EU Regulations will change everything with Daniel Thompson
In this episode, we dive into the Product Liability Directive and Cyber Resilience Act with Daniel Thompson, CEO of Crab Nebula. The EUโs new legislative framework impacts manufacturers in ways we don...
I talked to Daniel Thompson-Yvetot on the latest episode of #OpenSourceSecurity
The main topic was the coming regulation for software developers. While there are carve outs for open source projects, what counts as an open source project isn't as clear as I thought it was.
28.07.2025 16:22 โ ๐ 0 ๐ 0 ๐ฌ 0 ๐ 0
Open source microprocessors with Jan Pleskac
In this episode Jan Pleskac, CEO and co-founder of Tropic Square, shares insights on the challenges and innovations in creating open and auditable hardware. While most hardware is very closed, Tropic ...
This #OpenSourceSecurity episode I chatted with Jan Pleskac from Tropic Square about open source microprocessors
I learned an incredible amount about how this all works, what Tropic Square is trying to do, and what we can start to expect in the future
21.07.2025 14:36 โ ๐ 0 ๐ 0 ๐ฌ 0 ๐ 0
Package URLs with Philippe Ombredanne
Iโm joined by Philippe Ombredanne, creator of the Package URL (PURL), to discuss the surprisingly complex and messy problem of simply identifying open source software packages. We dive into how PURLs ...
I chatted with Philippe Ombredanne about Package URLs, or PURLs. He created them, so he knows a thing or two.
We do complain about CPE quite a bit :)
But it's a really hard problem. It feels like a package identifier should be easy, but it's way harder than you think it is.
24.06.2025 17:55 โ ๐ 0 ๐ 0 ๐ฌ 0 ๐ 0
Hobbyist Maintainers with Thomas DePierre
Thomas DePierre joins Open Source Security to discuss the central idea from his blog post, โYou are all on the hobbyist maintainers turf now,โ exploring the massive disconnect between the corporate wo...
#OpenSourceSecurity chats with @Di4na@hachyderm.io about his blog post explaining hobbyist open source maintainers
Whatever you think you know about open source, you're going to learn something from this one
16.06.2025 13:40 โ ๐ 1 ๐ 0 ๐ฌ 0 ๐ 0
STIG automation with Aaron Lippold
I chat with Aaron Lippold, creator of MITREโs Security Automation Framework (SAF), to discuss how to escape the pain of manual STIG compliance. We explore the technical details of open-source tools li...
This episode of #OpenSourceSecurity I chat with Aaron Lippold from MITRE about #STIG automation (it's one big open source project)
STIG has historically been incredibly difficult
Thanks to #FedRAMP it's getting more attention than ever before and the work Aaron has been doing makes it a lot easier
09.06.2025 14:21 โ ๐ 1 ๐ 0 ๐ฌ 0 ๐ 0
Ecosyste.ms with Andrew Nesbitt
I recently chatted with Andrew Nesbitt about his project, Ecosyste.ms. Ecosyste.ms catalogs open source projects by tracking packages, dependencies, repositories, and more. With this dataset Andrew is...
This week #OpenSourceSecurity chats with @andrewnez.bsky.social about Ecosyste.ms
Ecosyste.ms is a massive collection of data about open source
It's an amazingly useful collection of data. If you're doing anything that needs information about open source you should check it out
02.06.2025 17:58 โ ๐ 4 ๐ 1 ๐ฌ 0 ๐ 0
Curl vs AI with Daniel Stenberg
Daniel Stenberg, the maintainer of Curl, discusses the increase in AI security reports that are wasting the time of maintainers. We discuss Curlโs new policy of banning the bad actors while establishi...
I chatted with @daniel.haxx.se about #Curl and the recent #AI happenings
It's always fun talking to Daniel, and I think there's a lot of good ideas in this one, especially on how to approach AI fueled contributions that aren't slop. And even suggestions on how to deal with slop contributions :)
27.05.2025 16:46 โ ๐ 9 ๐ 3 ๐ฌ 1 ๐ 0
Repository signing with Kairo De Araujo
I recently had a chat with Kairo about a project he maintains called Repository Service for TUF (RSTUF). We explain why TUF is tough (har har har), what RSTUF can do, and some of the challenges around...
