Matt "msw" Wilson's Avatar

Matt "msw" Wilson

@msw.bsky.social

717 Followers  |  220 Following  |  161 Posts  |  Joined: 25.04.2023  |  2.3205

Latest posts by msw.bsky.social on Bluesky

Itโ€™s really hard for OSS projects too. Imagine a leaked GH access token from a project maintainer who is not responding, and who is not an employee because OSS isnโ€™t a company. How do you the project get that token revoked? You canโ€™t. You have to de-list the maintainer from your GH org.

27.07.2025 17:11 โ€” ๐Ÿ‘ 2    ๐Ÿ” 1    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

Tricky thing is when people have built their own automation (predating Actions), using CI/CD tools and services, making for something other than a โ€œpure GitHubโ€ implementation. ๐Ÿ˜ฌ

26.07.2025 20:10 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0

That said: prevention > detection, as always

26.07.2025 17:48 โ€” ๐Ÿ‘ 8    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

Also, speaking for myself, hurray for watchful, diligent security folks detecting things before vandals could fix their syntax error.

26.07.2025 17:47 โ€” ๐Ÿ‘ 14    ๐Ÿ” 0    ๐Ÿ’ฌ 2    ๐Ÿ“Œ 1
Preview
GitHub Actions - Updating the default GITHUB_TOKEN permissions to read-only - GitHub Changelog Previously, GitHub Actions gets a GITHUB_TOKEN with both read/write permissions by default whenever Actions is enabled on a repository. As a default, this is too permissive, so to improve securityโ€ฆ

Later in 2023 GitHub changed the default permissions for access tokens.

Unfortunately this leaves older projects, organizations, and enterprises with an unsafe default.
github.blog/changelog/20...

26.07.2025 17:31 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

โ€œAll this to prove one thing: that vulnerable workflows canโ€™t keep a secret.โ€

This was true in 2023 as it is now. You have to make sure you scope down GitHub access tokens.

26.07.2025 17:29 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0
Leaking Secrets From GitHub Actions: Reading Files And Environment Variables, Intercepting Network/Process Communication, Dumping Memory GitHub Actions is a CI/CD solution built into GitHub. It allows users to for example, deploy their repositoryโ€™s code on every push, or to automatically respo...

Here is a blog post that describes a similar problem as reported in CodeBuild in the context of GitHub Actions workers back in early 2023.
karimrahal.com/2023/01/05/g...

26.07.2025 17:27 โ€” ๐Ÿ‘ 2    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0

From my POV, the most important message for everyone who is doing the hazardous work of developing software in public on platforms like GitHub: you have to pay *close attention* to GitHub token permission scoping.
Itโ€™s not well known outside of security research circles how often GitHub tokens leak.

26.07.2025 17:26 โ€” ๐Ÿ‘ 27    ๐Ÿ” 7    ๐Ÿ’ฌ 3    ๐Ÿ“Œ 0
Preview
Project Definition | Linux Foundation Documentation

You can see what's on the menu of legal services when you set up a project here... LF Projects LLC is generally for software projects, Joint Development Foundation Projects, LLC is generally for standards development...
docs.linuxfoundation.org/lfx/project-...

22.07.2025 19:58 โ€” ๐Ÿ‘ 2    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Home - LF Projects, LLC LF Projects, LLC Policies LF Projects, LLC is a Delaware series limited liability company (โ€œLF Projectsโ€). Projects of LF Projects (โ€œProjectsโ€) are established as separate โ€˜seriesโ€™ of LF Projects. In....

It's a corporate holding structure of the Linux Foundation, used as the owner of intellectual property, etc.

A committed community of maintainers doesn't have a LLC registered in Delaware that can hold trademarks... This is infrastructure Linux Foundation provides.

lfprojects.org

22.07.2025 19:49 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0

Valkey is maintained by the Valkey maintainers, not by a neutral foundation. Linux Foundation provides the tent, but without committed maintainers the tent is empty.

The thing that keeps the power of any one company in check isn't the Linux foundation, it's a committed community of mutual interest.

22.07.2025 19:44 โ€” ๐Ÿ‘ 4    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Open Source Is Too Important To Dilute The definition of "open source" is quietly eroding. When these lines blur, trust breaks โ€” and open source doesnโ€™t work without trust.

There's much to agree with in Dan's piece on defending the definition of Open Source. On details, I quibble.

"Today, Valkey is maintained by a neutral foundation, ensuring no one company can take it away from open source."

Linux Foundation doesn't maintain Valkey. thenewstack.io/open-source-...

22.07.2025 19:38 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 2    ๐Ÿ“Œ 0
A ghost nightlight with the word Kiro

A ghost nightlight with the word Kiro

Thrilled for the launch of @kiro.dev today! We started with two main ideas that led to Kiro's spec-driven development features:
1) AI can help us build better products through rapid prototyping
2) Devs can declare their app's requirements to get better results from AI, close to production-grade code

14.07.2025 19:58 โ€” ๐Ÿ‘ 12    ๐Ÿ” 2    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Hello,

I hope this message finds you well.

As part of our ongoing efforts to comply with the EU Cyber Resilience Act (CRA), we are currently conducting a cybersecurity risk assessment of third-party software vendors whose products or components are integrated into our systems.

