#openjs — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #openjs, aggregated by home.social.
-
OpenJS Foundation Security Program: Annual Report 2025, by @openjsf:
-
OpenJS Foundation Security Program: Annual Report 2025, by @openjsf:
-
Lit Is Joining the OpenJS Foundation, by @lit.dev:
-
Lit Is Joining the OpenJS Foundation, by @lit.dev:
-
🚀 Recent #Lodash updates focus on stronger #CI & #security posture!
✅ CI support expanded (Node 4 → 25)
🌐 New browser tests via #Playwright
📝 Docs now have dedicated CI
🔒 Added #OpenJS #CNA escalation policy
📊 Reporting #OSSF #Scorecard
🧯 New Incident Response Plan (#IRP)
🧠 Threat Model inspired by #Express & #Webpack
More details: https://blog.ulisesgascon.com/the-future-of-lodash
-
🚀 Recent #Lodash updates focus on stronger #CI & #security posture!
✅ CI support expanded (Node 4 → 25)
🌐 New browser tests via #Playwright
📝 Docs now have dedicated CI
🔒 Added #OpenJS #CNA escalation policy
📊 Reporting #OSSF #Scorecard
🧯 New Incident Response Plan (#IRP)
🧠 Threat Model inspired by #Express & #Webpack
More details: https://blog.ulisesgascon.com/the-future-of-lodash
-
Welcome Rafael Gonzaga to the #OpenJS #CNA team! 👏 👏 👏
https://github.com/openjs-foundation/security-collab-space/pull/297
-
Welcome Rafael Gonzaga to the #OpenJS #CNA team! 👏 👏 👏
https://github.com/openjs-foundation/security-collab-space/pull/297
-
🍿 Exciting news! The #OpenJS Foundation #AI Collaboration Space holds its first meeting next week.
A community hub where developers, maintainers and policy thinkers explore how #JavaScript connects billions of people to #AI.
-
🍿 Exciting news! The #OpenJS Foundation #AI Collaboration Space holds its first meeting next week.
A community hub where developers, maintainers and policy thinkers explore how #JavaScript connects billions of people to #AI.
-
-
-
XZ 的後門事件,以及 OpenJS Foundations 也遇到類似的問題
XZ 的後門事件從暴發出來也已經一個多月了,大多數的證據也都分析的差不多了,是差不多可以回顧一下...
#Computer #Murmuring #Security #Software #backdoor #community #engineering #foundations #maintainer #open #openjs #security #social #source #xz
-
Open sourcerers say suspected #xz-style attacks continue to target #maintainers
#SocialEngineering patterns spotted across range of popular projects
Higher-ups at the #OpenJS Foundation and #OpenSource Security Foundation (#OpenSSF) believe the attempt to plant a #backdoor into #Linux's xz data compression library "may not be an isolated incident" given their recent observations.
https://www.theregister.com/2024/04/16/xz_style_attacks_continue/ -
Open sourcerers say suspected #xz-style attacks continue to target #maintainers
#SocialEngineering patterns spotted across range of popular projects
Higher-ups at the #OpenJS Foundation and #OpenSource Security Foundation (#OpenSSF) believe the attempt to plant a #backdoor into #Linux's xz data compression library "may not be an isolated incident" given their recent observations.
