The internet was on fire. 🔥
One small library affecting billions of systems.
Log4Shell was the biggest security vulnerability of all time.
Now, Log4J maintainer, Christian Grobmeier tells us what it felt like inside the flames 👉 github.blog/open-source/...
20.10.2025 18:37 — 👍 115 🔁 19 💬 5 📌 3
“Ignorance will break all software.”
Log4Shell’s one line of code broke the internet, and taught us all a lesson we can’t ignore. As Christian Grobmeier, maintainer of Log4J puts it: "Learning is the only cure for ignorance. So just keep learning."
20.10.2025 19:05 — 👍 0 🔁 1 💬 0 📌 0
Oh, congrats Kara!
19.10.2025 02:58 — 👍 1 🔁 0 💬 0 📌 0
Our plan for a more secure npm supply chain
GitHub is strengthening npm's security with stricter authentication, granular tokens, and enhanced trusted publishing.
Recent account takeovers and attacks on package registries are a wake-up call: it's time to raise the bar on authentication and secure publishing practices. Find out what npm is doing—and what steps you can take—to help secure the open source supply chain: github.blog/security/sup...
23.09.2025 16:11 — 👍 3 🔁 3 💬 1 📌 0
Yay!
03.09.2025 03:18 — 👍 1 🔁 0 💬 0 📌 0
When we see your smile for 2001 vs. Twilight, we know what the final result will be 😂
12.08.2025 04:40 — 👍 7 🔁 0 💬 0 📌 0
Hey security people, if you’re in Las Vegas, say hi!
If you want to talk open source security, or GitHub security products, I’d be happy to chat!
05.08.2025 16:37 — 👍 0 🔁 0 💬 0 📌 0
LinkedIn
This link will take you to a page that’s not on LinkedIn
Are you at Security BSides Las Vegas?
Our very own Madison Oliver is joining a panel on the evolving role of the CVE Program — from funding challenges to global coordination and new governance models.
ℹ️ pretalx.com/security-bsi...
🗓️ August 5 | ⏰ 13:00–13:45 PT
05.08.2025 07:38 — 👍 1 🔁 1 💬 0 📌 0
Anyone else going to #ossna and flight to Denver is delayed, without visibility?
23.06.2025 00:57 — 👍 0 🔁 0 💬 0 📌 0
Throw them a volleyball and see what happens. We need to know.
23.06.2025 00:54 — 👍 1 🔁 0 💬 0 📌 0
If you, a business, are reliant on an open source project to function it is YOUR responsibility to assess and ensure the health of that project by either contributing to it yourself or by using an alternative if project health cannot be guaranteed.
22.06.2025 22:11 — 👍 371 🔁 73 💬 7 📌 7
I am curious now … which one?
16.06.2025 01:30 — 👍 1 🔁 0 💬 0 📌 0
It’s free. It’s fun. It’s easy.
Learn about secure coding with the GitHub secure code game.
04.06.2025 05:44 — 👍 1 🔁 0 💬 0 📌 0
Depends. It would take me too long to arrive … I would make long pauses on the grass!
29.05.2025 05:55 — 👍 1 🔁 0 💬 0 📌 0
Security Best Practices for your Project
Strengthen your project’s future by building trust through essential security practices — from MFA and code scanning to safe dependency management and private vulnerability reporting.
Is your open source project built on a foundation of trust and security? 🛡️
Strengthen its future with essential practices like MFA, code scanning, safe dependency management, and private vulnerability reporting. 🔐
Learn how to implement these to protect your project and users with this guide. ⬇️
28.05.2025 20:21 — 👍 39 🔁 7 💬 0 📌 0
Season 3 of the GitHub Secure Code Game is coming — AI enters the chat 🤖🔥
Catchup with Season 1 and 2 at gh.io/secure-code-game
09.05.2025 16:02 — 👍 11 🔁 6 💬 0 📌 0
It’s a long time wish. I remember when he was invited by Macron to the French military parade (Bastille day) in 2017 he said he wanted to do a similar parade in the US.
02.05.2025 03:18 — 👍 1 🔁 0 💬 0 📌 0
So relatable. Thank you Ashley ❤️
27.04.2025 17:36 — 👍 1 🔁 0 💬 0 📌 0
YouTube video by Star Wars
ONE HOUR OF DANCING MON MOTHMA | Andor Season 2 | Disney+
Star Wars has released one hour of Mon Mothma dancing. #Andor www.youtube.com/watch?v=y6wL...
