home.social

#easyjson — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #easyjson, aggregated by home.social.

  1. Contd. [en] Software Supply Chain or Software Politics

    2/2

    "Although no malicious functionality was identified, the case showed how #software #provenance and #governance relationships may create #strategic concerns that are not visible through traditional #technical #analysis." ...

    "#AI systems such as #Mythos may transform how governments identify software vulnerabilities, but vulnerabilities are only part of the strategic picture. The lessons of #XZ, #SolarWinds, and easyjson suggest that some of the most consequential risks may not emerge from #vulnerable code, but from the software ecosystem through which code is governed, trusted, and delivered."

    justsecurity.org/142183/hiding

    #supplychain #vulnerability #go #easyjson #vk #invasion #ukraine #russia

  2. Contd. [en] Software Supply Chain or Software Politics

    2/2

    "Although no malicious functionality was identified, the case showed how #software #provenance and #governance relationships may create #strategic concerns that are not visible through traditional #technical #analysis." ...

    "#AI systems such as #Mythos may transform how governments identify software vulnerabilities, but vulnerabilities are only part of the strategic picture. The lessons of #XZ, #SolarWinds, and easyjson suggest that some of the most consequential risks may not emerge from #vulnerable code, but from the software ecosystem through which code is governed, trusted, and delivered."

    justsecurity.org/142183/hiding

    #supplychain #vulnerability #go #easyjson #vk #invasion #ukraine #russia

  3. [en] Software Supply Chain or Software Politics

    1/2

    "In 2025, a #software supply chain #vulnerability was discovered in the widely used #Go programming library #easyjson that drew scrutiny due to its association with engineers from the #Russian technology company #VK. The package was hosted on GitHub by a MailRu account, which is owned by VK, and the VK CEO was sanctioned in 2022 by the U.S. Treasury following the Russian #invasion of #Ukraine, due to being or having been a leader or official of the Government of #Russia, amongst other reasons." ...

    ./2

    #supplychain #ai #mythos #xz #solarwinds

  4. [en] Software Supply Chain or Software Politics

    1/2

    "In 2025, a #software supply chain #vulnerability was discovered in the widely used #Go programming library #easyjson that drew scrutiny due to its association with engineers from the #Russian technology company #VK. The package was hosted on GitHub by a MailRu account, which is owned by VK, and the VK CEO was sanctioned in 2022 by the U.S. Treasury following the Russian #invasion of #Ukraine, due to being or having been a leader or official of the Government of #Russia, amongst other reasons." ...

    ./2

    #supplychain #ai #mythos #xz #solarwinds