home.social

#opensourcesecurity — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #opensourcesecurity, aggregated by home.social.

  1. We're LIVE! Join the Anchore Open Source team now to discuss Syft, Grype, and the latest in . Ask your questions! youtube.com/watch?v=UGUnqfA0VuA

  2. We're LIVE! Join the Anchore Open Source team now to discuss Syft, Grype, and the latest in . Ask your questions! youtube.com/watch?v=UGUnqfA0VuA

  3. 🚨 Neuer Angriff auf das NPM‑Ökosystem!
    Am 23. Jan. 2024 wurden kritische JavaScript‑Pakete mit der Malware **“Shuffled NPM”** kompromittiert.

    **Wichtig:**
    - Prüft eure Abhängigkeiten ▶ Verwendet Hash‑Checks & automatisierte Scans.
    - Folgt den Sicherheitswarnungen von npm‑security.
    - Nutzt Lock‑Files & Monorepos, um ungewollte Updates zu verhindern.

    #JavaScript #NPM #OpenSourceSecurity #NodeJS #PrivacyFirst

    🔗 news.google.com/rss/articles/C

  4. I had a chat with @eighthave about @fdroidorg on #OpenSourceSecurity

    We cover how it works, the security angles for running an app store, and talk about some of the changes that are coming for Android that will make F-Droid's job a lot harder

    I learned a ton from Hans, it's a great discussion

    opensourcesecurity.io/2026/202

  5. We're LIVE! Join the Anchore Open Source team now to discuss Syft, Grype, and the latest in . Ask your questions! youtube.com/watch?v=N-6Sc5CQwI0

  6. We're LIVE! Join the Anchore Open Source team now to discuss Syft, Grype, and the latest in . Ask your questions! youtube.com/watch?v=N-6Sc5CQwI0

  7. We're LIVE! Join the Anchore Open Source team now to discuss Syft, Grype, and the latest in #OpenSourceSecurity. Ask your questions! youtube.com/watch?v=N-6Sc5CQwI0

  8. We're LIVE! Join the Anchore Open Source team now to discuss Syft, Grype, and the latest in #OpenSourceSecurity. Ask your questions! youtube.com/watch?v=N-6Sc5CQwI0

  9. We're LIVE! Join the Anchore Open Source team now to discuss Syft, Grype, and the latest in #OpenSourceSecurity. Ask your questions! youtube.com/watch?v=N-6Sc5CQwI0

  10. We're LIVE! Join the Anchore Open Source team now to discuss Syft, Grype, and the latest in #OpenSourceSecurity. Ask your questions! youtube.com/watch?v=N-6Sc5CQwI0

  11. We're LIVE! Join the Anchore Open Source team now to discuss Syft, Grype, and the latest in #OpenSourceSecurity. Ask your questions! youtube.com/watch?v=N-6Sc5CQwI0

  12. We're LIVE! Join the Anchore Open Source team now to discuss Syft, Grype, and the latest in #OpenSourceSecurity. Ask your questions! youtube.com/watch?v=N-6Sc5CQwI0

  13. We're LIVE! Join the Anchore Open Source team now to discuss Syft, Grype, and the latest in #OpenSourceSecurity. Ask your questions! youtube.com/watch?v=N-6Sc5CQwI0

  14. We're LIVE! Join the Anchore Open Source team now to discuss Syft, Grype, and the latest in #OpenSourceSecurity. Ask your questions! youtube.com/watch?v=N-6Sc5CQwI0

  15. 🧑‍💻 Built your own MFA system yet?

    We just dropped a full walkthrough on how to integrate Google Authenticator into RELIANOID’s MFA portal — with secrets stored in AD or LDAP.

    🔐 Based on TOTP
    🛡️ Validates tokens post-login
    📱 Generates QR codes for new users

    It’s secure, scalable, and open-source-friendly.

    📖 Dive in:

    relianoid.com/resources/knowle

  16. 🚀 NEW on We ❤️ Open Source 🚀

    SBOMs are the foundation of a more secure open source ecosystem. Alan Pope shows how Syft & Grype help you inventory & scan your software for vulnerabilities—fast, locally, and openly.

    allthingsopen.org/articles/sbo

    #WeLoveOpenSource #SBOM #OpenSourceSecurity #Syft #Grype #FOSS #DevSecOps #SecureByDesign

  17. This week on #OpenSourceSecurity I chat with @djc and @ctz about #Rustls. A lot has happened with Rustls in the last few years (and there's a lot more to come). Writing a TLS implementation is incredibly complicated, even when you don't have to worry about memory safety

    opensourcesecurity.io/2025/202

    #TLS #Rustls #Rust #MemorySafety

  18. 📝 New article by a CrowdSec Ambassador, Killian Prin-Abeil! 🎉

    In this deep dive, Killian breaks down React2Shell (CVE-2025-55182), from how the RCE works in React Server Components to why Next.js apps are vulnerable by default.

