Fair. Maybe itβs a scam. Will have to wait and see.
16.04.2025 11:37 β π 0 π 0 π¬ 1 π 0
Good news for Java developers! Central now validates OpenSSF sigstore signatures as part of publishing. If youβre already signing your artifacts with Sigstore, youβll now get real-time validation feedback in the Central Publisher Portal.
Read more details here: www.sonatype.com/blog/central...
29.01.2025 17:53 β π 5 π 3 π¬ 0 π 0
π’ The @linuxfoundation.org, with Harvard's Laboratory for Innovation Science, has released Census III of Free and Open Source Software β Application Libraries. π₯οΈ Key insights from OpenSSF help reduce FOSS vulnerabilities and secure supply chains. Read more: openssf.org/press-releas...
04.12.2024 15:54 β π 3 π 2 π¬ 0 π 0
Engineering Director, Open Source and Supply Chain Security
New to Cambridge. Works in Open Source Licensing, OSPOs, M&A, SCA, SBOMs and Security
Love my bike, electronics/Arduino/radio/rf and walkable cities!
Father, husband, cybersecurity professional, lover of all things that go βvrooomβ, and avid watch collector.
Creator of OWASP Dependency-Track. Chair of OWASP CycloneDX and Ecma TC54. OWASP Global Board of Directors.
https://about.me/stevespringett
Co-founder/committer @omnibor/@nservicemesh, Distinguished Engineer @Cisco
Linux/kernel/systems/Kubernetes/cloud hacker, backyard farmer, home brewer, woodworker, Vespa rider, amateur triathlete, Portland Thorns/Timbers fan, Pygmy kayaks, Nor Rel Muk Wintu
open source hack of minor notoriety. former CISA, MSFT, OSI.
unapologetically queer. all opinions π― mine.
SBOM Champion. Full service technocrat. Now at @CISAgov, formerly NTIA. Lapsed{engineer, academic, author}. Personal Account. Food, drink, dogs, SBOM
Black.
#opensource governance: @kubernetes.io, @openssf.org, TODO Group
Office of the CTO, Bloomberg β Opinions are my own
Bio and links: https://whois.auggie.dev/
#Blacksky
Formerly @stephenaugustus (Twitter), @justaugustus@hachyderm.io (Mastodon)
Kubernetes SIG Security co-chair, container escape artist, aurora chaser, goose in the mainframe. Minneapolis. They/them. Stay punk π΄
Securing open source software is good for everyone.
FINOS TOC; OpenSSF Baseline; CNCF TAG Security & Compliance
RedDotRocket, building AgentUp ! https://github.com/RedDotRocket/agentup
Head of Security @ Eclipse Foundation
We build our computers (systems) the way we build our cities: over time, without a plan, on top of ruins β Ellen Ullman
Open Source Security Foundation (OpenSSF) http://openssf.org Together, we're securing the #opensource ecosystem #OSSsecurity