home.social

#openjs — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #openjs, aggregated by home.social.

fetched live
  1. 🚀 Recent updates focus on stronger & posture!

    ✅ CI support expanded (Node 4 → 25)

    🌐 New browser tests via

    📝 Docs now have dedicated CI

    🔒 Added escalation policy

    📊 Reporting

    🧯 New Incident Response Plan (#IRP)

    🧠 Threat Model inspired by &

    More details: blog.ulisesgascon.com/the-futu

  2. 🚀 Recent #Lodash updates focus on stronger #CI & #security posture!

    ✅ CI support expanded (Node 4 → 25)

    🌐 New browser tests via #Playwright

    📝 Docs now have dedicated CI

    🔒 Added #OpenJS #CNA escalation policy

    📊 Reporting #OSSF #Scorecard

    🧯 New Incident Response Plan (#IRP)

    🧠 Threat Model inspired by #Express & #Webpack

    More details: blog.ulisesgascon.com/the-futu

  3. 🍿 Exciting news! The Foundation Collaboration Space holds its first meeting next week.

    A community hub where developers, maintainers and policy thinkers explore how connects billions of people to .

    github.com/openjs-foundation/a

  4. 🍿 Exciting news! The #OpenJS Foundation #AI Collaboration Space holds its first meeting next week.

    A community hub where developers, maintainers and policy thinkers explore how #JavaScript connects billions of people to #AI.

    github.com/openjs-foundation/a

  5. 🗞️ Exciting news: now has a Security Working Group!

    We’ll:
    👉 Define triage & policies
    👉 Guide secure plugin development
    👉 Improve report processes
    👉 Promote best practices
    👉 Support & initiatives

    github.com/webpack/security-wg

  6. 🗞️ Exciting news: #webpack now has a Security Working Group!

    We’ll:
    👉 Define triage & policies
    👉 Guide secure plugin development
    👉 Improve report processes
    👉 Promote best practices
    👉 Support #OpenJS & #OpenSSF initiatives

    github.com/webpack/security-wg

  7. I’ll be in #London tomorrow with some time to kill. Feels like a waste to just work in my hotel. If you want to meet up or have tips, let me know!

    Attending the #OpenJS Vizualization Summit at the Microsoft offices Tuesday and Wednesday. Mostly as an excuse to meet my #MapLibre colleagues. 🙂

  8. I’ll be in #London tomorrow with some time to kill. Feels like a waste to just work in my hotel. If you want to meet up or have tips, let me know!

    Attending the #OpenJS Vizualization Summit at the Microsoft offices Tuesday and Wednesday. Mostly as an excuse to meet my #MapLibre colleagues. 🙂

  9. Open sourcerers say suspected #xz-style attacks continue to target #maintainers
    #SocialEngineering patterns spotted across range of popular projects
    Higher-ups at the #OpenJS Foundation and #OpenSource Security Foundation (#OpenSSF) believe the attempt to plant a #backdoor into #Linux's xz data compression library "may not be an isolated incident" given their recent observations.
    theregister.com/2024/04/16/xz_

  10. Open sourcerers say suspected #xz-style attacks continue to target #maintainers
    #SocialEngineering patterns spotted across range of popular projects
    Higher-ups at the #OpenJS Foundation and #OpenSource Security Foundation (#OpenSSF) believe the attempt to plant a #backdoor into #Linux's xz data compression library "may not be an isolated incident" given their recent observations.
    theregister.com/2024/04/16/xz_

  11. Excellent summary by Solar Designer on oss-security of what's happened in the last two weeks in response to the #xz #backdoor:

    openwall.com/lists/oss-securit

    Noteworthy:
    - #OpenSSH implemented systemd notification
    - #systemd moves to dlopen(3) for some dependencies
    - another detailed timeline at research.swtch.com/xz-timeline
    - similar social engineering takeover attempts suspected in #OpenJS and #OpenSSF

  12. Excellent summary by Solar Designer on oss-security of what's happened in the last two weeks in response to the #xz #backdoor:

    openwall.com/lists/oss-securit

    Noteworthy:
    - #OpenSSH implemented systemd notification
    - #systemd moves to dlopen(3) for some dependencies
    - another detailed timeline at research.swtch.com/xz-timeline
    - similar social engineering takeover attempts suspected in #OpenJS and #OpenSSF

  13. This exemplifies the unique network of human beings in and around Open Source that makes it so _resilient_.

    With OSS, people are curious. They are empowered to take a peek under the hood. To share what they find with others. To ignore organizational and architectural boundaries.