    He also explores how the community reacted in hours, with CrowdSec shipping a virtual patch and threat intel to reduce exposure immediately.

    👉Read it here: crowdsec.net/blog/react2shell-

    #react #NextJS #AppSec #opensourcesecurity #react2shell #CVE

  19. Supply chain security meets reproducible builds.
    ExpressVPN is sponsoring PlanetNix 2026, highlighting the intersection of privacy, open-source infrastructure, and build reproducibility.
    Event focus areas:
    • Deterministic builds
    • Secure deployment pipelines
    • DevSecOps integration
    • Team-level onboarding models
    • Production-grade Nix environments

    Reproducibility is increasingly tied to:
    – Software supply chain integrity
    – Auditability
    – Compliance frameworks
    – Infrastructure security baselines
    As build determinism becomes more relevant to threat modeling, open-source tooling like Nix may play a critical role.

    Source: planetnix.com/

    Are reproducible systems now essential for modern security architecture?

    Engage in the comments.
    Follow TechNadu for high-signal infosec reporting.
    Repost to amplify open-source security discussions.

    #Infosec #DevSecOps #SupplyChainSecurity #ReproducibleBuilds #NixOS #OpenSourceSecurity #ExpressVPN #CloudSecurity #InfrastructureSecurity #ThreatModeling

  20. Supply chain security meets reproducible builds.
    ExpressVPN is sponsoring PlanetNix 2026, highlighting the intersection of privacy, open-source infrastructure, and build reproducibility.
    Event focus areas:
    • Deterministic builds
    • Secure deployment pipelines
    • DevSecOps integration
    • Team-level onboarding models
    • Production-grade Nix environments

    Reproducibility is increasingly tied to:
    – Software supply chain integrity
    – Auditability
    – Compliance frameworks
    – Infrastructure security baselines
    As build determinism becomes more relevant to threat modeling, open-source tooling like Nix may play a critical role.

    Source: planetnix.com/

    Are reproducible systems now essential for modern security architecture?

    Engage in the comments.
    Follow TechNadu for high-signal infosec reporting.
    Repost to amplify open-source security discussions.

    #Infosec #DevSecOps #SupplyChainSecurity #ReproducibleBuilds #NixOS #OpenSourceSecurity #ExpressVPN #CloudSecurity #InfrastructureSecurity #ThreatModeling

  21. Supply chain security meets reproducible builds.
    ExpressVPN is sponsoring PlanetNix 2026, highlighting the intersection of privacy, open-source infrastructure, and build reproducibility.
    Event focus areas:
    • Deterministic builds
    • Secure deployment pipelines
    • DevSecOps integration
    • Team-level onboarding models
    • Production-grade Nix environments

    Reproducibility is increasingly tied to:
    – Software supply chain integrity
    – Auditability
    – Compliance frameworks
    – Infrastructure security baselines
    As build determinism becomes more relevant to threat modeling, open-source tooling like Nix may play a critical role.

    Source: planetnix.com/

    Are reproducible systems now essential for modern security architecture?

    Engage in the comments.
    Follow TechNadu for high-signal infosec reporting.
    Repost to amplify open-source security discussions.

    #Infosec #DevSecOps #SupplyChainSecurity #ReproducibleBuilds #NixOS #OpenSourceSecurity #ExpressVPN #CloudSecurity #InfrastructureSecurity #ThreatModeling

  22. Supply chain security meets reproducible builds.
    ExpressVPN is sponsoring PlanetNix 2026, highlighting the intersection of privacy, open-source infrastructure, and build reproducibility.
    Event focus areas:
    • Deterministic builds
    • Secure deployment pipelines
    • DevSecOps integration
    • Team-level onboarding models
    • Production-grade Nix environments

    Reproducibility is increasingly tied to:
    – Software supply chain integrity
    – Auditability
    – Compliance frameworks
    – Infrastructure security baselines
    As build determinism becomes more relevant to threat modeling, open-source tooling like Nix may play a critical role.

    Source: planetnix.com/

    Are reproducible systems now essential for modern security architecture?

    Engage in the comments.
    Follow TechNadu for high-signal infosec reporting.
    Repost to amplify open-source security discussions.

