Sustaining Package Repositories with Brian Fox
Brian Fox discusses the challenges and future of open source package repository infrastructure. We discuss the complexities of managing public registries, the impact of overconsumption, and the import...
On #OpenSourceSecurity I had a chat with @brianfox.bsky.social about the sustainability letter from the open source package registries
This one is a big deal. The costs for open source are paid by someone, if you don't know who, you need to read this letter
opensourcesecurity.io/2025/2025-10...
06.10.2025 14:26 β π 2 π 1 π¬ 0 π 0
Yes all of this. Now itβs time to fix it.
25.09.2025 13:05 β π 2 π 0 π¬ 0 π 0
From Abuse to Alignment: Why We Need Sustainable Open Source Infrastructure
Open source relies on shared infrastructure. Learn why sustainable stewardship is critical to keep ecosystems like Maven Central strong.
Free isnβt free: the infrastructure behind open source has real costs, and itβs time we aligned usage with responsibility.
This morning we jointly launch a new blog and open letter on sustainable stewardship.
www.sonatype.com/blog/from-ab...
23.09.2025 10:34 β π 24 π 14 π¬ 0 π 2
We see more new affected packages over night. It highlights why we built this ml/model for this back when it was still called ml/ai and use it to protect customers in real time.
We will be updating the blog shortly with the new packages.
09.09.2025 13:55 β π 1 π 0 π¬ 0 π 0
More than 1
08.09.2025 20:36 β π 0 π 0 π¬ 0 π 0
Our malware systems at Sonatype seem to be picking these up coming from other, not yet reported accounts. This attack seems to have landed more publishers as this unfolds. Check your accounts folks while we work with others to contain.
08.09.2025 20:12 β π 9 π 4 π¬ 2 π 1
Fair. Maybe itβs a scam. Will have to wait and see.
16.04.2025 11:37 β π 0 π 0 π¬ 1 π 0
Good news for Java developers! Central now validates OpenSSF sigstore signatures as part of publishing. If youβre already signing your artifacts with Sigstore, youβll now get real-time validation feedback in the Central Publisher Portal.
Read more details here: www.sonatype.com/blog/central...
29.01.2025 17:53 β π 5 π 3 π¬ 0 π 0
π’ The @linuxfoundation.org, with Harvard's Laboratory for Innovation Science, has released Census III of Free and Open Source Software β Application Libraries. π₯οΈ Key insights from OpenSSF help reduce FOSS vulnerabilities and secure supply chains. Read more: openssf.org/press-releas...
04.12.2024 15:54 β π 3 π 2 π¬ 0 π 0
Engineering Director, Open Source and Supply Chain Security
New to Cambridge. Works in Open Source Licensing, OSPOs, M&A, SCA, SBOMs and Security
Love my bike, electronics/Arduino/radio/rf and walkable cities!
Father, husband, cybersecurity professional, lover of all things that go βvrooomβ, and avid watch collector.
Creator of OWASP Dependency-Track. Chair of OWASP CycloneDX and Ecma TC54. OWASP Global Board of Directors.
https://about.me/stevespringett
Co-founder/committer @omnibor/@nservicemesh, Distinguished Engineer @Cisco
Linux/kernel/systems/Kubernetes/cloud hacker, backyard farmer, home brewer, woodworker, Vespa rider, amateur triathlete, Portland Thorns/Timbers fan, Pygmy kayaks, Nor Rel Muk Wintu
F/OSS hack of minor notoriety. former CISA, MSFT, OSI, OpenStack, & more.
π³οΈββ§οΈ & ποΈ & πͺπΊ.
all opinions π― mine.
SBOM Champion. Full service technocrat. Now at @CISAgov, formerly NTIA. Lapsed{engineer, academic, author}. Personal Account. Food, drink, dogs, SBOM
Black.
#opensource governance: @kubernetes.io, @openssf.org, TODO Group
Office of the CTO, Bloomberg β Opinions are my own
Bio and links: https://whois.auggie.dev/
#Blacksky
Formerly @stephenaugustus (Twitter), @justaugustus@hachyderm.io (Mastodon)
K8s SIG Security Co-Chair
container escape artist
goose in the machine
chaotic good
Minneapolis. They/them.
Stay punk π΄
Securing open source software is good for everyone.
FINOS TOC; OpenSSF Baseline; CNCF TAG Security & Compliance
Head of Security @ Eclipse Foundation
We build our computers (systems) the way we build our cities: over time, without a plan, on top of ruins β Ellen Ullman
Open Source Security Foundation (OpenSSF)
Together, we're securing the open source ecosystem
http://openssf.org
#OSSSecurity #OpenSSFCommunity