photog.social is one of the many independent Mastodon servers you can use to participate in the fediverse.
🌈 An inclusive place for your photos, silliness, and convos! 🌈

Administered by:

Server stats:

249
active users

#openssf

0 posts0 participants0 posts today
OpenSSF<p>The <a href="https://social.lfx.dev/tags/OpenSSF" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>OpenSSF</span></a> Memory Safety SIG just released the <a href="https://social.lfx.dev/tags/MemorySafety" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>MemorySafety</span></a> Continuum!<br>Practical steps to tackle memory safety risks and strengthen <a href="https://social.lfx.dev/tags/OSSSecurity" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>OSSSecurity</span></a> — no matter where you are today.<br>👉 Read more: https://<a href="https://openssf.org/blog/2025/04/28/announcing-the-release-of-the-memory-safety-continuum/" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">openssf.org/blog/2025/04/28/an</span><span class="invisible">nouncing-the-release-of-the-memory-safety-continuum/</span></a></p>
OpenSSF<p>🔍 How can we better protect open source ecosystems from supply chain attacks?<br>Datadog, an <a href="https://social.lfx.dev/tags/OpenSSF" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>OpenSSF</span></a> member, advances security with <a href="https://social.lfx.dev/tags/GuardDog" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>GuardDog</span></a>, an open source tool detecting malicious packages in PyPI &amp; npm while contributing to a public threat dataset.<br>Read the blog: <a href="https://openssf.org/blog/2025/03/28/guarddog-strengthening-open-source-security-against-supply-chain-attacks/" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">openssf.org/blog/2025/03/28/gu</span><span class="invisible">arddog-strengthening-open-source-security-against-supply-chain-attacks/</span></a></p>
AndiMann<p>"<a href="https://masto.ai/tags/OpenSSF" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>OpenSSF</span></a> Defines Baseline for Securing <a href="https://masto.ai/tags/OpenSource" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>OpenSource</span></a> <a href="https://masto.ai/tags/Software" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Software</span></a>"</p><p>ICYMI, a new <a href="https://masto.ai/tags/OSS" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>OSS</span></a> project aims to standardize a <a href="https://masto.ai/tags/cybersecurity" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>cybersecurity</span></a> framework for OSS maintainers. </p><p>Love it! Coz my research has shown breaking down org boundaries has a very strong correlation with <a href="https://masto.ai/tags/DevOps" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>DevOps</span></a> success!</p><p><a href="https://devops.com/openssf-defines-baseline-for-securing-open-source-software/" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">devops.com/openssf-defines-bas</span><span class="invisible">eline-for-securing-open-source-software/</span></a></p>
AndiMann<p>"<a href="https://masto.ai/tags/OpenSSF" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>OpenSSF</span></a> Defines Baseline for Securing <a href="https://masto.ai/tags/OpenSource" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>OpenSource</span></a> <a href="https://masto.ai/tags/Software" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Software</span></a>"</p><p>ICYMI, a new <a href="https://masto.ai/tags/OSS" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>OSS</span></a> project aims to standardize a <a href="https://masto.ai/tags/cybersecurity" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>cybersecurity</span></a> framework for OSS maintainers. </p><p>Love it! Coz my research has shown breaking down org boundaries has a very strong correlation with <a href="https://masto.ai/tags/DevOps" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>DevOps</span></a> success!</p><p><a href="https://devops.com/openssf-defines-baseline-for-securing-open-source-software/" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">devops.com/openssf-defines-bas</span><span class="invisible">eline-for-securing-open-source-software/</span></a></p>
OpenSSF<p>🚀 OpenSSF is securing the open source ecosystem! With over 100 members and thousands of contributors, we’re shaping the future of secure software development.📥 Download the Annual Report to see our impact in 2024: <a href="https://hubs.la/Q0318XDQ0" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://</span><span class="">hubs.la/Q0318XDQ0</span><span class="invisible"></span></a> <a href="https://social.lfx.dev/tags/OSS" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>OSS</span></a> <a href="https://social.lfx.dev/tags/OpenSSF" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>OpenSSF</span></a> <a href="https://social.lfx.dev/tags/SoftwareSecurity" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>SoftwareSecurity</span></a></p>
