Michael Lieberman's Avatar

Michael Lieberman

@mikeneeds.rest.bsky.social

Software supply chain security

181 Followers  |  169 Following  |  44 Posts  |  Joined: 22.09.2023  |  2.1716

Latest posts by mikeneeds.rest on Bluesky

Are some large enterprises acting like ignorant children? ๐Ÿค”

22.06.2025 23:15 โ€” ๐Ÿ‘ 6    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

If I'm writing a personal project? I'm a little bit more flexible.

If I'm working on something for my employer, I'm looking at the risks. A sandbox research project is going to go through different scrutiny than something like an online banking application.

22.06.2025 22:46 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

I think the way Europe is looking at this with the CRA is also something to look at. Europe says in your example it's still the responsibility of the organization consuming the OSS to ensure it meets the regulation.

22.06.2025 22:37 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

Open source in and of itself is just code thrown out to the public with no warranty. Some of it is good, some bad. In your example if, maybe I would look at a different project or buy it from a reputable organization instead of something with few maintainers.

22.06.2025 22:35 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0

Yes absolutely. People leave up all sorts of stuff. Unless you are purposefully misleading folks it's up to the consumer to do some level of due diligence. I have worked at massive banks where there were policies in place to prevent including that sort of stuff.

22.06.2025 21:58 โ€” ๐Ÿ‘ 12    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0

It is still the responsibility of the consumer. Full stop.

22.06.2025 21:31 โ€” ๐Ÿ‘ 8    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0
Preview
Startup Embeds AI Security Analysis in Dev Workflow Kusari Inspector analyzes dependencies and code changes during pull requests, providing devs with actionable go/no-go recommendations before code merges.

I was interviewed recently about Kusari's new security PR bot. Check it out!

18.06.2025 02:10 โ€” ๐Ÿ‘ 2    ๐Ÿ” 2    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Post image 21.05.2025 17:09 โ€” ๐Ÿ‘ 488    ๐Ÿ” 89    ๐Ÿ’ฌ 9    ๐Ÿ“Œ 2
License to `npm install`? Why do we burden our road builders when the drivers are drunk at the wheel? | Michael Lieberman Alright, let's talk about the digital world we've built. It runs on open source software (OSS). Your phone, your cat's smart litter box, the thing that tells you pizza is on the way โ€“ all powered in l...

I recently wrote my thoughts on why we should focus more on securely consuming open source than trying to enforce the trustworthiness of devs mikeneeds.rest/license-to-n...
Since some folks aren't familiar with satire, this is satire, this is tongue in cheek, please don't take this too seriously :).

20.05.2025 19:46 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

I wonder how many people know you can install non-python code via pip and the like? I know most package managers support some level of arbitrary downloading of static content and most have also some level of arbitrary code execution on build/install.

15.05.2025 13:57 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0
Post image

The new #Cybersecurity Skills Framework maps 14 core job roles to real-world security skills.

โœ… Built by practitioners
โœ… Easy to customize
โœ… Standards-aligned

๐Ÿ”— Launch the free tool: cybersecurityframework.io
๐Ÿ“ฐ Read more: openssf.org/press-releas...

14.05.2025 13:16 โ€” ๐Ÿ‘ 0    ๐Ÿ” 3    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Post image

Giant Bomb lives! Fandom has sold the site to us and it is now fully independent and employee-owned. We'll see you all on Tuesday for the Giant Bombcast.

For more info right now, head over to www.giantbomb.com/join

10.05.2025 23:12 โ€” ๐Ÿ‘ 14751    ๐Ÿ” 3491    ๐Ÿ’ฌ 579    ๐Ÿ“Œ 782

polygon and giant bomb dead in the same week is just unfathomable

01.05.2025 18:27 โ€” ๐Ÿ‘ 3033    ๐Ÿ” 513    ๐Ÿ’ฌ 47    ๐Ÿ“Œ 19
Cat lying down with bread neck pillow

Cat lying down with bread neck pillow

Close up photo of orange cat wearing bread neck pillow

Close up photo of orange cat wearing bread neck pillow

Cat

23.04.2025 15:40 โ€” ๐Ÿ‘ 3    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

Because they clearly donโ€™t have a vision. Theyโ€™re ruining their flagship product to chase after something consumers by and large donโ€™t want.

18.04.2025 16:32 โ€” ๐Ÿ‘ 35    ๐Ÿ” 5    ๐Ÿ’ฌ 2    ๐Ÿ“Œ 1
Preview
TAG Security @ KubeCon EU 2025 - YouTube

Here's a playlist with the 7 KubeCon talks from TAG Security leads!

