Reposted by Mikael Barberoæva black @aeva.online · 12/08/2026Hardware scarcity is our new reality — and spells growing difficulty for mid-sized businesses, managed hosting providers, and many open source communities. 042
Mikael Barbero @mikael.barbero.tech · 07/07/2026I'm joining Jenn Gile and Paul McCarty on The @opensourcemalware.bsky.social Show to talk about securing Open VSX and the Eclipse Foundation! 🗓️ Thu, July 9, 2:35pm PST LinkedIn event: www.linkedin.com/events/74785... YouTube livestream: youtube.com/live/l3YE9Yi...youtube.comThe OpenSourceMalware Show - #12YouTube video by OpenSourceMalware 021
Mikael Barbero @mikael.barbero.tech · 06/07/2026Go learn, for free, what the CRA entails with this great resource. It should be your top learning priority for the summer! 011
Mikael Barbero @mikael.barbero.tech · 22/06/2026Who am I, if not a wetware agent running legacy autonomy software? 000
Mikael Barbero @mikael.barbero.tech · 19/06/2026AI-assisted vulnerability reports should not just include polished findings. They should include the prompt, model details, context, tools, repo state, and validation method. For maintainers, provenance is the new reproduction step. Start with the prompt! mikael.barbero.tech/blog/post/20...mikael.barbero.techThe Vulnerability Report Is Dead. Long Live the Prompt!For years, maintainers have asked security reporters for a fairly reasonable thing: reproduction steps. Not a vibe. Not a screenshot from a scanner. Not a majestic wall of speculative prose explaining... 000
Reposted by Mikael BarberoEclipse Foundation @eclipse.org · 28/05/2026On June 2, the Eclipse Foundation will make optional identity verification generally available for Eclipse Foundation committers. Read more in this blog by Mikaël Barbero 👉 blogs.eclipse.org/post/mika%C3... #opensource #security #committers 031
Reposted by Mikael BarberoEclipse Foundation @eclipse.org · 18/05/2026We've been part of the Glasswing Project since its inception. To our knowledge, we're the only EU-domiciled organisation participating in the initiative, giving us a unique vantage point on how frontier AI capabilities are reshaping software security. Read more 👉 blogs.eclipse.org/post/mike-mi... 033
Reposted by Mikael BarberoMike McQuaid @mikemcquaid.com · 13/05/2026Open source maintainers at profitable companies: stop asking permission to fix what your employer already depends on. No paperwork. No programme. No manager’s blessing. Just maintain it on the clock.ossresistance.comOpen Source ResistanceA direct-action manifesto for maintainers keeping open source alive on company time. 319343
Reposted by Mikael BarberoEize Basa @eizebasa.baby · 05/04/2026“I will NOT sacrifice the Oxford comma. We've made too many compromises already; too many retreats. They assimilate the em dash and we fall back. They capture ‘not just X but y’ and we fall back. Not again. The line must be drawn here! This far, no further!” 16475132091
Mikael Barbero @mikael.barbero.tech · 26/03/2026I just published part 2! Don't become the next Trivy: how to make your releases, tags, and automation resistant to compromise mikael.barbero.tech/blog/post/20... #security #supplychainmikael.barbero.techDon't become the next Trivy: how to make your releases, tags, and automation resistant to compromiseThis is Part 2 of our response to the Trivy supply-chain compromise. Part 1 covered how to consume GitHub Actions safely. This post covers the other side: how to publish safely, so your project doesn’... 000
Mikael Barbero @mikael.barbero.tech · 24/03/2026I published a blog post that lists recommendations and outlines concrete steps that open source projects can (should?) take to reduce the risk of supply chain breaches similar to the recent Trivy incident: mikael.barbero.tech/blog/post/20...mikael.barbero.techStop trusting mutable references: how Eclipse Foundation projects should harden GitHub Actions after the Trivy compromiseOn March 19, 2026, an attacker used compromised credentials to publish a malicious Trivy v0.69.4 release, force-push 76 of 77 version tags in aquasecurity/trivy-action, and replace all 7 tags in aquas... 022