To support this initiative, we kindly request your input on the following questions related to your software product "libcurl" with version 7.87.0. Please provide your responses directly in the table below and do reply to all added in this email,

Hello, I hope this message finds you well. As part of our ongoing efforts to comply with the EU Cyber Resilience Act (CRA), we are currently conducting a cybersecurity risk assessment of third-party software vendors whose products or components are integrated into our systems. To support this initiative, we kindly request your input on the following questions related to your software product "libcurl" with version 7.87.0. Please provide your responses directly in the table below and do reply to all added in this email,

It has officially begun. The CRA info request counter is no longer at zero.

11.07.2025 07:44 โ€” ๐Ÿ‘ 42    ๐Ÿ” 90    ๐Ÿ’ฌ 15    ๐Ÿ“Œ 3

OH: "And so, it begins."

11.07.2025 16:56 โ€” ๐Ÿ‘ 7    ๐Ÿ” 1    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

The CVE... The "disputed" tag is on the record, which is the system working as designed.

www.cve.org/CVERecord?id...

09.07.2025 17:26 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

This is not an adventure that FOSS maintainers should have to endure, in my opinion.

Unfortunately The Rules don't prohibit allocating a CVE for an identified weakness that was never in a released Product...

www.cve.org/resourcessup....

09.07.2025 17:23 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0

I think itโ€™s more Red Hatโ€™s business model than any of the firms listed above.

And those who know the history of libxml2 (and friends like libxslt) know that Red Hat funded a lot of its development, directly and indirectly, via employing DV.

23.06.2025 14:51 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0

I do not like this timeline.

22.06.2025 00:38 โ€” ๐Ÿ‘ 6    ๐Ÿ” 1    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

While there is much more that industry can do, and NEEDS to do, we should recognize that in the past Google has directly sponsored libxml2 development.

It's not *just* been Project Zero sending vulnerability disclosures to the maintainer.
gitlab.gnome.org/GNOME/libxml...

21.06.2025 23:08 โ€” ๐Ÿ‘ 5    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

The innovation of piped water and sewer systems had an enormous impact on public health and economic growth.

It's infrastructure that we generally take for granted in developed industrialized nations.

20.06.2025 18:44 โ€” ๐Ÿ‘ 5    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

A dimension of open source software supply chain risk management that we don't discuss enough...
โฌ‡๏ธ

17.06.2025 17:37 โ€” ๐Ÿ‘ 5    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0

#hugops to all that operate, no matter who you work for.

12.06.2025 20:35 โ€” ๐Ÿ‘ 2    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Whether the 5.3 branch is planned to fix CVE-2016-1000027 vulnerabilities in 5.3.39? ยท Issue #34765 ยท spring-projects/spring-framework Hello, Currently, the latest JDK8 version 5.3.39 still has vulnerabilities. Can the open source community release a new 5.3.x version to fix the vulnerabilities so that JDK8 can be used? ths, look ...

Whether the 5.3 branch is planned to fix CVE-2016-1000027 vulnerabilities in 5.3.39!

Sigh.

github.com/spring-proje...

12.06.2025 03:30 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

"Producing new artifacts every time a problem like that happens is not sustainable technically and as a community. It feels like we're trying to solve organizational issues from a pure technical perspective, and this rarely works." - Spring maintainer in 2020...

And yet, in 2025...

12.06.2025 03:29 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0

"I'd suggest sharing your experience with your security team and security vendor: if developers need to consider switching development stack completely [by abandoning Spring] because tools and processes raise false positives[...], there's a broader problem that needs to be addressed."

๐Ÿ’ฏ this!

12.06.2025 03:28 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0
Preview
Sonatype vulnerability CVE-2016-1000027 in Spring-web project ยท Issue #24434 ยท spring-projects/spring-framework Affects: \5.2.3.RELEASE Issue Title : Sonartype vulnerability CVE-2016-1000027 in Spring-web project Description Description from CVE Pivotal Spring Framework 4.1.4 suffers from a potential remote ...

The story of #CVE-2016-1000027 is a tell of woe for Open Source maintainers.

A zombie CVE from a CNA long dead, a CVSSv3 base score of 9.8 in the NVD, and a weakness that is intrinsic in the language ecosystem (do not deserialize Java from untrusted sources, people!!!).
github.com/spring-proje...

12.06.2025 03:25 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0

Not all Foundations are the same.

11.06.2025 22:57 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0
Anonymous CVS Access Returns

I feel so old.

lists.gnome.org/archives/gno...

11.06.2025 02:19 โ€” ๐Ÿ‘ 5    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0
GNOME Has a New Infrastructure Partner: Welcome AWS! โ€“ The GNOME Foundation

Oh the _feels_ when reading this announcement!

I was one of the GNOME projectโ€™s first sysadmins, back in the days of a single CVS server running on a machine hosted at Red Hatโ€™s office.

Itโ€™s amazing to see their journey to the cloud!
foundation.gnome.org/2025/06/10/g...

11.06.2025 02:15 โ€” ๐Ÿ‘ 6    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0

@msw is following 20 prominent accounts