vmbrasseur, to opensource
@vmbrasseur@social.vmbrasseur.com avatar

Reviewing some content in this ante-penultimate (!!!) chapter of _Business Success with _ and suspect I may have been in an "I'm sick of this crap" mood when I wrote this.

Definitely keeping it in the book.

https://fossbiz.com

vmbrasseur, to opensource
@vmbrasseur@social.vmbrasseur.com avatar

I'll be in Seattle next week (Apr 15-18). Have questions about how your company uses/releases , about it's management, or about its overall /positioning?

Let's talk. I'm now scheduling free advice sessions. Grab your time here: https://calendly.com/vmbrasseur/ossna-2024-seattle-meetup

boosts appreciated!

underlap, to random
@underlap@fosstodon.org avatar

Given the news of the xz backdoor, may I recommend this seminal paper from Ken Thompson's 1984 Turing Award lecture showing how a compiler with no backdoors in the source code can nevertheless propagate a backdoor.

Reflections on trusting trust | the morning paper
https://blog.acolyer.org/2016/09/09/reflections-on-trusting-trust/

Anachron, to random German
@Anachron@fosstodon.org avatar

Holy canneloni, the / issue seems to be around one year in the making.

I guess we really need a way how to prevent new people from doing harm to .

https://news.ycombinator.com/item?id=39866936

underlap,
@underlap@fosstodon.org avatar

@Anachron Same problem exists for proprietary software too. doesn't get to have all the fun.

sebastian, to php
@sebastian@phpc.social avatar

PHPUnit 8.5.35, PHPUnit 9.6.14, and PHPUnit 10.5.0 are the first versions of PHPUnit where composer.lock is under version control and part of the (signed, of course) release tag.

The PHAR binary of PHPUnit now has a --composer-lock CLI option that prints the composer.lock that was used to build the PHAR.

Making the build of PHPUnit's PHAR reproducible is another step towards a more secure .

sebastian,
@sebastian@phpc.social avatar

Interested in the #SoftwareSupplyChain of #PHP projects?

Have a look at this presentation:

https://thephp.cc/presentations/the-php-stacks-supply-chain?ref=mastodon

fosslife, to security
@fosslife@fosstodon.org avatar
fosslife, to security
@fosslife@fosstodon.org avatar

Sonatype's 9th annual State of the Software Supply Chain report shows a rise in attacks https://www.fosslife.org/open-source-software-supply-chain-attacks-rise

BishopFox, to Cybersecurity

Be proactive about your security. A well-planned strategy can prevent costly breaches before they happen. Check out our write-up for more info. https://bfx.social/3r6wqzl

fosslife, to security
@fosslife@fosstodon.org avatar

New roadmap for open source security released by the Cybersecurity & Infrastructure Security Agency https://www.fosslife.org/cisa-lays-out-roadmap-open-source-software-security

fosslife, to opensource
@fosslife@fosstodon.org avatar
fosslife, to random
@fosslife@fosstodon.org avatar
fosslife, to random
@fosslife@fosstodon.org avatar
fosslife, to programming
@fosslife@fosstodon.org avatar
  • All
  • Subscribed
  • Moderated
  • Favorites
  • provamag3
  • khanakhh
  • mdbf
  • InstantRegret
  • Durango
  • Youngstown
  • rosin
  • slotface
  • thenastyranch
  • osvaldo12
  • ngwrru68w68
  • kavyap
  • cisconetworking
  • DreamBathrooms
  • megavids
  • magazineikmin
  • cubers
  • vwfavf
  • modclub
  • everett
  • ethstaker
  • Leos
  • tacticalgear
  • normalnudes
  • tester
  • GTA5RPClips
  • anitta
  • JUstTest
  • All magazines