Reposted by Mikael BarberoJoshua Bloch @joshbloch.bsky.social · 11/03/2026R.I.P. Tony Hoare (11 January 1934 - 5 March 2026). It's a good day to read (or re-read) his wonderful 1980 Turing Award lecture. It's every bit as relevant today as it was in 1980. dl.acm.org/doi/10.1145/...dl.acm.orgThe emperor's old clothes | Communications of the ACM 0143
Reposted by Mikael BarberoAndrew Nesbitt @andrewnez.bsky.social · 10/03/2026I've been working on a unified cli that works for github, gitlab, gitea/forgejo and bitbucket. So you (or a coding agent) doesn't need to learn 4 different sets of commands for what are basically all doing the same things: github.com/git-pkgs/forgegithub.comGitHub - git-pkgs/forge: Go library and CLI for working with git forges. Supports GitHub, GitLab, Gitea/Forgejo, and Bitbucket Cloud through a single interface.Go library and CLI for working with git forges. Supports GitHub, GitLab, Gitea/Forgejo, and Bitbucket Cloud through a single interface. - git-pkgs/forge 4246
Reposted by Mikael BarberoTechnology Connections @techconnectify.bsky.social · 30/01/2026Let's do this. www.youtube.com/watch?v=KtQ9...youtube.comYou are being misled about renewable energy technology.YouTube video by Technology Connections 667109723555
Reposted by Mikael BarberoLaurieWired @lauriewired.bsky.social · 31/01/2026today’s one-sentence horror: sudo has been largely maintained by a single person for ~30+ years 918436
Reposted by Mikael BarberoArnaud Héritier @aheritier.net · 25/01/2026+10000 the safety rules to manage this new ecosystem isn’t here yet and is critical. We’ll need safe ways to share these new artifacts (skills, plugins, MCP …) 062
Reposted by Mikael BarberoMichael Gasch @embano1.mgasch.com · 25/01/2026From curl | bash off the internet… …to docker run some random image… …to /plugin install in coding agents. Same vibes, bigger blast radius. Supply chain management for plugins, anyone? :) 231
Reposted by Mikael BarberoDana Fried @leftoblique.bsky.social · 26/11/2025This is an insightful but deeply upsetting article about why everyone in the US feels poor, and why the current political situation emerges as a direct result. www.yesigiveafig.com/p/part-1-my-...yesigiveafig.comPart 1: My Life Is a LieHow a Broken Benchmark Quietly Broke America 23933384
Reposted by Mikael Barberosarcastic parrot @monkchips.com · 14/11/2025So I wrote a thing redmonk.com/jgovernor/on...redmonk.comOn Cursor, Erich Gamma, VS Code forks and the surprising role of the Eclipse FoundationI was writing this post today when the news dropped that Cursor has just raised a new round. > We’re pleased to announce a new round of financing: our Series D of $2.3B at a $29.3B post-money valuat... 386
Mikael Barbero @mikael.barbero.tech · 13/11/2025The recording is available and, as expected, it is exceptionally good! It will genuinely ignite (or re-ignite) your enthusiasm for being an engineer! Thank you, @bcantrill.bsky.social www.youtube.com/watch?v=Cum5...youtube.comThe Complexity of SimplicityYouTube video by Oxide Computer Company 0215
Mikael Barbero @mikael.barbero.tech · 29/10/2025Single most desirable feature from Supply Chain Security PoV 010
Mikael Barbero @mikael.barbero.tech · 20/10/2025I had a great time chatting with @josh.bressers.name! Go check out what’s happening on the security front at the Eclipse Foundation (@eclipse.org) 041
Mikael Barbero @mikael.barbero.tech · 18/10/2025And it gets even worse when the metrics are averages rather than percentiles! 010
