Sign in

Mikael Barbero

@mikael.barbero.tech
265 followers 193 following 297 posts

Head of Security @ Eclipse Foundation We build our computers (systems) the way we build our cities: over time, without a plan, on top of ruins — Ellen Ullman

PostsRepliesMedia
Reposted by Mikael Barbero
æva black @aeva.online · 12/08/2026
Hardware scarcity is our new reality — and spells growing difficulty for mid-sized businesses, managed hosting providers, and many open source communities.
042
Mikael Barbero @mikael.barbero.tech · 07/07/2026
I'm joining Jenn Gile and Paul McCarty on The @opensourcemalware.bsky.social Show to talk about securing Open VSX and the Eclipse Foundation! 🗓️ Thu, July 9, 2:35pm PST LinkedIn event: www.linkedin.com/events/74785... YouTube livestream: youtube.com/live/l3YE9Yi...
youtube.com
The OpenSourceMalware Show - #12
YouTube video by OpenSourceMalware
021
Mikael Barbero @mikael.barbero.tech · 06/07/2026
Go learn, for free, what the CRA entails with this great resource. It should be your top learning priority for the summer!
011
Mikael Barbero @mikael.barbero.tech · 22/06/2026
Who am I, if not a wetware agent running legacy autonomy software?
000
Mikael Barbero @mikael.barbero.tech · 19/06/2026
AI-assisted vulnerability reports should not just include polished findings. They should include the prompt, model details, context, tools, repo state, and validation method. For maintainers, provenance is the new reproduction step. Start with the prompt! mikael.barbero.tech/blog/post/20...
mikael.barbero.tech
The Vulnerability Report Is Dead. Long Live the Prompt!
For years, maintainers have asked security reporters for a fairly reasonable thing: reproduction steps. Not a vibe. Not a screenshot from a scanner. Not a majestic wall of speculative prose explaining...
000
Reposted by Mikael Barbero
Eclipse Foundation @eclipse.org · 28/05/2026
On June 2, the Eclipse Foundation will make optional identity verification generally available for Eclipse Foundation committers. Read more in this blog by Mikaël Barbero 👉 blogs.eclipse.org/post/mika%C3... #opensource #security #committers
031
Reposted by Mikael Barbero
Eclipse Foundation @eclipse.org · 18/05/2026
We've been part of the Glasswing Project since its inception. To our knowledge, we're the only EU-domiciled organisation participating in the initiative, giving us a unique vantage point on how frontier AI capabilities are reshaping software security. Read more 👉 blogs.eclipse.org/post/mike-mi...
033
Reposted by Mikael Barbero
Mike McQuaid @mikemcquaid.com · 13/05/2026
Open source maintainers at profitable companies: stop asking permission to fix what your employer already depends on. No paperwork. No programme. No manager’s blessing. Just maintain it on the clock.
ossresistance.com
Open Source Resistance
A direct-action manifesto for maintainers keeping open source alive on company time.
319343
Reposted by Mikael Barbero
Eize Basa @eizebasa.baby · 05/04/2026
“I will NOT sacrifice the Oxford comma. We've made too many compromises already; too many retreats. They assimilate the em dash and we fall back. They capture ‘not just X but y’ and we fall back. Not again. The line must be drawn here! This far, no further!”
I know the tweet is Al generated when they use " ," before and.
16475132091
Mikael Barbero @mikael.barbero.tech · 26/03/2026
I just published part 2! Don't become the next Trivy: how to make your releases, tags, and automation resistant to compromise mikael.barbero.tech/blog/post/20... #security #supplychain
mikael.barbero.tech
Don't become the next Trivy: how to make your releases, tags, and automation resistant to compromise
This is Part 2 of our response to the Trivy supply-chain compromise. Part 1 covered how to consume GitHub Actions safely. This post covers the other side: how to publish safely, so your project doesn’...
000
Mikael Barbero @mikael.barbero.tech · 24/03/2026
I published a blog post that lists recommendations and outlines concrete steps that open source projects can (should?) take to reduce the risk of supply chain breaches similar to the recent Trivy incident: mikael.barbero.tech/blog/post/20...
mikael.barbero.tech
Stop trusting mutable references: how Eclipse Foundation projects should harden GitHub Actions after the Trivy compromise
On March 19, 2026, an attacker used compromised credentials to publish a malicious Trivy v0.69.4 release, force-push 76 of 77 version tags in aquasecurity/trivy-action, and replace all 7 tags in aquas...
022
Reposted by Mikael Barbero
Joshua Bloch @joshbloch.bsky.social · 11/03/2026
R.I.P. Tony Hoare (11 January 1934 - 5 March 2026). It's a good day to read (or re-read) his wonderful 1980 Turing Award lecture. It's every bit as relevant today as it was in 1980. dl.acm.org/doi/10.1145/...
dl.acm.org
The emperor's old clothes | Communications of the ACM
0143
Reposted by Mikael Barbero
Andrew Nesbitt @andrewnez.bsky.social · 10/03/2026
I've been working on a unified cli that works for github, gitlab, gitea/forgejo and bitbucket. So you (or a coding agent) doesn't need to learn 4 different sets of commands for what are basically all doing the same things: github.com/git-pkgs/forge
github.com
GitHub - git-pkgs/forge: Go library and CLI for working with git forges. Supports GitHub, GitLab, Gitea/Forgejo, and Bitbucket Cloud through a single interface.
Go library and CLI for working with git forges. Supports GitHub, GitLab, Gitea/Forgejo, and Bitbucket Cloud through a single interface. - git-pkgs/forge
