Audun Mo's Avatar

Audun Mo

@audunmo.dev.bsky.social

I like helping people make safer software. #appsec #cloudsec

24 Followers  |  46 Following  |  74 Posts  |  Joined: 13.11.2024  |  1.6478

Latest posts by audunmo.dev on Bluesky

Is Github Actions down again?

27.01.2026 13:01 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0

As an "I use vim actually" guy, I am always inclined to blame every scourge of society on Emacs of course

05.01.2026 06:32 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

Mark Zuckerberg opens Emacs and writes some PHP -> the fates of Venezuela, and potentially Greenland, are uncertain.

That's the butterfly effect for you

05.01.2026 06:31 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0

I strongly believe that almost every software business should be creating, aggregsting, and analyzing SBOMs, but the proprietary solutions are all bundled in with massive packages that are ill-suited to smaller shops. DTrack fills a hole there, but I think it's too much of a hassle for most to use

15.12.2025 21:17 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

As much as I love the spirit and idea of DependencyTrack, I really dislike the implementation. The app is heavy on resource consumption, the API is clunky to use, and lack of token auth for automation feels ironic for a security focused project

15.12.2025 21:15 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0

I opened X to look at Elon Musk tweet. Do I hate myself? Why did I do that to myself?

15.12.2025 21:13 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

What is h a p p e n i n g over at cloudflare. Down, again???

05.12.2025 08:55 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Amber The Programming Language Amber The Programming Language

Damn, ECMAScript-like syntax and compiles to bash? Folks, I think I'm in love amber-lang.com

12.11.2025 07:16 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

Me: let me simplify this app

Also me: let me start by describing exactly how I'm going to overengineer this thing

16.10.2025 20:59 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
a woman wearing a tiara and a sash with the words fork yeah on it ALT: a woman wearing a tiara and a sash with the words fork yeah on it
16.10.2025 12:29 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

*forking

16.10.2025 12:28 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0

Then I think the next thing to implement would be a gRPC implementation of the REST API.

16.10.2025 12:28 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

I'm thinking of forming dependency track. I think its promise could be delivered in a much simpler app. First thing is to combine the frontend and API to a single container. Second order of business would be to introduce OIDC based token auth for m2m

16.10.2025 12:26 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 3    ๐Ÿ“Œ 0

Manifesto:

16.10.2025 07:09 โ€” ๐Ÿ‘ 281    ๐Ÿ” 53    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

Within sometime in the next five years, there will be a story of someone using an LLM like a GPS to navigate, and it will be hilarious

11.10.2025 15:47 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

I have no earthly idea why the world landed on using SPDX over CycloneDX as its default. And I'm so sad about it

06.10.2025 11:58 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

But it's honestly just crazy that tags are not immutable by default. They just should be. They should never change

02.10.2025 09:39 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

As far as I can tell, this is because the base layer got rebuilt with a different timestamp. Same final image, but there is a diff all the way through the build steps

So that's not great

02.10.2025 09:38 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

Today, Go's 1.25.1-bookworm image suddenly changed hash

02.10.2025 09:37 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 2    ๐Ÿ“Œ 0

The fact that tags are immutable on docker hub by default blows my mind.

02.10.2025 09:37 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

At what point do we just classify the entirety of npm as a vulnerability, and just be done with it? Js needs a better standard library, and packages that can't randomly RCE your build pipeline if they feel like it

17.09.2025 18:13 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

If you sell products that purport to shift left, but don't support IaC or other code-based config, the product is not doing that. UIs and click-ops invite reactive, right-end operations, and it's often a sign of other legacy thinking / approaches in your tools

01.07.2025 10:17 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

Pushing ads on a service, then making a subscription to not have ads, is not a feature. It's not a product. And if it's the best you can think of, your company produces nothing

24.06.2025 12:09 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

Linkedins algorithm for what to create notifications for needs to be studied. I don't think I've seen an algo less able to find relevant information

16.06.2025 13:36 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

Bad features cause security risks, like bad road layouts lead to accidents. Case in point, github notifications. Filtering out the noise is so hard that I find drawn to separate apps to handle them. I don't because of the risk, but the avalanche ushers me in their direction

12.06.2025 10:57 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

A long time ago, I saw a thing about programmers on dating apps who make themselves out to be much more important than they are.

"Calm down, Brad. You're making computers go beep boop correctly" is still one of my favorite take down of anyone online

12.06.2025 05:34 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

I thought to myself "the clock is just Thursday". In other words, my friend's 5 day bachelor party is going well

01.05.2025 19:50 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

Note to anyone creating a scripting or rule or whatever language. Do not design your language so that comparison happens with =. Always assign with = and compare with ==. Otherwise all code produced in your language will be bad. And if = does both, you do not deserve good things in your life

28.04.2025 15:26 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

Right? I think this is people trying to replicate informal verbal conversation, which is sympathetic, but doesn't actually work in digital communication.

Which is why we're the jerks if we correct them.. But cmon just get to the point

11.04.2025 06:28 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

It is 2025. Stop sending "hi" on slack. Just say the thing you want or need right away

10.04.2025 08:23 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0

@audunmo.dev is following 19 prominent accounts