    #Infosec #DevSecOps #SupplyChainSecurity #ReproducibleBuilds #NixOS #OpenSourceSecurity #ExpressVPN #CloudSecurity #InfrastructureSecurity #ThreatModeling

  23. Supply chain security meets reproducible builds.
    ExpressVPN is sponsoring PlanetNix 2026, highlighting the intersection of privacy, open-source infrastructure, and build reproducibility.
    Event focus areas:
    • Deterministic builds
    • Secure deployment pipelines
    • DevSecOps integration
    • Team-level onboarding models
    • Production-grade Nix environments

    Reproducibility is increasingly tied to:
    – Software supply chain integrity
    – Auditability
    – Compliance frameworks
    – Infrastructure security baselines
    As build determinism becomes more relevant to threat modeling, open-source tooling like Nix may play a critical role.

    Source: planetnix.com/

    Are reproducible systems now essential for modern security architecture?

    Engage in the comments.
    Follow TechNadu for high-signal infosec reporting.
    Repost to amplify open-source security discussions.

    #Infosec #DevSecOps #SupplyChainSecurity #ReproducibleBuilds #NixOS #OpenSourceSecurity #ExpressVPN #CloudSecurity #InfrastructureSecurity #ThreatModeling

  24. I had a chat on #OpenSourceSecurity with Kat Cosgrove about open source being critical infrastructure (neglected critical infrastructure)

    Kat has a ton of experience in the world of Kubernetes and had some really interesting things to tell us about both successful projects as well as having to shut down projects that didn't get enough resources

    Kat even gives me some optimism at the end, which is in rare supply lately

    opensourcesecurity.io/2026/202

  25. We're LIVE! Join the Anchore Open Source team now to discuss Syft, Grype, and the latest in . Ask your questions! youtube.com/watch?v=52p2WywWq7g

  26. We're LIVE! Join the Anchore Open Source team now to discuss Syft, Grype, and the latest in . Ask your questions! youtube.com/watch?v=52p2WywWq7g

  27. We're LIVE! Join the Anchore Open Source team now to discuss Syft, Grype, and the latest in . Ask your questions! youtube.com/watch?v=0GtI0pEWpzI

  28. We're LIVE! Join the Anchore Open Source team now to discuss Syft, Grype, and the latest in . Ask your questions! youtube.com/watch?v=0GtI0pEWpzI

  29. We're LIVE! Join the Anchore Open Source team and our guest Michael Coté from Broadcom catching up on Bitnami Secure Images, Syft, Grype, and the latest in . Ask your questions! youtube.com/watch?v=m7RfVrN1TUc

  30. We're LIVE! Join the Anchore Open Source team and our guest Michael Coté from Broadcom catching up on Bitnami Secure Images, Syft, Grype, and the latest in . Ask your questions! youtube.com/watch?v=m7RfVrN1TUc

  31. I had another chat with David Bernstein about creating a disaster recovery plan on #OpenSourceSecurity

    With all the events unfolding almost every day lately, there's never been a better time to put a plan like this together. In a few weeks David will tell us how to test such a plan once we create it

    It's a lot less complicated than it seems, I know I've made this a lot harder than it needs to be

    opensourcesecurity.io/2026/202

  32. We're LIVE! Join the Anchore Open Source team now to discuss Syft, Grype, and the latest in . Ask your questions! youtube.com/watch?v=ZxkXfccgKvI

  33. We're LIVE! Join the Anchore Open Source team now to discuss Syft, Grype, and the latest in . Ask your questions! youtube.com/watch?v=ZxkXfccgKvI

  34. We're LIVE! Join the Anchore Open Source team now to discuss Syft, Grype, and the latest in . Ask your questions! youtube.com/watch?v=204PIweyiTA

  35. We're LIVE! Join the Anchore Open Source team now to discuss Syft, Grype, and the latest in . Ask your questions! youtube.com/watch?v=204PIweyiTA

  36. 🐱‍💻 Oh, Astral's here to save us all from the horrors of open source security, one blog post at a time. Because, clearly, a company that "builds tools" for "millions" will tame the wild world of supply chain attacks with just a sprinkle of their secret sauce. 🥄✨
    astral.sh/blog/open-source-sec #OpenSourceSecurity #AstralSupplyChain #CybersecurityBlog #SupplyChainAttacks #TechInnovation #HackerNews #ngated

  37. We're LIVE! Join the Anchore Open Source team now to discuss Syft, Grype, and the latest in . Ask your questions! youtube.com/watch?v=diRrt9HJRZU