4246
Reposted by Mikael Barbero
Technology Connections @techconnectify.bsky.social · 30/01/2026
Let's do this. www.youtube.com/watch?v=KtQ9...
youtube.com
You are being misled about renewable energy technology.
YouTube video by Technology Connections
667109723555
Reposted by Mikael Barbero
LaurieWired @lauriewired.bsky.social · 31/01/2026
today’s one-sentence horror: sudo has been largely maintained by a single person for ~30+ years
918436
Reposted by Mikael Barbero
Arnaud Héritier @aheritier.net · 25/01/2026
+10000 the safety rules to manage this new ecosystem isn’t here yet and is critical. We’ll need safe ways to share these new artifacts (skills, plugins, MCP …)
062
Reposted by Mikael Barbero
Michael Gasch @embano1.mgasch.com · 25/01/2026
From curl | bash off the internet… …to docker run some random image… …to /plugin install in coding agents. Same vibes, bigger blast radius. Supply chain management for plugins, anyone? :)
231
Reposted by Mikael Barbero
Dana Fried @leftoblique.bsky.social · 26/11/2025
This is an insightful but deeply upsetting article about why everyone in the US feels poor, and why the current political situation emerges as a direct result. www.yesigiveafig.com/p/part-1-my-...
yesigiveafig.com
Part 1: My Life Is a Lie
How a Broken Benchmark Quietly Broke America
23933384
Reposted by Mikael Barbero
sarcastic parrot @monkchips.com · 14/11/2025
So I wrote a thing redmonk.com/jgovernor/on...
redmonk.com
On Cursor, Erich Gamma, VS Code forks and the surprising role of the Eclipse Foundation
I was writing this post today when the news dropped that Cursor has just raised a new round.   > We’re pleased to announce a new round of financing: our Series D of $2.3B at a $29.3B post-money valuat...
386
Mikael Barbero @mikael.barbero.tech · 13/11/2025
The recording is available and, as expected, it is exceptionally good! It will genuinely ignite (or re-ignite) your enthusiasm for being an engineer! Thank you, @bcantrill.bsky.social www.youtube.com/watch?v=Cum5...
youtube.com
The Complexity of Simplicity
YouTube video by Oxide Computer Company
0215
Mikael Barbero @mikael.barbero.tech · 29/10/2025
Single most desirable feature from Supply Chain Security PoV
010
Mikael Barbero @mikael.barbero.tech · 20/10/2025
I had a great time chatting with @josh.bressers.name! Go check out what’s happening on the security front at the Eclipse Foundation (@eclipse.org)
041
Mikael Barbero @mikael.barbero.tech · 18/10/2025
And it gets even worse when the metrics are averages rather than percentiles!
010
Mikael Barbero @mikael.barbero.tech · 17/10/2025
I can’t wait for the video of this one, the deck is already so bonkers! Love it! Also, no mention of LLM ;)
030
Mikael Barbero @mikael.barbero.tech · 16/10/2025
🎙 Just wrapped a fantastic conversation with @josh.bressers.name. We dive deep into enhancing open source security and how we do it at the @eclipse.org Can't wait for you to hear the full episode, coming soon!
131
Reposted by Mikael Barbero
Filippo Valsorda @filippo.abyssdomain.expert · 10/10/2025
To implement robust mitigations across Geomys, I did a survey of open source project compromises in 2024/2025. Three root causes dominate: phishing, control handoff, and unsafe GitHub Actions triggers. All three can be systematically avoided. words.filippo.io/compromise-s...
words.filippo.io
A Retrospective Survey of 2024/2025 Open Source Supply Chain Compromises
Project compromises have common root causes we can mitigate: phishing, control handoff, and unsafe GitHub Actions triggers.
46321
Reposted by Mikael Barbero
Shane Curcuru @shanecurcuru.bsky.social · 25/09/2025
🏷️ Reason #3.7.2 why it's critical to clearly and publicly define your #OpenSource project #Governance, for code, distributions, trademarks, and domain names. And, of course, not breaking norms and cosplaying a public charity while bowing to a sole sponsor over the community. 😢
043
Reposted by Mikael Barbero
Eclipse Foundation @eclipse.org · 23/09/2025
The future of digital innovation depends on sustainable #opensource infrastructure. Learn how businesses can help ensure long-term sustainability in #EclipseFdn Executive Director Mike Milinkovich’s latest blog: hubs.la/Q03Kz6D50 #PreserveOpenSource #SoftwareSupplyChain #OpenSourceResponsibility
053
Reposted by Mikael Barbero
Eclipse Foundation @eclipse.org · 03/09/2025
#OCX26 is where the future of open source takes shape. Do you want to be part of it? As an #OCX26 sponsor, you get to align your brand with the communities shaping tomorrow’s tech all in one place. 👉 Get the prospectus or get in touch with our team directly: www.ocxconf.org/event/2026/b...
011
Reposted by Mikael Barbero
Josh Bressers @josh.bressers.name · 28/08/2025
The Register wrote a story about a single maintainer open source project, I think it's shameful and upsetting So I wrote a blog post about it An absolutely ridiculous amount of open source is one person projects. I have the data to prove it opensourcesecurity.io/2025/08-oss-...
opensourcesecurity.io
Open Source is one person
The Register recently published a story titled Putin on the code: DoD reportedly relies on utility written by Russian dev. They should be ashamed of this story, and the company behind the ambulance ch...
65627
Reposted by Mikael Barbero
Meredith Whittaker @meredithmeredith.bsky.social · 19/02/2025
Stand by this: www.politico.com/newsletters/...
What’s a technology that you think is overhyped?

