home.social
  1. 🚀 The @openjsf now has an RSS feed! Subscribe to get notified about new CVEs across all OpenJS projects as they are published.

    cna.openjsf.org/feed.xml

  2. 🔐 7 out of 10 of reports for and are invalid.

    The current spike is LLM-generated noise eating volunteers' time that should go to releases, features, and real bugs.

    Our tooling wasn't designed for this volume. Every report still needs to be read, cross-referenced, and responded to. We need better tooling and support to sustain this.

  3. 🔖 The latest issue of my is live, issue 012.

    February in numbers: 5 CVEs patched across & , 5 releases shipped, and a hard conversation about whether security triage is still sustainable in the age of AI 🔐

    blog.ulisesgascon.com/newslett

  4. 🔖 The latest issue of my is out, issue 010.

    Stories from reviving & reimagining , secure publishing on , why doesn’t fail because of code, backlog updates &

    blog.ulisesgascon.com/newslett

  5. Just shipped a new newsletter to my GitHub Sponsors! 🎁

    This one includes my latest talk, secure publishing research, updates, improvements, and a bunch of ecosystem news.

    It will be public soon, but you can read it early and support my OSS work here:
    github.com/sponsors/UlisesGasc

  6. 🚀 Great news!

    deployments for @openssf are running smoothly and PR preview environments are fully live 🎉

    It’s the perfect time to get involved. We have plenty of good-first-issues and help-wanted items ready for you: github.com/ossf/scorecard-weba

    Your contributions are welcome. Come build with us ❤️‍🔥

  7. 🚀 Recent updates focus on stronger & posture!

    ✅ CI support expanded (Node 4 → 25)

    🌐 New browser tests via

    📝 Docs now have dedicated CI

    🔒 Added escalation policy

    📊 Reporting

    🧯 New Incident Response Plan ()

    🧠 Threat Model inspired by &

    More details: blog.ulisesgascon.com/the-futu

  8. 🍿 Exciting news! The Foundation Collaboration Space holds its first meeting next week.

    A community hub where developers, maintainers and policy thinkers explore how connects billions of people to .

    github.com/openjs-foundation/a

  9. 🗞️ Exciting news: now has a Security Working Group!

    We’ll:
    👉 Define triage & policies
    👉 Guide secure plugin development
    👉 Improve report processes
    👉 Promote best practices
    👉 Support & initiatives

    github.com/webpack/security-wg

  10. 🎉 Boa notícia! "Dominando o " agora tem uma versão para toda a comunidade de fala portuguesa! 📚

    Aprenda , , , , e para criar escaláveis.

    novatec.com.br/livros/dominand

  11. Spent the last few weeks laser-focused on for , and I’m excited to introduce the ecosystem!

    Discover two community-built tools and in action (demo included): openpathfinder.com/blog/welcome

  12. 📦 I just released ossf/[email protected] 🎉🙌🥳

    The project has been donated to the @openssf making it an official tool in the ecosystem.

    🍿Check out the release details: github.com/marketplace/actions

  13. I am very proud to announce that the Monitor tool that I created, it will be part of the @openssf as I donated the project.

    I will continue working on it, so be ready for the next release!

    More details about the journey: github.com/ossf/scorecard-moni

  14. Yes! I am very proud to announce that the Monitor tool that I created, it will be part of the @openssf as I donated the project.

    I will continue working on it, so be ready for the next release!

    More info: github.com/marketplace/actions

  15. 🎉 OpenSSF Scorecard Monitor version 2.0.0-beta7 is out!.

    Simplify tracking in your organization with automated and reports, plus optional issue .

    Check it out:
    github.com/marketplace/actions