I spoke with Kairo De Araujo about signing package repositories with RSTUF. It's one of those topics that's incredibly hard and I learn so much anytime I chat with an expert
Just because you're using a package mirror doesn't mean you shouldn't think about signing the artifacts
19.05.2025 15:22 โ ๐ 1 ๐ 0 ๐ฌ 0 ๐ 0
This was fun, make sure you check it out!
06.05.2025 14:32 โ ๐ 2 ๐ 1 ๐ฌ 0 ๐ 0
Embedded Security with Paul Asadoorian
Recently, I had the pleasure of chatting with Paul Asadoorian, Principal Security Researcher at Eclypsium and the host of the legendary Paulโs Security Weekly podcast. Our conversation dove into the o...
This episode of #OpenSourceSecurity I talk with @paulasadoorian.bsky.social about embedded security, but with an open source twist
It's open source all the way down. And old open source quite often. It's a really fun discussion, I learned a lot!
opensourcesecurity.io/2025/2025-05...
05.05.2025 16:21 โ ๐ 1 ๐ 1 ๐ฌ 0 ๐ 1
tj-actions with Endor Lab's Dimitri Stiliadis
Dimitri Stiliadis, CTO from Endor Labs, discusses the recent tj-actions/changed-files supply chain attack, where a compromised GitHub Action exposed CI/CD secrets. We explore the impressive multi-stag...
This episode of #OpenSourceSecurity I chat with Dimitri Stiliadis of @endorlabs.bsky.social about the tj-actions/changed-files backdoor
Endor did some great research into how many repos were affected and we cover some of the background on this attack. It's way weirder than you can imagine
28.04.2025 14:58 โ ๐ 2 ๐ 1 ๐ฌ 0 ๐ 0
It's always amusing when I tell someone to search for "buffer overflow" on GitHub and it returns a ton of things
20.04.2025 11:54 โ ๐ 0 ๐ 0 ๐ฌ 0 ๐ 0
I donโt think itโs a scam, but itโs not the best way to build trust
16.04.2025 12:33 โ ๐ 0 ๐ 0 ๐ฌ 0 ๐ 0
No names or details. Cool, cool
16.04.2025 10:17 โ ๐ 0 ๐ 0 ๐ฌ 1 ๐ 0
Ecosystem Funds is Generally Available
**Today Open Source Collective and ecosyste.ms are launching Funds supporting 291 Open Source Ecosystems. Unsurprisingly, we call them Ecosystem Funds.**
A few, short weeks before the holidays we announced Ecosystem Funds; a collaboration between Open Source Collective and ecosyste.ms that makes it easier to support your critical software dependencies.
### What are Ecosystem Funds?
Using billions of data points from ecosyste.ms weโve packaged millions of the most critical open source components into a few hundred Funds centred on a language, framework, or package, turning a process that can take months into a five minute conversation with your CTO.
### What have we been up to?
We launched with a $67,500 commitment from Sentry to the Rust, Python, Django and Javascript Ecosystems.
Weโve since distributed over 80% of the funds in 375 individual payments to 136 projects. Weโve sent money to projects on GitHub Sponsors, Patreon, BuyMeACoffee, Ko-fi, and of course Open Collective. We contacted hundreds maintainers, asking them to update their โfunding.ymlโ so anyone could support them, for those who didnโt we paid maintainers directly, again through Open Collective.
Weโre hoping to distribute the remaining funds this month which is why weโre launching Ecosystem Funds to the general public today.
### How does it work?
Once again for those in the back: Sponsor the technology you depend upon, weโll do the rest.
Find an ecosystem using our search and donate a single or recurring sponsorship. We handle everything else. Weโll direct your money (minus a 10% management fee) to maintainers, using the tools they have chosen to manage their finances. We allocate 100% of the donations in every fund with a balance of $1,000 or more, on a monthly basis. Every donation and payment is traceable through both Ecosystem Funds and Open Collective.
Donations can be made directly through funds.ecosyste.ms or, if you have an account, on Open Collective. Companies who wish to make a large donation, or start a Fund of their own, can request an Invoice from Open Source Collective โ who are already an approved vendor to most large open-source-supporting organisations.
### Whatโs next?
While weโre launching with nearly three hundred Funds weโre certain that weโll have missed more than a few ecosystems around your favourite framework, tool, or package, and weโre happy to add them. Just get in touch and weโll do some data wrangling to add it โ note that weโre not going to include a Fund for just the projects you work on, thatโs what GitHub Sponsors is for.