Jan Schaumann<p>Excellent summary by Solar Designer on oss-security of what's happened in the last two weeks in response to the <a href="https://mstdn.social/tags/xz" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>xz</span></a> <a href="https://mstdn.social/tags/backdoor" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>backdoor</span></a>:</p><p><a href="https://www.openwall.com/lists/oss-security/2024/04/16/5" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">openwall.com/lists/oss-securit</span><span class="invisible">y/2024/04/16/5</span></a></p><p>Noteworthy:<br>- <a href="https://mstdn.social/tags/OpenSSH" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>OpenSSH</span></a> implemented systemd notification<br>- <a href="https://mstdn.social/tags/systemd" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>systemd</span></a> moves to dlopen(3) for some dependencies<br>- another detailed timeline at <a href="https://research.swtch.com/xz-timeline" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://</span><span class="">research.swtch.com/xz-timeline</span><span class="invisible"></span></a><br>- similar social engineering takeover attempts suspected in <a href="https://mstdn.social/tags/OpenJS" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>OpenJS</span></a> and <a href="https://mstdn.social/tags/OpenSSF" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>OpenSSF</span></a></p>
paris :1up:<p>heading to <a href="https://hachyderm.io/tags/openssf" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>openssf</span></a> community day as part of <a href="https://hachyderm.io/tags/ossna" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>ossna</span></a> <a href="https://hachyderm.io/tags/osssna" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>osssna</span></a> summit. come say hi to talk about <a href="https://hachyderm.io/tags/swift" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>swift</span></a>, <a href="https://hachyderm.io/tags/pkl" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>pkl</span></a>, the cool stuff i’m up to, or <a href="https://hachyderm.io/tags/opensource" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>opensource</span></a> governance today or throughout the week </p><p>hope to see you 💖</p>
Ed W8EMV<p>OpenSSF scorecard, wow, OMG, <span class="h-card" translate="no"><a href="https://hachyderm.io/@Rejekts" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>Rejekts</span></a></span> edition</p><p><span class="h-card" translate="no"><a href="https://hachyderm.io/@justaugustus" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>justaugustus</span></a></span> Stephen Augustus, Cisco</p><p><a href="https://whois.auggie.dev" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://</span><span class="">whois.auggie.dev</span><span class="invisible"></span></a></p><p>"Is the project safe"<br>"Is it maintained"<br>"Is there a security policy"<br>"Are there contributors from multiple organizations"<br>"Is the code good"</p><p>^^^ quick things, a few minutes</p><p>harder things:</p><p>"are there unfixed vulnerabilities"</p><p>much harder things</p><p>"is the project doing fuzzing"</p><p>---<br><a href="https://hachyderm.io/tags/OpenSSF" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>OpenSSF</span></a> Scorecard</p><p><a href="https://scorecard.dev/" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://</span><span class="">scorecard.dev/</span><span class="invisible"></span></a></p><p><a href="https://hachyderm.io/tags/rejekts2024" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>rejekts2024</span></a></p>
heise online (inoffiziell)Sigstore, der kostenlose Software-Signierungsdienst der OpenSSF, gilt nach Erreichen von Version 1.0 als offiziell reif für den produktiven Einsatz. <br><a href="https://www.heise.de/news/Software-Supply-Chain-Security-Sigstore-ist-einsatzreif-fuer-die-Produktion-7325958.html" rel="nofollow noopener" target="_blank">Software Supply Chain Security: Sigstore ist einsatzreif für die Produktion</a><br>
heise online (inoffiziell)Insgesamt 800.000 US-Dollar verteilt die OpenSSF an die Open-Source-Organisationen. Das Geld soll in Personal und Ressourcen für Security-Maßnahmen fließen. <br><a href="https://www.heise.de/news/Open-Source-Security-Finanzspritze-fuer-Eclipse-und-Python-Software-Foundation-7146434.html" rel="nofollow noopener" target="_blank">Open-Source-Security: Finanzspritze für Eclipse und Python Software Foundation</a><br>
Boiling Steam<p>AWS commits additional $10M to OpenSSF for open source security: <a href="https://aws.amazon.com/blogs/opensource/aws-investing-an-additional-10-million-in-open-source-supply-chain-security/" rel="nofollow noopener" target="_blank"><span class="invisible">https://</span><span class="ellipsis">aws.amazon.com/blogs/opensourc</span><span class="invisible">e/aws-investing-an-additional-10-million-in-open-source-supply-chain-security/</span></a> <a href="https://mastodon.cloud/tags/linux" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>linux</span></a> <a href="https://mastodon.cloud/tags/foss" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>foss</span></a> <a href="https://mastodon.cloud/tags/openssf" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>openssf</span></a> <a href="https://mastodon.cloud/tags/security" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>security</span></a></p>
