On our last Securi-Taco Tuesday @puerco welcomed @rdcallaw & @haydentherapper from @Google's Open Source Security Team (GOSST) on to chat about how code signing and @projectsigstore secure the software supply chain.
Read the recap & watch the replay here:
https://t.co/gMI7Nzf6am
Do you verify Dependabot CVE patching PRs? Today it is trying to fix a critical Docker CVE but it got the version wrong, instead of 26.1.4, should be 26.1.5 🙃 https://t.co/pD9gqGhjKe
In this blog, @decodebytes dives into CVE's - they are not devoid of merit, but they are excessively emphasized, leading to alert fatigue among developers and internal security teams.
Instead, let's focus on more actionable indicators.
https://t.co/6GNTHCzXS4
Next Tuesday join me and @stacey_potter to kick off our new series of fun conversations about the software supply chain!
For our first episode, we managed to convince @decodebytes to be our test subject (sorry Luke!)
Send your questions and don't forget to Bring Your Own Tacos!
JULY 17: Join Stackers @jaosorior & Jakub Hrozek for this @CloudNativeFdn Livestream to learn how you can automate pinning GitHub Actions & container images to their digests!
Sign up here: https://t.co/ivFJgKA6jf
Or tune in to https://t.co/c891bcl9cc or https://t.co/nwLXthTFZz
Pinning actions and container images to digests is a security best practice, but tedious to do. The new #oss Frizbee GitHub Action makes automating this process easier. https://t.co/rYsLXslFdb #appsec#github
#oss maintainers, if you're tired of trying to make sure every project repo has a https://t.co/oiGiAk6ZXt file, branch protections enabled, Dependabot configured, etc—Minder can help you automate this, and it's free for public repos. Here's how. https://t.co/OUNfM55UYN
If you're an #opensource owner/maintainer & your project has 20+ repos #MinderCloud (FREE FOREVER for public repos) can help automate away the drudgery of setting & continuously monitoring config for all of those repos! It can even auto-remediate when it detects repo config drift
Secure your software projects using @StackLokHQ Minder Cloud https://t.co/quuu2nHEfy via @YouTube
In my latest #YouTube video I dive into the #Stacklok#Minder Cloud product for helping to secure your software projects.
Wish I could have made it to Seattle as planned. Thanks @christianh814 for filling in opening for me, with the fabulous @stacey_potter 💖🙌☺️ Admiring y'all from afar this time. See you all in #opengitops slack at https://t.co/thRyFYeGiO for live updates and follow-ups 👀🙂🫶
hey people! I wrote a thing on progressive delivery and service meshes in k8s 🦄 Can I be unbiased as a Flux maintainer? I interviewed folks from Argo, Flagger, and Linkerd to find out 💖 Big thanks to them for taking the time! Tell me what y’all think? 🫶 https://t.co/nrK3tUJ7UT
if you are looking to hire a software engineer that can:
write good Go and goodish Rust
work with k8s and containers
learn tough concepts and codebases quickly; and
has experience working in open source
then i’d really appreciate it if you considered hiring me, thanks!
CFP for #PlatformEngineeringDay closes December 3 at 11:59pm CET (5:59pm ET | 2:59pm PT).
Share your lessons learned in building & managing internal platforms, measuring platform maturity & improving golden paths & developer experience!
#PlatEngDay#KubeCon#KubeConEU
Submit to speak at Platform Engineering Day, a CNCF-hosted co-located event at #KubeCon + #CloudNativeCon Europe, 19-22 March 2024 in Paris. Speak about #PlatformEngineering, platform success, platform maturity & more!
Submit by 3 December: https://t.co/5nqE707obC. #PlatEngDay
ICYMI: The CNCF-hosted co-located events call for proposals at #KubeCon + #CloudNativeCon Europe is open! 🎉🎉🎉 Speak at ArgoCon, Istio Day, OpenTofu Day + more. Learn more + submit to speak in Paris, 19-22 March.
Submissions are due 3 December: https://t.co/DbgW9XOwUG.