https://www.theregister.com/2024/04/16/xz_style_attacks_continue/ -
Following the XZ Utils attack, @openssf and @openjsf urge open source project maintainers to be alert for social engineering takeover attempts https://www.admin-magazine.com/News/OpenSSF-Issues-Guidance-to-Help-Prevent-Social-Engineering-Attacks #security #OpenSource #SocialEngineering #XZattack #OpenSFF #OpenJS #LinuxFoundation #2FA #MFA #phishing
-
Following the XZ Utils attack, @openssf and @openjsf urge open source project maintainers to be alert for social engineering takeover attempts https://www.admin-magazine.com/News/OpenSSF-Issues-Guidance-to-Help-Prevent-Social-Engineering-Attacks #security #OpenSource #SocialEngineering #XZattack #OpenSFF #OpenJS #LinuxFoundation #2FA #MFA #phishing
-
Open Source Security (#OpenSSF) and #OpenJS Warn of Fake #Maintainers Targeting #JavaScript Projects
Alarming #socialengineering attacks target critical #opensource projects! Learn how to protect your project and the open-source community from takeovers. https://www.hackread.com/openssf-fake-maintainers-target-javascript-projects/ #itsec #cybersecurity #supplychain -
Open Source Security (#OpenSSF) and #OpenJS Warn of Fake #Maintainers Targeting #JavaScript Projects
Alarming #socialengineering attacks target critical #opensource projects! Learn how to protect your project and the open-source community from takeovers. https://www.hackread.com/openssf-fake-maintainers-target-javascript-projects/ #itsec #cybersecurity #supplychain -
Excellent summary by Solar Designer on oss-security of what's happened in the last two weeks in response to the #xz #backdoor:
https://www.openwall.com/lists/oss-security/2024/04/16/5
Noteworthy:
- #OpenSSH implemented systemd notification
- #systemd moves to dlopen(3) for some dependencies
- another detailed timeline at https://research.swtch.com/xz-timeline
- similar social engineering takeover attempts suspected in #OpenJS and #OpenSSF -
Excellent summary by Solar Designer on oss-security of what's happened in the last two weeks in response to the #xz #backdoor:
https://www.openwall.com/lists/oss-security/2024/04/16/5
Noteworthy:
- #OpenSSH implemented systemd notification
- #systemd moves to dlopen(3) for some dependencies
- another detailed timeline at https://research.swtch.com/xz-timeline
- similar social engineering takeover attempts suspected in #OpenJS and #OpenSSF -
#OpenJS Foundation Targeted in Potential JavaScript Project Takeover Attempt in a manner similar to the recent XZ incident:
#SoftwareSupplyChainSecurityhttps://thehackernews.com/2024/04/openjs-foundation-targeted-in-potential.html
https://thehackernews.com/2024/04/openjs-foundation-targeted-in-potential.html
-
#OpenJS Foundation Targeted in Potential JavaScript Project Takeover Attempt in a manner similar to the recent XZ incident:
#SoftwareSupplyChainSecurityhttps://thehackernews.com/2024/04/openjs-foundation-targeted-in-potential.html
https://thehackernews.com/2024/04/openjs-foundation-targeted-in-potential.html
-
Open Source Security (OpenSSF) and OpenJS Foundations Issue Alert for Social Engineering Takeovers of Open Source Projects
https://openssf.org/blog/2024/04/15/open-source-security-openssf-and-openjs-foundations-issue-alert-for-social-engineering-takeovers-of-open-source-projects/#OpenSSF #OpenJS #SocialEngineering #FOSS #Projects #TakeOver
-
Open Source Security (OpenSSF) and OpenJS Foundations Issue Alert for Social Engineering Takeovers of Open Source Projects
https://openssf.org/blog/2024/04/15/open-source-security-openssf-and-openjs-foundations-issue-alert-for-social-engineering-takeovers-of-open-source-projects/#OpenSSF #OpenJS #SocialEngineering #FOSS #Projects #TakeOver
-
This exemplifies the unique network of human beings in and around Open Source that makes it so _resilient_.
With OSS, people are curious. They are empowered to take a peek under the hood. To share what they find with others. To ignore organizational and architectural boundaries.
#OpenSource #FreeSoftware #FOSS #OSS #InfoSec #XZ #OpenJS #OpenSSF #Linux #SOSSCommunity
-
This exemplifies the unique network of human beings in and around Open Source that makes it so _resilient_.
With OSS, people are curious. They are empowered to take a peek under the hood. To share what they find with others. To ignore organizational and architectural boundaries.