Mikael Barbero @mikael.barbero.tech · 17/10/2025I can’t wait for the video of this one, the deck is already so bonkers! Love it! Also, no mention of LLM ;) 030
Mikael Barbero @mikael.barbero.tech · 16/10/2025🎙 Just wrapped a fantastic conversation with @josh.bressers.name. We dive deep into enhancing open source security and how we do it at the @eclipse.org Can't wait for you to hear the full episode, coming soon! 131
Reposted by Mikael BarberoFilippo Valsorda @filippo.abyssdomain.expert · 10/10/2025To implement robust mitigations across Geomys, I did a survey of open source project compromises in 2024/2025. Three root causes dominate: phishing, control handoff, and unsafe GitHub Actions triggers. All three can be systematically avoided. words.filippo.io/compromise-s...words.filippo.ioA Retrospective Survey of 2024/2025 Open Source Supply Chain CompromisesProject compromises have common root causes we can mitigate: phishing, control handoff, and unsafe GitHub Actions triggers. 46321
Reposted by Mikael BarberoShane Curcuru @shanecurcuru.bsky.social · 25/09/2025🏷️ Reason #3.7.2 why it's critical to clearly and publicly define your #OpenSource project #Governance, for code, distributions, trademarks, and domain names. And, of course, not breaking norms and cosplaying a public charity while bowing to a sole sponsor over the community. 😢 043
Reposted by Mikael BarberoEclipse Foundation @eclipse.org · 23/09/2025The future of digital innovation depends on sustainable #opensource infrastructure. Learn how businesses can help ensure long-term sustainability in #EclipseFdn Executive Director Mike Milinkovich’s latest blog: hubs.la/Q03Kz6D50 #PreserveOpenSource #SoftwareSupplyChain #OpenSourceResponsibility 053
Reposted by Mikael BarberoEclipse Foundation @eclipse.org · 03/09/2025#OCX26 is where the future of open source takes shape. Do you want to be part of it? As an #OCX26 sponsor, you get to align your brand with the communities shaping tomorrow’s tech all in one place. 👉 Get the prospectus or get in touch with our team directly: www.ocxconf.org/event/2026/b... 011
Reposted by Mikael BarberoJosh Bressers @josh.bressers.name · 28/08/2025The Register wrote a story about a single maintainer open source project, I think it's shameful and upsetting So I wrote a blog post about it An absolutely ridiculous amount of open source is one person projects. I have the data to prove it opensourcesecurity.io/2025/08-oss-...opensourcesecurity.ioOpen Source is one personThe Register recently published a story titled Putin on the code: DoD reportedly relies on utility written by Russian dev. They should be ashamed of this story, and the company behind the ambulance ch... 65627
Reposted by Mikael BarberoMeredith Whittaker @meredithmeredith.bsky.social · 19/02/2025Stand by this: www.politico.com/newsletters/... 15496623143
Reposted by Mikael BarberoJoshua Bloch @joshbloch.bsky.social · 04/07/2025🇺🇸Happy Fourth of July🇺🇸 This year, I'm wearing my 𝐑𝐞𝐬𝐢𝐬𝐭 shirt to show my patriotism. I'm reading the declaration of independence as I always do on this occasion. Several of King George's offenses against the colonies resonate this year. Here they are, verbatim: 0105
Mikael Barbero @mikael.barbero.tech · 03/07/2025Iwata Satoru was an unconventional CEO. In all the best ways that could imply! 000
Reposted by Mikael BarberoAlexandria Ocasio-Cortez @aoc.bsky.social · 11/06/2025I will be damned if I allow a bunch of Confederate-waving January 6th apologists give the American people a lecture on flag waving. There is ZERO reason to enter an argument about patriotism with people who still worship traitors to America 150+ years later. They. Are. Breaking. The. Law. 136910266721947