I’m going to give a sideways answer to this, which is that the venture capital business model needs to be understood as requiring hype. You can go back to the Netscape IPO, and that was the proof point that made venture capital the financial lifeblood of the tech industry.

Venture capital looks at valuations and growth, not necessarily at profit or revenue. So you don’t actually have to invest in technology that works, or that even makes a profit, you simply have to have a narrative that is compelling enough to float those valuations. So you see this repetitive and exhausting hype cycle as a feature in this industry. A couple of years ago, you would have been asking me about the metaverse, then last year, you would have asked me about Web3 and crypto, and for each of these inflection points there’s an Andreessen Horowitz manifesto.

It’s not simply that one piece of technology is overhyped, it’s that hype is a necessary ingredient of the current business ecosystem of the tech industry. We should examine how often the financial incentive for hype is rewarded without any real social returns, without any meaningful progress in technology, without these tools and services and worlds ever actually manifesting. That’s key to understanding the growing chasm between the narrative of techno-optimists and the reality of our tech-encumbered world.
15496623143
Reposted by Mikael Barbero
Joshua Bloch @joshbloch.bsky.social · 04/07/2025
🇺🇸Happy Fourth of July🇺🇸 This year, I'm wearing my 𝐑𝐞𝐬𝐢𝐬𝐭 shirt to show my patriotism. I'm reading the declaration of independence as I always do on this occasion. Several of King George's offenses against the colonies resonate this year. Here they are, verbatim:
He has refused his Assent to Laws, the most wholesome and necessary for the public good.
He has endeavoured to prevent the population of these States; for that purpose obstructing the Laws for Naturalization of Foreigners.
He has obstructed the Administration of Justice, by refusing his Assent to Laws for establishing Judiciary powers.
He has made Judges dependent on his Will alone.
He has erected a multitude of New Offices, and sent hither swarms of Officers to harass our people, and eat out their substance.
He has affected to render the Military independent of and superior to the Civil power.
For cutting off our Trade with all parts of the world
For depriving us in many cases, of the benefits of Trial by Jury
In every stage of these Oppressions We have Petitioned for Redress in the most humble terms: Our repeated Petitions have been answered only by repeated injury. A Prince, whose character is thus marked by every act which may define a Tyrant, is unfit to be the ruler of a free people.
0105
Mikael Barbero @mikael.barbero.tech · 03/07/2025
Iwata Satoru was an unconventional CEO. In all the best ways that could imply!
000
Reposted by Mikael Barbero
Alexandria Ocasio-Cortez @aoc.bsky.social · 11/06/2025
I will be damned if I allow a bunch of Confederate-waving January 6th apologists give the American people a lecture on flag waving. There is ZERO reason to enter an argument about patriotism with people who still worship traitors to America 150+ years later. They. Are. Breaking. The. Law.
136910266721947
Reposted by Mikael Barbero
Open Regulatory Compliance @orcwg.org · 05/06/2025
🗓 On 4 June, the ORC community was represented by some of its members in the CRA Expert Group meeting hosted by @ec.europa.eu We’re grateful to @ec.europa.eu for facilitating this discussion and to everyone involved. @j-rico.bsky.social @tobie.bsky.social @mikael.barbero.tech @apache.org
012
Reposted by Mikael Barbero
Eclipse Foundation @eclipse.org · 04/06/2025
📢 Calling developers, users, and committers! The Eclipse Foundation Security team is offering a new security training focused on vulnerability management and related subjects. Register for Day 2 (June 10 on 4PM CEST): eclipse.zoom.us/meeting/regi... ➡️ blogs.eclipse.org/post/marta-r...
