#easyjson — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #easyjson, aggregated by home.social.
-
Contd. [en] Software Supply Chain or Software Politics
2/2
"Although no malicious functionality was identified, the case showed how #software #provenance and #governance relationships may create #strategic concerns that are not visible through traditional #technical #analysis." ...
"#AI systems such as #Mythos may transform how governments identify software vulnerabilities, but vulnerabilities are only part of the strategic picture. The lessons of #XZ, #SolarWinds, and easyjson suggest that some of the most consequential risks may not emerge from #vulnerable code, but from the software ecosystem through which code is governed, trusted, and delivered."
https://www.justsecurity.org/142183/hiding-geopolitics-software-supply-chains/
#supplychain #vulnerability #go #easyjson #vk #invasion #ukraine #russia
-
Contd. [en] Software Supply Chain or Software Politics
2/2
"Although no malicious functionality was identified, the case showed how #software #provenance and #governance relationships may create #strategic concerns that are not visible through traditional #technical #analysis." ...
"#AI systems such as #Mythos may transform how governments identify software vulnerabilities, but vulnerabilities are only part of the strategic picture. The lessons of #XZ, #SolarWinds, and easyjson suggest that some of the most consequential risks may not emerge from #vulnerable code, but from the software ecosystem through which code is governed, trusted, and delivered."
https://www.justsecurity.org/142183/hiding-geopolitics-software-supply-chains/
#supplychain #vulnerability #go #easyjson #vk #invasion #ukraine #russia
-
[en] Software Supply Chain or Software Politics
1/2
"In 2025, a #software supply chain #vulnerability was discovered in the widely used #Go programming library #easyjson that drew scrutiny due to its association with engineers from the #Russian technology company #VK. The package was hosted on GitHub by a MailRu account, which is owned by VK, and the VK CEO was sanctioned in 2022 by the U.S. Treasury following the Russian #invasion of #Ukraine, due to being or having been a leader or official of the Government of #Russia, amongst other reasons." ...
./2
-
[en] Software Supply Chain or Software Politics
1/2
"In 2025, a #software supply chain #vulnerability was discovered in the widely used #Go programming library #easyjson that drew scrutiny due to its association with engineers from the #Russian technology company #VK. The package was hosted on GitHub by a MailRu account, which is owned by VK, and the VK CEO was sanctioned in 2022 by the U.S. Treasury following the Russian #invasion of #Ukraine, due to being or having been a leader or official of the Government of #Russia, amongst other reasons." ...
./2