www.liquibase.com/blog/liquiba...
www.liquibase.com/blog/liquiba...
It’s not well known outside of security research circles how often GitHub tokens leak.
Good news: No one at AWS (human or AI) merged in a dodgy PR, because...
Bad news: It was an exciting new exploited vulnerability in CodeBuild.
It’s not well known outside of security research circles how often GitHub tokens leak.
"Today, Valkey is maintained by a neutral foundation, ensuring no one company can take it away from open source."
Linux Foundation doesn't maintain Valkey. thenewstack.io/open-source-...
"Today, Valkey is maintained by a neutral foundation, ensuring no one company can take it away from open source."
Linux Foundation doesn't maintain Valkey. thenewstack.io/open-source-...
1) AI can help us build better products through rapid prototyping
2) Devs can declare their app's requirements to get better results from AI, close to production-grade code
1) AI can help us build better products through rapid prototyping
2) Devs can declare their app's requirements to get better results from AI, close to production-grade code
https://daniel.haxx.se/blog/2025/07/11/cybersecurity-risk-assessment-request/
#curl #cra
Unfortunately The Rules don't prohibit allocating a CVE for an identified weakness that was never in a released Product...
www.cve.org/resourcessup....
Unfortunately The Rules don't prohibit allocating a CVE for an identified weakness that was never in a released Product...
www.cve.org/resourcessup....
It's not *just* been Project Zero sending vulnerability disclosures to the maintainer.
gitlab.gnome.org/GNOME/libxml...
It's not *just* been Project Zero sending vulnerability disclosures to the maintainer.
gitlab.gnome.org/GNOME/libxml...
It's infrastructure that we generally take for granted in developed industrialized nations.
It's infrastructure that we generally take for granted in developed industrialized nations.
⬇️
www.kubernetes.dev/blog/2025/06...
⬇️
A zombie CVE from a CNA long dead, a CVSSv3 base score of 9.8 in the NVD, and a weakness that is intrinsic in the language ecosystem (do not deserialize Java from untrusted sources, people!!!).
github.com/spring-proje...
A zombie CVE from a CNA long dead, a CVSSv3 base score of 9.8 in the NVD, and a weakness that is intrinsic in the language ecosystem (do not deserialize Java from untrusted sources, people!!!).
github.com/spring-proje...
the membership.
i had a call with a friend who is executive director of another 501(c)3 and he drew me this picture for his org. i think it's a helpful reminder that the foundation serves the project.
that's the whole reason we're here.
I was one of the GNOME project’s first sysadmins, back in the days of a single CVS server running on a machine hosted at Red Hat’s office.
It’s amazing to see their journey to the cloud!
foundation.gnome.org/2025/06/10/g...
I was one of the GNOME project’s first sysadmins, back in the days of a single CVS server running on a machine hosted at Red Hat’s office.
It’s amazing to see their journey to the cloud!
foundation.gnome.org/2025/06/10/g...
this is emphatically not an open source license.
github.com/meta-llama/l...
Introducing Strands Agents, an Open Source AI Agents SDK
#AWS #OpenSource
Introducing Strands Agents, an Open Source AI Agents SDK
#AWS #OpenSource
By @fredericl.bsky.social
By @fredericl.bsky.social