    #OpenSource #FreeSoftware #FOSS #OSS #InfoSec #XZ #OpenJS #OpenSSF #Linux #SOSSCommunity

    twitter.com/postgresperf/statu

  14. This exemplifies the unique network of human beings in and around Open Source that makes it so _resilient_.

    With OSS, people are curious. They are empowered to take a peek under the hood. To share what they find with others. To ignore organizational and architectural boundaries.

    #OpenSource #FreeSoftware #FOSS #OSS #InfoSec #XZ #OpenJS #OpenSSF #Linux #SOSSCommunity

    twitter.com/postgresperf/statu

  15. Free and Open Source software communities are anything *but* “fragile” in light of recent failed attacks.

    They are smart. They are vigilant. They are resilient.

    But they also need support from institutions given the resources attackers may have.

    #OpenSource #FreeSoftware #FOSS #OSS #InfoSec #XZ #OpenJS #OpenSSF #Linux #SOSSCommunity

  16. Free and Open Source software communities are anything *but* “fragile” in light of recent failed attacks.

    They are smart. They are vigilant. They are resilient.

    But they also need support from institutions given the resources attackers may have.

    #OpenSource #FreeSoftware #FOSS #OSS #InfoSec #XZ #OpenJS #OpenSSF #Linux #SOSSCommunity

  17. Open Source Security (OpenSSF) and OpenJS Foundations Issue Alert for Social Engineering Takeovers of Open Source Projects

    XZ Utils cyberattack likely not an isolated incident

    #OpenSource #FreeSoftware #FOSS #OSS #InfoSec #XZ #OpenJS #OpenSSF #Linux

    openjsf.org/blog/openssf-openj

  18. Open Source Security (OpenSSF) and OpenJS Foundations Issue Alert for Social Engineering Takeovers of Open Source Projects

    XZ Utils cyberattack likely not an isolated incident

    #OpenSource #FreeSoftware #FOSS #OSS #InfoSec #XZ #OpenJS #OpenSSF #Linux

    openjsf.org/blog/openssf-openj

  19. How does Wikimedia approach security and performance?

    We're quite selective in our dependencies and often audit the sources ourselves. Progressive enhancement makes for a blazing fast and accessible site, and, I argue, it's also the cheaper choice in the long run!

    timotijhof.net/posts/2023/wiki

  20. How does Wikimedia approach security and performance?

    We're quite selective in our dependencies and often audit the sources ourselves. Progressive enhancement makes for a blazing fast and accessible site, and, I argue, it's also the cheaper choice in the long run!

    timotijhof.net/posts/2023/wiki

    #mediawiki #Wikipedia #OpenJS #infosec #webperf #foss #floss

  21. #CrabLang (a fork of #Rust), reminds me of Io.js, which forked from #Node.js because corporate sponsors were holding the language back. Due to extreme bureaucratic caution, adding new JavaScript features to Node.js took a very long time (years!).

    The good thing is that this led to the formation of the Node.js Foundation and, eventually, the #OpenJS Foundation. The result is a platform with better governance and faster iteration. #Io.js and #Node.js were merged in the end.

  22. #CrabLang (a fork of #Rust), reminds me of Io.js, which forked from #Node.js because corporate sponsors were holding the language back. Due to extreme bureaucratic caution, adding new JavaScript features to Node.js took a very long time (years!).

    The good thing is that this led to the formation of the Node.js Foundation and, eventually, the #OpenJS Foundation. The result is a platform with better governance and faster iteration. #Io.js and #Node.js were merged in the end.

  23. :flowforge: #FlowForge is joining the #OpenJS Foundation

    FlowForge makes Node-RED available for the enterprise, and lets you manage your Node-RED instances all in one place. We're excited to see what they will bring to the OpenJS community.

    :nodered: #NodeRED

    openjsf.org/announcement/2022/

  24. :flowforge: #FlowForge is joining the #OpenJS Foundation

    FlowForge makes Node-RED available for the enterprise, and lets you manage your Node-RED instances all in one place. We're excited to see what they will bring to the OpenJS community.

    :nodered: #NodeRED

    openjsf.org/announcement/2022/