Is there a web browser that won’t try to shiv me in my sleep? #askingforafriend
This episode #OpenSourceSecurity talks to @Sheogorath about forking open source projects It's a lot more complicated than you think it is, and Sheogorath has some first hand experience from one of the most complicated forks I've ever seen in HedgeDoc It's a fun chat filled with lessons
Now that 2025 is here, it's time to wind down the #osspodcast It was a fun run, but it was time to be done. I have a new project I'm calling "Open Source Security" (the domain is too good to not do something with it) I want to chat with people securing the use and creating of open source. I explain a lot more in the blog post (which also has audio) If you're one of these people, let me know! There are a lot of lessons for us all, and the people doing the best work aren't being listened to https://opensourcesecurity.io/posts/2025-01-the_future_of_open_source_security/
Looks like #NVD has stopped enriching #CVE again. So that's neat image
I wrote a blog post about the #SBOM complaining that seems to pop up every few months SBOMs are used all over the place, they're just not always called SBOMs