Weโre also hugely aware of the limitations of our approach. Weโre missing all the standards bodies, documentation projects, and foundations who support open source outside of the dependency graph. Weโre also missing domain-specific Funds, thereโs no climate, marine, aviation, or space-exploration based Funds to support.
To address this weโll be building ways for communities (and corporations) to package their own Ecosystem Fund, and support it.
### โฆ Just one more thing
While building a service to support thousands of the most critical software components might be enough for some, itโs not for us. Over the coming months weโll be building a tool to track all your open source โinvestmentsโ, to better understand the impact your money is having on the projects you depend on most.
Ecosystem Funds is Generally Available https://blog.ecosyste.ms/2025/04/04/ecosystem-funds-ga.html
07.04.2025 17:19 โ ๐ 10 ๐ 10 ๐ฌ 0 ๐ 2
cargo-semver-checks has a *security* impact on Rust too.
Make version upgrades less painful, and people upgrade more! No more "we got hacked because we were running 5 year old unpatched software." More on this in the podcast ๐
07.04.2025 14:11 โ ๐ 8 ๐ 2 ๐ฌ 0 ๐ 0
cargo-semver-checks with Predrag Gruevski
Cargo Semver Checks is a Rust tool by Predrag Gruevski that is tackling the problem of broken dependencies that cost developers time when trying to upgrade dependencies. Predragโs work shows how autom...
This episode of #OpenSourceSecurity talks to @predr.ag about cargo-semver-checks
it's a #Rust tool that can help you figure out if you broke #semver
We also touch on the difficulty of detecting breaking changes, sustainable open source, and what's to come for semver checking
07.04.2025 13:37 โ ๐ 3 ๐ 0 ๐ฌ 0 ๐ 1
Co-founder and journalist at 404media.co
I read every email
https://github.com/ljharb
software engineer/nerd/teacher/will try anything once; surgeon with git rebase. @TC39 ex @Coinbase/@Airbnb/@Twitter/@MobBase. Fav punctuation โธฎ, scent petrichor
N9HAK, Dad, CyberSecurity, National Anthem Singer, Ninja Warrior, Trainiac, "Life is like an Oreo cookie, Pass the beer nuts", Theatre person
Blog: siliconshecky.com
hi this is @annierau.bsky.social! my DMs are open
Consultant, developer, evangelist, gardener. Co-founder of SBOMEurope.eu. Team lead of OWASP Transparency Exchange API (Projekt Koala). Member of CycloneDX industry working group, OWASP SBOM Forum. IETF and much more.
the foundation of my radical cause in my increasingly old age is that I want everyone to be ok.
Open source program person, JD, working on an LL.M in cybercrime, cybersecurity and international law
All-end developer and software gardener
aka Chief Technical Architect at Porsche Informatik.
๐ derkoe.dev
The dumbest and weirdest video game show on YouTube since 2007 | ๐ง stopskeletons@gmail.com
21 | she/her๐ณ๏ธโโง๏ธ | the only person in scotland to care about the FDS release of SMB2 | game collector | retro tech enthusiast
Staff writer at The Atlantic. Cat guy, democracy defender. Actor for a day on Succession, Jeopardy champ. Atlantic Starter Pack: go.bsky.app/NVbMa2Y
Author of cargo-semver-checks & Trustfall // https://github.com/sponsors/obi1kenobi // https://predr.ag/blog // ex Principal Eng @Kensho // MIT alum // https://hachyderm.io/@predrag // not from around here ๐ฒ๐ฐ // he-him
A Podcast around #Meshtastic and related mesh technologies.
I'm Codey, Just your Everyday Cyber Robinhood
Step 1: Take Big Org $$$
Step 2: Provide Security for their EOL OSS
Step 3: Give $$$ back to Open Source Creators and Maintainers
Proudly given $M,ILL,ION.S back to the Open Source Community
Boldly going where no Jedi has beamed before. Earth is our spaceship.
#AltGov
DOJ executive providing honest commentary on American politics. Opinions are my own and do not represent those of my employer. โMorganโ in the book โWe Are #AltGovโ by Dr. Amanda Sturgill. (I have NO financial ties to the book)
Twitter: @altScalesOfJust
OG AltGov. thatโs now here.
Make good choices! #swiftie #altgov #nafo #accidentaldiplomat