#easyjson — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #easyjson, aggregated by home.social.
-
Contd. [en] Software Supply Chain or Software Politics
2/2
"Although no malicious functionality was identified, the case showed how #software #provenance and #governance relationships may create #strategic concerns that are not visible through traditional #technical #analysis." ...
"#AI systems such as #Mythos may transform how governments identify software vulnerabilities, but vulnerabilities are only part of the strategic picture. The lessons of #XZ, #SolarWinds, and easyjson suggest that some of the most consequential risks may not emerge from #vulnerable code, but from the software ecosystem through which code is governed, trusted, and delivered."
https://www.justsecurity.org/142183/hiding-geopolitics-software-supply-chains/
#supplychain #vulnerability #go #easyjson #vk #invasion #ukraine #russia
-
Contd. [en] Software Supply Chain or Software Politics
2/2
"Although no malicious functionality was identified, the case showed how #software #provenance and #governance relationships may create #strategic concerns that are not visible through traditional #technical #analysis." ...
"#AI systems such as #Mythos may transform how governments identify software vulnerabilities, but vulnerabilities are only part of the strategic picture. The lessons of #XZ, #SolarWinds, and easyjson suggest that some of the most consequential risks may not emerge from #vulnerable code, but from the software ecosystem through which code is governed, trusted, and delivered."
https://www.justsecurity.org/142183/hiding-geopolitics-software-supply-chains/
#supplychain #vulnerability #go #easyjson #vk #invasion #ukraine #russia
-
[en] Software Supply Chain or Software Politics
1/2
"In 2025, a #software supply chain #vulnerability was discovered in the widely used #Go programming library #easyjson that drew scrutiny due to its association with engineers from the #Russian technology company #VK. The package was hosted on GitHub by a MailRu account, which is owned by VK, and the VK CEO was sanctioned in 2022 by the U.S. Treasury following the Russian #invasion of #Ukraine, due to being or having been a leader or official of the Government of #Russia, amongst other reasons." ...
./2
-
[en] Software Supply Chain or Software Politics
1/2
"In 2025, a #software supply chain #vulnerability was discovered in the widely used #Go programming library #easyjson that drew scrutiny due to its association with engineers from the #Russian technology company #VK. The package was hosted on GitHub by a MailRu account, which is owned by VK, and the VK CEO was sanctioned in 2022 by the U.S. Treasury following the Russian #invasion of #Ukraine, due to being or having been a leader or official of the Government of #Russia, amongst other reasons." ...
./2
-
[en] Software Supply Chain or Software Politics
1/2
"In 2025, a #software supply chain #vulnerability was discovered in the widely used #Go programming library #easyjson that drew scrutiny due to its association with engineers from the #Russian technology company #VK. The package was hosted on GitHub by a MailRu account, which is owned by VK, and the VK CEO was sanctioned in 2022 by the U.S. Treasury following the Russian #invasion of #Ukraine, due to being or having been a leader or official of the Government of #Russia, amongst other reasons." ...
./2
-
[en] Software Supply Chain or Software Politics
1/2
"In 2025, a #software supply chain #vulnerability was discovered in the widely used #Go programming library #easyjson that drew scrutiny due to its association with engineers from the #Russian technology company #VK. The package was hosted on GitHub by a MailRu account, which is owned by VK, and the VK CEO was sanctioned in 2022 by the U.S. Treasury following the Russian #invasion of #Ukraine, due to being or having been a leader or official of the Government of #Russia, amongst other reasons." ...
./2
-
[en] Software Supply Chain or Software Politics
1/2
"In 2025, a #software supply chain #vulnerability was discovered in the widely used #Go programming library #easyjson that drew scrutiny due to its association with engineers from the #Russian technology company #VK. The package was hosted on GitHub by a MailRu account, which is owned by VK, and the VK CEO was sanctioned in 2022 by the U.S. Treasury following the Russian #invasion of #Ukraine, due to being or having been a leader or official of the Government of #Russia, amongst other reasons." ...