001
Reposted by Mikael Barbero
Marta Rybczynska @mrybczyn.bsky.social · 30/05/2025
On June 3rd and 10th with my colleagues from the Eclipse Foundation we will be running a free security training on vulnerability management and related subject. More details and registration links on blogs.eclipse.org/post/marta-r...
blogs.eclipse.org
Announcing Security Training on Vulnerability Management, SBOM and related subjects
Do you want to know more about
021
Reposted by Mikael Barbero
Eclipse Foundation @eclipse.org · 26/05/2025
🔒 Master vulnerability management! Our security training on 3 June and 10 June covers CVE reporting, embargoes, dependency evaluation, and SBOMs. 📅 Day 1: eclipse.zoom.us/meeting/regi... 📅 Day 2: eclipse.zoom.us/meeting/regi...
001
Reposted by Mikael Barbero
Noah Barkin @noahbarkin.bsky.social · 02/05/2025
Rubio publicly criticizing an ally for cracking down on right-wing extremism. And Germany hitting back. We are in a new world
22145075412284
Reposted by Mikael Barbero
Paris Marx @parismarx.com · 21/04/2025
The days of Google Docs are ending; we enter the age of Docs, made by France's Interministerial Directorate for Digital Affairs and Germany's Center for Digital Sovereignty of Public Administration. We need more governments to collaborate on public software projects to achieve digital sovereignty.
techspot.com
France and Germany unveil Docs, a homegrown alternative to Google Docs
The Trump administration has set out to drastically reshape the relationship between the US and Europe. In response, Brussels is scrambling to adapt to this new reality,...
522094731
Reposted by Mikael Barbero
Tib3rius @tib3rius.bsky.social · 15/04/2025
BREAKING. From a reliable source. MITRE support for the CVE program is due to expire tomorrow. The attached letter was sent out to CVE Board Members.
35672409
Mikael Barbero @mikael.barbero.tech · 08/04/2025
Nailed it :D
000
Reposted by Mikael Barbero
Marta Rybczynska @mrybczyn.bsky.social · 14/03/2025
VulnCon is a quite unique conference focus on software (and not only) vulnerability management. It is happening at the beginning of April and I will be speaking twice.
031
Reposted by Mikael Barbero
Sky Marchini @sky.skymarchini.net · 28/03/2025
dead
signal appstore icon: 

Signal - Private Messenger
Today Update

• Hidden “invite random journalist” button moved
to avoid accidental taps

Version 7.52 • 143.9 MB
153169588
Reposted by Mikael Barbero
Meredith Whittaker @meredithmeredith.bsky.social · 26/03/2025
This is inaccurate. There is no known vulnerability with Signal's core tech. The memo was discussing phishing attempts, which Signal has worked to mitigate. And it was hastily reported. It's important not to spread misinfo that can confuse people into moving away from meaningfully private comms.
1122527735
Reposted by Mikael Barbero
ReversingLabs @reversinglabs.com · 13/03/2025
👀 New report from RL: While #OSS risks are not going away, attack trends show third-party commercial software presents the greatest risk to the enterprise. Learn more: www.reversinglabs.com/blog/hidden-... #SoftwareSupplyChainSecurity #AppSec #DevSecOps #Dev
reversinglabs.com
Hidden threats lurk in commercial software: How to manage risk
While open-source software risks are not going away, attack trends show third-party software presents the greatest risk to the enterprise.
053
Reposted by Mikael Barbero
Mike Ginn @shutupmikeginn.bsky.social · 08/03/2025
its amazing how chatgpt knows everything about subjects I know nothing about, but is wrong like 40% of the time in things im an expert on. not going to think about this any further
126187674576
Mikael Barbero @mikael.barbero.tech · 06/03/2025
Claude Malhuret, always up to the challenges!
010