Seven!! ๐Ÿคฏ

@mikeneeds.rest @sublimi.no

www.youtube.com/playlist?lis...

16.04.2025 18:11 โ€” ๐Ÿ‘ 8    ๐Ÿ” 2    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Average Score in the session feedback: 10 out of 10.

Average Score in the session feedback: 10 out of 10.

This is it, @mikeneeds.rest.

The high water mark. The peak. The climax. The apex. It only goes down from here.

14.04.2025 16:37 โ€” ๐Ÿ‘ 3    ๐Ÿ” 1    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Post image

๐Ÿšจ OpenSSF community is heading to Denver for #OpenSSFCommunity Day NA 2025 on June 26!
AI security, SBOM tooling, real-world TTX, and more โ€” all in one day.
๐ŸŒ„ Co-located with #OSSummit
๐Ÿ›ก๏ธ Agenda is live โ€” register now!
๐Ÿ”— openssf.org/blog/2025/04...
#CyberSecurity #OpenSourceSecurity

09.04.2025 19:47 โ€” ๐Ÿ‘ 4    ๐Ÿ” 1    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

Love when companies post about being major contributors to #opensource projects after laying off a ton of core contributors to those projects!

08.04.2025 19:15 โ€” ๐Ÿ‘ 112    ๐Ÿ” 16    ๐Ÿ’ฌ 9    ๐Ÿ“Œ 0

I think itโ€™s more an LHR experience. That airport always just seems so disorganized across the board.

06.04.2025 23:45 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0

I got there early, it was pretty empty, went to the bathroom, got out and it was absolutely packed. No seats, people just standing around.

05.04.2025 10:50 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0

Iโ€™m around all day if anyone wants to chat more about it! Ping me on cncf slack or stop by the Kusari booth.

04.04.2025 09:07 โ€” ๐Ÿ‘ 2    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

Thanks! I appreciate the kind words.

04.04.2025 09:06 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Post image

A keynote about the EU Cyber Resilience Act at the #KubeCon #CloudNativeCon EU couldn't be more appropriate!

Happy to see it there and that we start collectively discussing the implications, how to comply, etc.!

Thanks @eddieknight.dev and @michaellieberman.bsky.social for bringing that topic ๐Ÿ™‚

04.04.2025 08:57 โ€” ๐Ÿ‘ 5    ๐Ÿ” 2    ๐Ÿ’ฌ 2    ๐Ÿ“Œ 0

Are you confused about the CRA? Check out @mikeneeds.rest and @eddieknight.dev's #KubeCon keynote on Friday morning.

02.04.2025 17:28 โ€” ๐Ÿ‘ 3    ๐Ÿ” 1    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 1
Video thumbnail

AOC: I want to live in an America that guarantees healthcare to every person.

I want to live in an America that has a living wage for every person

I want to live in an America where you have free speech to express yourself and not be afraid of being put on a list or deported.

21.03.2025 03:34 โ€” ๐Ÿ‘ 72224    ๐Ÿ” 14817    ๐Ÿ’ฌ 1230    ๐Ÿ“Œ 985

I'm looking for my next thing, and I need to move fast. I have several years of experience in developer relations from startups to the enterprise, and I'm particularly skilled at distilling complex topics into something easily understood by newbies and non-technical folks alike, on stage or off. 1/3

19.03.2025 16:47 โ€” ๐Ÿ‘ 349    ๐Ÿ” 210    ๐Ÿ’ฌ 6    ๐Ÿ“Œ 11

Resign.

14.03.2025 22:36 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

If you're wondering where we stand on politics coverage, we're not slowing down, or stopping anytime soon.

Some words from our Global Editorial Director @katie-drummond.bsky.social:

04.03.2025 16:12 โ€” ๐Ÿ‘ 2036    ๐Ÿ” 306    ๐Ÿ’ฌ 25    ๐Ÿ“Œ 15
Preview
How do Claude models perform on the 2025 AI puzzle competition? In this article I read 2.5 million characters output by Claude models to score them on the 3 problems I proposed in the previous articles.

After testing OpenAI and Gemini models on the 3 puzzle problems proposed in January on my blog, it is time to look at how Claude models answer them. Tested only versions 3 and 3.5 since I ran the scripts back in Jan, but even so the models performed quite well.

More on my blog: mihai.page/ai-2025-5

04.03.2025 01:48 โ€” ๐Ÿ‘ 2    ๐Ÿ” 2    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

@mikeneeds.rest is following 20 prominent accounts