computers (systems) the way we build our cities: over time, without a plan, on top of ruins — Ellen Ullman
www.youtube.com/watch?v=Cum5...
www.youtube.com/watch?v=Cum5...
Once tagged, releases can’t be changed. No more worrying about malicious actors swapping out assets or moving tags.
Single-use version tags with signed attestations. This is the supply chain protection open source really needs 🔒
#GitHubUniverse
My favorite project they have is helping projects generate #SBOMs, but there's a lot happening. If you want to see some public examples of how to do security right, give it a listen!
Humans have a strong bias for throughput.
"I can handle X requests per second."
Real capacity engineers use response-time curves.
Can't wait for you to hear the full episode, coming soon!
Can't wait for you to hear the full episode, coming soon!
Three root causes dominate: phishing, control handoff, and unsafe GitHub Actions triggers. All three can be systematically avoided.
words.filippo.io/compromise-s...
Three root causes dominate: phishing, control handoff, and unsafe GitHub Actions triggers. All three can be systematically avoided.
words.filippo.io/compromise-s...
And, of course, not breaking norms and cosplaying a public charity while bowing to a sole sponsor over the community. 😢
And, of course, not breaking norms and cosplaying a public charity while bowing to a sole sponsor over the community. 😢
Learn how businesses can help ensure long-term sustainability in #EclipseFdn Executive Director Mike Milinkovich’s latest blog: hubs.la/Q03Kz6D50 #PreserveOpenSource #SoftwareSupplyChain #OpenSourceResponsibility
Learn how businesses can help ensure long-term sustainability in #EclipseFdn Executive Director Mike Milinkovich’s latest blog: hubs.la/Q03Kz6D50 #PreserveOpenSource #SoftwareSupplyChain #OpenSourceResponsibility
As an #OCX26 sponsor, you get to align your brand with the communities shaping tomorrow’s tech all in one place.
👉 Get the prospectus or get in touch with our team directly: www.ocxconf.org/event/2026/b...
As an #OCX26 sponsor, you get to align your brand with the communities shaping tomorrow’s tech all in one place.
👉 Get the prospectus or get in touch with our team directly: www.ocxconf.org/event/2026/b...
So I wrote a blog post about it
An absolutely ridiculous amount of open source is one person projects. I have the data to prove it
opensourcesecurity.io/2025/08-oss-...
So I wrote a blog post about it
An absolutely ridiculous amount of open source is one person projects. I have the data to prove it
opensourcesecurity.io/2025/08-oss-...
There is ZERO reason to enter an argument about patriotism with people who still worship traitors to America 150+ years later.
They. Are. Breaking. The. Law.
There is ZERO reason to enter an argument about patriotism with people who still worship traitors to America 150+ years later.
They. Are. Breaking. The. Law.
We’re grateful to @ec.europa.eu for facilitating this discussion and to everyone involved.
@j-rico.bsky.social @tobie.bsky.social @mikael.barbero.tech @apache.org
We’re grateful to @ec.europa.eu for facilitating this discussion and to everyone involved.
@j-rico.bsky.social @tobie.bsky.social @mikael.barbero.tech @apache.org
Register for Day 2 (June 10 on 4PM CEST): eclipse.zoom.us/meeting/regi...
➡️ blogs.eclipse.org/post/marta-r...
Register for Day 2 (June 10 on 4PM CEST): eclipse.zoom.us/meeting/regi...
➡️ blogs.eclipse.org/post/marta-r...
More details and registration links on blogs.eclipse.org/post/marta-r...
More details and registration links on blogs.eclipse.org/post/marta-r...
📅 Day 1: eclipse.zoom.us/meeting/regi...
📅 Day 2: eclipse.zoom.us/meeting/regi...
📅 Day 1: eclipse.zoom.us/meeting/regi...
📅 Day 2: eclipse.zoom.us/meeting/regi...
We need more governments to collaborate on public software projects to achieve digital sovereignty.
We need more governments to collaborate on public software projects to achieve digital sovereignty.
From a reliable source. MITRE support for the CVE program is due to expire tomorrow. The attached letter was sent out to CVE Board Members.
From a reliable source. MITRE support for the CVE program is due to expire tomorrow. The attached letter was sent out to CVE Board Members.