Open Source JobHub · @osjobhub
639 followers · 162 posts · Server fosstodon.org

Helping thousands of customers manage open source every day, Sonatype is on a mission to make software development easier. Browse open positions now on opensourcejobhub.com/company/7

#OSJobHub #sonatype #jobs #career #opensource #softwaresupplychain #engineer #sales #fullstack #firewall #security

Last updated 1 year ago

FOSSlife · @fosslife
2063 followers · 226 posts · Server fosstodon.org
Louis Lang · @louislang
108 followers · 200 posts · Server fosstodon.org

We are once again blocking a attack! Weve reporting on our efforts to protect and developers in recent weeks. Now it's 's turn.

Stopping authors publishing to πŸ¦€

blog.phylum.io/rust-malware-st

#softwaresupplychain #javascript #python #rust #malware #cratesio

Last updated 1 year ago

Matthias Schmidt · @mattication
28 followers · 241 posts · Server cloud-native.social
ToddySM · @toddysm
8 followers · 24 posts · Server twit.social

OK, provenance is supposed to prove how the software was created and by whom. Why am I missing the "whom" part of the provenance in every attestation that I pull?

#slsa #softwaresupplychain

Last updated 1 year ago

Jay Cuthrell · @jay
107 followers · 484 posts · Server cuthrell.com
Jay Cuthrell · @jay
106 followers · 462 posts · Server cuthrell.com
Jay Cuthrell · @jay
103 followers · 438 posts · Server cuthrell.com
Beth Pariseau · @BPariseau
311 followers · 126 posts · Server hachyderm.io
Amy B · @amyg12345
112 followers · 194 posts · Server hachyderm.io

Developer friends - If you happen to know Clojure and want to work on a great team working to improve the developer experience for the software supply chain, check out this opening on one of the teams that I work with: jobs.ashbyhq.com/docker/6368cc

#docker #hiring #developer #clojure #softwaresupplychain

Last updated 1 year ago

ToddySM · @toddysm
8 followers · 18 posts · Server twit.social

Spent the last week or so digging into data about and how the tools report those. Honestly, I don't want to be on the receiving end of those reports. Using the same approach for container vulnerabilities as for VM vulnerabilities is certainly not working.

#vulnerability #containers #softwaresupplychain

Last updated 1 year ago

VentureBeat :press: · @VentureBeat
69 followers · 55 posts · Server press.coop

The recent 3CX highlights that organizations can't afford to overlook the risks presented by attacks. See how to mitigate these kinds of attacks: venturebeat.com/security/3cx-d

#databreach #softwaresupplychain #press

Last updated 2 years ago

ToddySM · @toddysm
8 followers · 17 posts · Server twit.social

Managing for is not as simple as for VMs. It is hard to turn the wheel of an industry that has been doing this for years - needs a lot of education.

#vulnerabilities #containers #securesupplychain #security #softwaresupplychain

Last updated 2 years ago

VM (Vicky) Brasseur · @vmbrasseur
1567 followers · 1212 posts · Server social.vmbrasseur.com

πŸ“– Software Bill of Materials ( )

Those who wish to incorporate SBOMs into their processes must deal with the growing pains of an evolving ecosystem.

anonymoushash.vmbrasseur.com/2

#sbom #foss #opensource #softwaresupplychain

Last updated 2 years ago

FOSSlife · @fosslife
1605 followers · 88 posts · Server fosstodon.org
FOSSlife · @fosslife
1601 followers · 86 posts · Server fosstodon.org
OpenSSF · @openssf
157 followers · 43 posts · Server social.lfx.dev

Google somehow made catchy?

youtube.com/watch?v=NaR8WlLtPw

Also looks like there might be a few Cloud-Native Easter eggs in there...

#softwaresupplychain #SLSA

Last updated 2 years ago

FOSSlife · @fosslife
1569 followers · 74 posts · Server fosstodon.org
Ian Barker · @iandbarker
42 followers · 222 posts · Server newsie.social