heise online (inoffiziell)Die OpenSSF hat mit Package Analysis ein Projekt gestartet, das Open-Source-Pakete auf verdächtiges Verhalten untersucht. <br><a href="https://www.heise.de/news/Open-Source-Tool-spuert-Schadcode-in-Paketen-auf-npm-PyPI-und-Co-auf-7070895.html" rel="nofollow noopener" target="_blank">Open-Source-Tool spürt Schadcode in Paketen auf npm, PyPI und Co auf</a><br>
heise online (inoffiziell)Die Open Source Security Foundation wählt Node.js als erstes förderwürdiges Projekt im Rahmen der Alpha-Omega-Initiative aus und investiert 300.000 US-Dollar. <br><a href="https://www.heise.de/news/Finanzspritze-soll-Security-der-JavaScript-Runtime-Node-js-staerken-7060618.html" rel="nofollow noopener" target="_blank">Finanzspritze soll Security der JavaScript-Runtime Node.js stärken</a><br>
GambaJo<p><a href="https://social.tchncs.de/tags/Google" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Google</span></a> und <a href="https://social.tchncs.de/tags/Microsoft" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Microsoft</span></a> finanzieren <a href="https://social.tchncs.de/tags/OpenSource" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>OpenSource</span></a>-Sicherheitskampagne .</p><p>Das ist ein Dilemma. Einerseits tut eine Geldspritze der Community sicherlich gut. Andererseits haben so Konzerne großen Einfluss drauf, in welche Richtung die Reise geht.</p><p><a href="https://social.tchncs.de/tags/OpenSSF" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>OpenSSF</span></a> </p><p><a href="https://www.heise.de/news/Google-und-Microsoft-finanzieren-Open-Source-Sicherheitskampagne-6347070.html" rel="nofollow noopener" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">heise.de/news/Google-und-Micro</span><span class="invisible">soft-finanzieren-Open-Source-Sicherheitskampagne-6347070.html</span></a></p>
heise online (inoffiziell)Eine neue Initiative der OpenSSF ist das Ergebnis von Verhandlungen im Weißen Haus. 5 Millionen US-Dollar fließen in den Schutz von Open-Source-Anwendungen. <br><a href="https://www.heise.de/news/Google-und-Microsoft-finanzieren-Open-Source-Sicherheitskampagne-6347070.html" rel="nofollow noopener" target="_blank">Google und Microsoft finanzieren Open-Source-Sicherheitskampagne</a><br>
Dr. Roy Schestowitz (罗伊)<a class="hashtag" href="https://pleroma.site/tag/arduino" rel="nofollow noopener" target="_blank">#arduino</a> joins dodgy <a class="hashtag" href="https://pleroma.site/tag/openssf" rel="nofollow noopener" target="_blank">#openssf</a> (controlled by <a class="hashtag" href="https://pleroma.site/tag/microsoft" rel="nofollow noopener" target="_blank">#microsoft</a> 'moles') <a href="http://www.tuxmachines.org/node/143788#comment-26966" rel="nofollow noopener" target="_blank">http://www.tuxmachines.org/node/143788#comment-26966</a> see <a href="http://techrights.org/2020/10/30/openssf-microsoft/" rel="nofollow noopener" target="_blank">http://techrights.org/2020/10/30/openssf-microsoft/</a>
Dr. Roy Schestowitz (罗伊)With <a class="hashtag" href="https://pleroma.site/tag/microsoft" rel="nofollow noopener" target="_blank">#Microsoft</a> in Charge, <a class="hashtag" href="https://pleroma.site/tag/openssf" rel="nofollow noopener" target="_blank">#OpenSSF</a> Seems More Like It’s About <a class="hashtag" href="https://pleroma.site/tag/backdoors" rel="nofollow noopener" target="_blank">#BackDoors</a> — Not Real <a class="hashtag" href="https://pleroma.site/tag/security" rel="nofollow noopener" target="_blank">#Security</a> — Inside the <a class="hashtag" href="https://pleroma.site/tag/linuxfoundation" rel="nofollow noopener" target="_blank">#LinuxFoundation</a> <a href="http://techrights.org/2020/10/30/openssf-microsoft/" rel="nofollow noopener" target="_blank">http://techrights.org/2020/10/30/openssf-microsoft/</a>
Dr. Roy Schestowitz (罗伊)<a class="hashtag" href="https://pleroma.site/tag/openssf" rel="nofollow noopener" target="_blank">#OpenSSF</a> already infiltrated and now headed by <a class="hashtag" href="https://pleroma.site/tag/microsoft" rel="nofollow noopener" target="_blank">#microsoft</a> (the <a class="hashtag" href="https://pleroma.site/tag/nsa" rel="nofollow noopener" target="_blank">#nsa</a> back doors), so <a class="hashtag" href="https://pleroma.site/tag/linuxfoundation" rel="nofollow noopener" target="_blank">#linuxfoundation</a> is a total farce <a href="https://www.techrepublic.com/article/openssf-and-linux-foundation-offer-3-free-courses-on-developing-secure-open-source-software/" rel="nofollow noopener" target="_blank">https://www.techrepublic.com/article/openssf-and-linux-foundation-offer-3-free-courses-on-developing-secure-open-source-software/</a>
Dr. Roy Schestowitz (罗伊)Unfettered Freedom, Ep. 1 - <a class="hashtag" href="https://pleroma.site/tag/linux" rel="nofollow noopener" target="_blank">#Linux</a> 5.8, Linux Libre, <a class="hashtag" href="https://pleroma.site/tag/openssf" rel="nofollow noopener" target="_blank">#OpenSSF</a> , <a class="hashtag" href="https://pleroma.site/tag/libreoffice" rel="nofollow noopener" target="_blank">#LibreOffice</a> , the Fediverse <a href="https://www.youtube.com/watch?v=eWG7FboQj30" rel="nofollow noopener" target="_blank">https://www.youtube.com/watch?v=eWG7FboQj30</a>