Reposted by Mikael BarberoOpen Regulatory Compliance @orcwg.org · 05/06/2025🗓 On 4 June, the ORC community was represented by some of its members in the CRA Expert Group meeting hosted by @ec.europa.eu We’re grateful to @ec.europa.eu for facilitating this discussion and to everyone involved. @j-rico.bsky.social @tobie.bsky.social @mikael.barbero.tech @apache.org 012
Reposted by Mikael BarberoEclipse Foundation @eclipse.org · 04/06/2025📢 Calling developers, users, and committers! The Eclipse Foundation Security team is offering a new security training focused on vulnerability management and related subjects. Register for Day 2 (June 10 on 4PM CEST): eclipse.zoom.us/meeting/regi... ➡️ blogs.eclipse.org/post/marta-r... 001
Reposted by Mikael BarberoMarta Rybczynska @mrybczyn.bsky.social · 30/05/2025On June 3rd and 10th with my colleagues from the Eclipse Foundation we will be running a free security training on vulnerability management and related subject. More details and registration links on blogs.eclipse.org/post/marta-r...blogs.eclipse.orgAnnouncing Security Training on Vulnerability Management, SBOM and related subjectsDo you want to know more about 021
Reposted by Mikael BarberoEclipse Foundation @eclipse.org · 26/05/2025🔒 Master vulnerability management! Our security training on 3 June and 10 June covers CVE reporting, embargoes, dependency evaluation, and SBOMs. 📅 Day 1: eclipse.zoom.us/meeting/regi... 📅 Day 2: eclipse.zoom.us/meeting/regi... 001
Reposted by Mikael BarberoNoah Barkin @noahbarkin.bsky.social · 02/05/2025Rubio publicly criticizing an ally for cracking down on right-wing extremism. And Germany hitting back. We are in a new world 22145075412284
Reposted by Mikael BarberoParis Marx @parismarx.com · 21/04/2025The days of Google Docs are ending; we enter the age of Docs, made by France's Interministerial Directorate for Digital Affairs and Germany's Center for Digital Sovereignty of Public Administration. We need more governments to collaborate on public software projects to achieve digital sovereignty.techspot.comFrance and Germany unveil Docs, a homegrown alternative to Google DocsThe Trump administration has set out to drastically reshape the relationship between the US and Europe. In response, Brussels is scrambling to adapt to this new reality,... 522094731
Reposted by Mikael BarberoTib3rius @tib3rius.bsky.social · 15/04/2025BREAKING. From a reliable source. MITRE support for the CVE program is due to expire tomorrow. The attached letter was sent out to CVE Board Members. 35672409
Reposted by Mikael BarberoMarta Rybczynska @mrybczyn.bsky.social · 14/03/2025VulnCon is a quite unique conference focus on software (and not only) vulnerability management. It is happening at the beginning of April and I will be speaking twice. 031
Reposted by Mikael BarberoMeredith Whittaker @meredithmeredith.bsky.social · 26/03/2025This is inaccurate. There is no known vulnerability with Signal's core tech. The memo was discussing phishing attempts, which Signal has worked to mitigate. And it was hastily reported. It's important not to spread misinfo that can confuse people into moving away from meaningfully private comms. 1122527735
Reposted by Mikael BarberoReversingLabs @reversinglabs.com · 13/03/2025👀 New report from RL: While #OSS risks are not going away, attack trends show third-party commercial software presents the greatest risk to the enterprise. Learn more: www.reversinglabs.com/blog/hidden-... #SoftwareSupplyChainSecurity #AppSec #DevSecOps #Devreversinglabs.comHidden threats lurk in commercial software: How to manage riskWhile open-source software risks are not going away, attack trends show third-party software presents the greatest risk to the enterprise. 053
Reposted by Mikael BarberoMike Ginn @shutupmikeginn.bsky.social · 08/03/2025its amazing how chatgpt knows everything about subjects I know nothing about, but is wrong like 40% of the time in things im an expert on. not going to think about this any further 126187674576