@cmeik@sonatype Howdy. Could you clarify which "Remove button" isn't working? Note there is a community discourse and slack to report issues but I'll continue monitoring this thread. (https://t.co/wCQJs3qAbl)
Looking for something different to do? How about exercising your brain to contribute Jeopardy style questions to our effort to create a fun thing for Java folk. https://t.co/Zh927qzwpb
The Lift team at Sonatype is hiring! Come help us build developer-focused tools that improve code quality without slowing down development.
https://t.co/zWKfLX7hVB (USA)
https://t.co/by1Bw7WQgE (Canada)
It's here! Today, we're releasing our 7th annual State of the Software Supply Chain Report with key trends on open source supply, demand, security and governance. Take a peek - and let us know what you think! -> https://t.co/SIGgjxaaBD
#devops#opensource#softwaresupplychain
I have incredible joy in launching a product that is free for all #OpenSource projects. Welcome @sonatype Lift, your partner is code review, providing relevant deep code analysis to any Pull Request on GitHub. https://t.co/VgWFL7CKRk
🚀Sonatype Lift is finally here! Today we're launching the first-ever deep code analysis platform designed for #developers and focused on #codequality. Your code is about to get elevated. Learn more → https://t.co/HBAtKuwy5N #devops#appsec
I haven't been able to speak at a conference for quite a while, hopefully I'm not too rusty. Come see for yourself @sonatype Elevate! https://t.co/zLwMXUd6Ur
The last 2 weeks were so busy responding to the #bintray shut down and resulting Maven Central enabled OSS rescue mission, followed by the #namespace-confusion exploits that I forgot to mention we’re hiring for Dev Rel. Come join us make the world safer. https://t.co/EsneCHxRhY
#namespace attack wave 2. Bug bounty copy cats are out in force in less than 48 hours. When will wave 3, the actual attacks occur? https://t.co/4iYW60D4MD
BREAKING: Researcher @alxbrsn hacked Microsoft, Apple, Tesla, Uber, Netflix, more in a novel #opensource software supply chain attack via dependency hijacking.
But @sonatype's automated #malware detection system has been a step ahead, learn how:
https://t.co/D4gu0t8s6V
With the bintray/Jcenter situation, there are really two perspectives to mind. Firstly, what to do today if you're a developer or company affected, as well as a publisher publishing your open source. I blogged some plans for both
One last thing, if you are deploying to Central and want to see security analysis of your project dependencies, we've been working on that too. Hit me up and I'll share what we have with you preview style. We were just about to launch an Alpha program, so YOLO, here it is.
Alex really killed it with this entry to our internal video contest that explains the Sonatype platform from a film noir perspective: https://t.co/LcpZ0l3foo Great job
@alexzandelli
Alex really killed it with this entry to our internal video contest that explains the Sonatype platform from a developer perspective: https://t.co/3AvWZFDmIj Great job @alexzandelli
Fun time today chatting today with @Brian_Fox about open source, dependency management, and the evolution of modern #software development. Than you @RedHat@openshift!
Doing R development? We and the community just published a package to CRAN for scanning your R dependencies for known vulnerabilities. Check it out! https://t.co/eX2QYXIjj0 https://t.co/N1FOn6vTks