26.04.2025 21:51 — 👍 9 🔁 2 💬 0 📌 0
Agree. I think the best (worst?) episodes are when the plot is so plausible.
20.04.2025 01:45 — 👍 1 🔁 0 💬 0 📌 0
There is one sentence in all this non-sense that I agree with: « this film has to happen » - please DO IT!
17.04.2025 06:11 — 👍 1 🔁 0 💬 0 📌 0
Finally watched the first episode of The Studio. OMG this is hilarious. I must admit I had a hard time with the disrespect of my hero Marty … I’ll get over it, but it was a difficult moment.
15.04.2025 02:19 — 👍 0 🔁 0 💬 0 📌 0
In this demonstration I show the impact of CVE-2025-25291/CVE-2025-25292, an authentication bypass in ruby-saml used by high profile OSS projects such as GitLab. My team coordinated with both the ruby-saml maintainer and GitLab to get this vulnerability fixed and patches are available at gh.io/glfx
13.03.2025 16:08 — 👍 22 🔁 3 💬 1 📌 0
Alright but can you bring your image out of the room, or does it get wiped out in the elevator?
25.02.2025 05:30 — 👍 1 🔁 0 💬 1 📌 0
Does your outie code work on your innie’s machine?
24.02.2025 23:51 — 👍 11 🔁 0 💬 1 📌 0
Eng Lead @Microsoft, #Kubernetes SIG Auth chair, Founder @GarageDoorBuddy, EECS @UCBerkeley, open source, running distributed workloads at scale
Phd Histoire + ScPo
Fondateur @zistlit.bsky.social
P. @fabdecoloniale.bsky.social
Husband and father. 40th Governor of California. Former Lt. Governor of California. Former San Francisco Mayor. Personal account.
The account on classic and hit films. Details provided in our making of stories is direct from cast/crew or 3+ sources. Listen to our podcast for the best movie show out there at alltherightmovies.com
Official profile — OG Insta/X golf girl
Number 1 Purdue Fan
#2018 SI Swimsuit Model
Team: officialmanagementteampaige.org@gmail.com
OF: https://fans.ly/Onlypaigeaccount
Passes: passes.com/paigespiranac
Contents, Tips & Betting
Dad, husband, President, citizen. barackobama.com
southern roots, oakland blossoms 🌸
tech leader (ex google/slack/msft/github/dccc/parkwood)
@b.astrel.la’s weirder half
Never, ever be afraid to make some noise and get in good trouble, necessary trouble. -John Lewis
there will be typos
You know... the weird one.
Three Buddy Problem
https://securityconversations.com
Attorney, Proud Democrat, Anti Trump, Anti MAGA, Anti Musk; here to support democracy and freedom.
🇯🇲Culture critic, media & politics prof and researcher. I 💙 Art & Democracy. Writing: NPR, Boston Globe, IndieWire, LATimes, NYTimes, Washington Post, Oprah Daily, The Emancipator, Kirkus and BookPage. UNC J-School PhD. Linktr.ee/Cvbell
Romanista. Buy my book: https://www.penguinrandomhouse.com/books/665171/the-cruelty-is-the-point-by-adam-serwer/
Journalist and audio host.
Editor-in-chief, The Emancipator.
@theemancipator.org
criticism senior editor for @therumpus.net
submit work/pitches: therumpus.submittable.com/submit
she/her | sorayanadiamcdonald.com
The real jbouie. Columnist for the New York Times Opinion section. Co-host of the Unclear and Present Danger podcast. b-boy-bouiebaisse on TikTok. jbouienyt on Twitch. National program director of the CHUM Group.
Send me your mutual aid requests.
Fighter. Neo-Swoletariat.
Ex-Washington Post.
Substack: https://substack.com/@karenattiah?r=2bz6j&utm_medium=ios
Rogue Radical Professor: @resistanceschool.bsky.social
Race, Media + International Affairs Class: https://www.resistancesummerschool.com
Knight Professor of Journalism and Media Ethics at Washington&Lee U. Critic at Large, NPR. Blerd. Drummer. Author: Race-Baiter: How the Media Wields Dangerous Words to Divide a Nation. Media bloviator.
Government and policy writer. Views are my own. pbacon@tnr.com
The Emancipator is a digital magazine dedicated to examining and confronting racism and the inequities it creates. Visit our website: https://theemancipator.org