./2
-
#easyjson: a Golang package created by a Russian company with sanctioned CEO is found to be widely used in Helm, Istio, Kubernetes, ArgoCD, Grafana, Sigstore and across many US Government, Fortune 500 organisations:
👇
https://huntedlabs.com/the-russian-open-source-project-that-we-cant-live-without/ -
#easyjson: a Golang package created by a Russian company with sanctioned CEO is found to be widely used in Helm, Istio, Kubernetes, ArgoCD, Grafana, Sigstore and across many US Government, Fortune 500 organisations:
👇
https://huntedlabs.com/the-russian-open-source-project-that-we-cant-live-without/ -
#easyjson: a Golang package created by a Russian company with sanctioned CEO is found to be widely used in Helm, Istio, Kubernetes, ArgoCD, Grafana, Sigstore and across many US Government, Fortune 500 organisations:
👇
https://huntedlabs.com/the-russian-open-source-project-that-we-cant-live-without/ -
#easyjson: a Golang package created by a Russian company with sanctioned CEO is found to be widely used in Helm, Istio, Kubernetes, ArgoCD, Grafana, Sigstore and across many US Government, Fortune 500 organisations:
👇
https://huntedlabs.com/the-russian-open-source-project-that-we-cant-live-without/ -
#easyjson: a Golang package created by a Russian company with sanctioned CEO is found to be widely used in Helm, Istio, Kubernetes, ArgoCD, Grafana, Sigstore and across many US Government, Fortune 500 organisations:
👇
https://huntedlabs.com/the-russian-open-source-project-that-we-cant-live-without/ -
Researchers warn that open-source Go serialization tool #easyjson, owned by Russia’s #VKGroup and used by the US #DoD and others, poses a serious national security risk. #CyberSecurity #OpenSource #InfoSec #NationalSecurity #TechNews #DataSecurity #SupplyChainSecurity
-
Researchers warn that open-source Go serialization tool #easyjson, owned by Russia’s #VKGroup and used by the US #DoD and others, poses a serious national security risk. #CyberSecurity #OpenSource #InfoSec #NationalSecurity #TechNews #DataSecurity #SupplyChainSecurity
-
Researchers warn that open-source Go serialization tool #easyjson, owned by Russia’s #VKGroup and used by the US #DoD and others, poses a serious national security risk. #CyberSecurity #OpenSource #InfoSec #NationalSecurity #TechNews #DataSecurity #SupplyChainSecurity
-
Researchers warn that open-source Go serialization tool #easyjson, owned by Russia’s #VKGroup and used by the US #DoD and others, poses a serious national security risk. #CyberSecurity #OpenSource #InfoSec #NationalSecurity #TechNews #DataSecurity #SupplyChainSecurity
-
#Security Researchers Warn a Widely Used #OpenSource Tool Poses a 'Persistent' #Risk to the US
The open source software #easyjson is used by the US government and American companies. But its ties to Russia’s #VK , whose CEO has been #sanctioned , have researchers sounding the alarm.
#russia -
#Security Researchers Warn a Widely Used #OpenSource Tool Poses a 'Persistent' #Risk to the US
The open source software #easyjson is used by the US government and American companies. But its ties to Russia’s #VK , whose CEO has been #sanctioned , have researchers sounding the alarm.
#russia -
#Security Researchers Warn a Widely Used #OpenSource Tool Poses a 'Persistent' #Risk to the US
The open source software #easyjson is used by the US government and American companies. But its ties to Russia’s #VK , whose CEO has been #sanctioned , have researchers sounding the alarm.
#russia -
#Security Researchers Warn a Widely Used #OpenSource Tool Poses a 'Persistent' #Risk to the US
The open source software #easyjson is used by the US government and American companies. But its ties to Russia’s #VK , whose CEO has been #sanctioned , have researchers sounding the alarm.
#russia -
#Security Researchers Warn a Widely Used #OpenSource Tool Poses a 'Persistent' #Risk to the US
The open source software #easyjson is used by the US government and American companies. But its ties to Russia’s #VK , whose CEO has been #sanctioned , have researchers sounding the alarm.
#russia -
The #OpenSource software #easyjson is used by the US government and American companies. But its ties to Russia’s VK, whose CEO has been sanctioned, have researchers sounding the alarm.