#OpenSource #FreeSoftware #FOSS #OSS #InfoSec #XZ #OpenJS #OpenSSF #Linux #SOSSCommunity
-
Free and Open Source software communities are anything *but* “fragile” in light of recent failed attacks.
They are smart. They are vigilant. They are resilient.
But they also need support from institutions given the resources attackers may have.
#OpenSource #FreeSoftware #FOSS #OSS #InfoSec #XZ #OpenJS #OpenSSF #Linux #SOSSCommunity
-
Free and Open Source software communities are anything *but* “fragile” in light of recent failed attacks.
They are smart. They are vigilant. They are resilient.
But they also need support from institutions given the resources attackers may have.
#OpenSource #FreeSoftware #FOSS #OSS #InfoSec #XZ #OpenJS #OpenSSF #Linux #SOSSCommunity
-
Open Source Security (OpenSSF) and OpenJS Foundations Issue Alert for Social Engineering Takeovers of Open Source Projects
XZ Utils cyberattack likely not an isolated incident
#OpenSource #FreeSoftware #FOSS #OSS #InfoSec #XZ #OpenJS #OpenSSF #Linux
https://openjsf.org/blog/openssf-openjs-alert-social-engineering-takeovers
-
Open Source Security (OpenSSF) and OpenJS Foundations Issue Alert for Social Engineering Takeovers of Open Source Projects
XZ Utils cyberattack likely not an isolated incident
#OpenSource #FreeSoftware #FOSS #OSS #InfoSec #XZ #OpenJS #OpenSSF #Linux
https://openjsf.org/blog/openssf-openjs-alert-social-engineering-takeovers
-
How does Wikimedia approach security and performance?
We're quite selective in our dependencies and often audit the sources ourselves. Progressive enhancement makes for a blazing fast and accessible site, and, I argue, it's also the cheaper choice in the long run!
https://timotijhof.net/posts/2023/wikimedia-balances-security-and-openness/
#mediawiki #Wikipedia #OpenJS #infosec #webperf #foss #floss
-
How does Wikimedia approach security and performance?
We're quite selective in our dependencies and often audit the sources ourselves. Progressive enhancement makes for a blazing fast and accessible site, and, I argue, it's also the cheaper choice in the long run!
https://timotijhof.net/posts/2023/wikimedia-balances-security-and-openness/
#mediawiki #Wikipedia #OpenJS #infosec #webperf #foss #floss
-
#CrabLang (a fork of #Rust), reminds me of Io.js, which forked from #Node.js because corporate sponsors were holding the language back. Due to extreme bureaucratic caution, adding new JavaScript features to Node.js took a very long time (years!).
The good thing is that this led to the formation of the Node.js Foundation and, eventually, the #OpenJS Foundation. The result is a platform with better governance and faster iteration. #Io.js and #Node.js were merged in the end.
-
#CrabLang (a fork of #Rust), reminds me of Io.js, which forked from #Node.js because corporate sponsors were holding the language back. Due to extreme bureaucratic caution, adding new JavaScript features to Node.js took a very long time (years!).
The good thing is that this led to the formation of the Node.js Foundation and, eventually, the #OpenJS Foundation. The result is a platform with better governance and faster iteration. #Io.js and #Node.js were merged in the end.
-
:flowforge: #FlowForge is joining the #OpenJS Foundation
FlowForge makes Node-RED available for the enterprise, and lets you manage your Node-RED instances all in one place. We're excited to see what they will bring to the OpenJS community.
:nodered: #NodeRED
https://openjsf.org/announcement/2022/12/13/welcoming-flowforge-to-the-openjs-foundation/
-
:flowforge: #FlowForge is joining the #OpenJS Foundation
FlowForge makes Node-RED available for the enterprise, and lets you manage your Node-RED instances all in one place. We're excited to see what they will bring to the OpenJS community.
:nodered: #NodeRED
https://openjsf.org/announcement/2022/12/13/welcoming-flowforge-to-the-openjs-foundation/