Sign in

Piotr P. Karwasz

@piotr.karwasz.org
180 followers 356 following 49 posts

Java & Open Source expert | Apache Software Foundation member | VP Logging Services & Ecma Relations | Father of three wonderful daughters

PostsRepliesMedia
Reposted by Piotr P. Karwasz
Tim & struppig @mkltxt.bsky.social · 21/01/2026
Man kann halt nicht vorsichtig genug sein
Man im Laborkittel zeigt auf die Tafel, wo geschrieben steht: Every single person who confuses correation and causation ends up dying
152
Piotr P. Karwasz @piotr.karwasz.org · 07/10/2025
🚀 Great work, Tatu! We’ve just upgraded Log4j 3 to use Jackson 3 🎉 👉 github.com/apache/loggi... Next up: gearing up for a GA release by the end of the year. Fun fact: Log4j 3 is one year “younger”, branched in 2018, so we are next in line for graduation.
github.com
Upgrade Jackson from 2.x to 3.0.0-rc8 by kurtostfeld · Pull Request #3701 · apache/logging-log4j2
Upgrade Jackson from 2.x to 3.0.0-rc5
110
Reposted by Piotr P. Karwasz
Cowtown Coder @cowtowncoder.bsky.social · 03/10/2025
Jackson 3.0.0 (GA) release now starting! github.com/FasterXML/ja... #java #json #xml #csv #cbor #csv
github.com
Jackson Release 3.0
Main Portal page for the Jackson project. Contribute to FasterXML/jackson development by creating an account on GitHub.
44617
Piotr P. Karwasz @piotr.karwasz.org · 16/06/2025
🚀 Log4j 2.25.0 is out! Highlights include native GraalVM support and improved stack trace control and datetime formatting. Check out the full release notes: logging.apache.org/log4j/2.x/re...
logging.apache.org
Release notes :: Apache Log4j
0144
Piotr P. Karwasz @piotr.karwasz.org · 11/06/2025
We're teaming up with Open Source Economy to learn what users expect from critical Java libraries like #apache-commons, #httpclient, #log4j, #jackson and more—especially around version support, issues and security. Help us improve support by filling out this short survey: forms.gle/5Ad81MMcL7sy...
forms.gle
Java Critical Libraries Community Survey
Tell Us About Your Needs We’re gathering feedback on a set of Java libraries that the OpenSSF has classified as critical— including Log4j, HttpComponents, FasterXML Jackson & Woodstox, SnakeYAML, lu...
025
Piotr P. Karwasz @piotr.karwasz.org · 28/04/2025
I just released version `0.2.0` of SBOM Enforcer Maven Plugin. This plugin does for (CycloneDX) SBOMs what the Maven Enforcer Plugin does for POM files. Although the current number of built-in rules is small, the plugin is extensible and other built-in rules are on their way!
github.com
Release 0.2.0 · sbom-enforcer/sbom-enforcer
What's Changed fix: possible NPEs in handling Maven and CycloneDX models by @ppkarwasz in #42 fix: handle modules with packaging pom by @ppkarwasz in #43 fix: set global workflow permissions to em...
000
Reposted by Piotr P. Karwasz
Sergiu Gatlan @serghei.bsky.social · 16/04/2025
A coalition of CVE Board members launched a new CVE Foundation "to ensure the long-term viability, stability, and independence of the Common Vulnerabilities and Exposures (CVE) Program." www.thecvefoundation.org
Press release from the CVE Foundation:

CVE Foundation Launched to Secure the Future of the CVE Program

[Bremerton, Washington] – The CVE Foundation has been formally established to ensure the long-term viability, stability, and independence of the Common Vulnerabilities and Exposures (CVE) Program, a critical pillar of the global cybersecurity infrastructure for 25 years.

Since its inception, the CVE Program has operated as a U.S. government-funded initiative, with oversight and management provided under contract. While this structure has supported the program’s growth, it has also raised longstanding concerns among members of the CVE Board about the sustainability and neutrality of a globally relied-upon resource being tied to a single government sponsor.

This concern has become urgent following an April 15, 2025 letter from MITRE notifying the CVE Board that the U.S. government does not intend to renew its contract for managing the program. While we had hoped this day would not come, we have been preparing for this possibility.

In response, a coalition of longtime, active CVE Board members have spent the past year developing a strategy to transition CVE to a dedicated, non-profit foundation. The new CVE Foundation will focus solely on continuing the mission of delivering high-quality vulnerability identification and maintaining the integrity and availability of CVE data for defenders worldwide.

“CVE, as a cornerstone of the global cybersecurity ecosystem, is too important to be vulnerable itself,” said Kent Landfield, an officer of the Foundation. “Cybersecurity professionals around the globe rely on CVE identifiers and data as part of their daily work—from security tools and advisories to threat intelligence and response. Without CVE, defenders are at a massive disadvantage against global cyber threats.”

The formation of the CVE Foundation marks a major step toward eliminating a single point of failure in the vulnerability management ecosystem and ensuring…
12513
Piotr P. Karwasz @piotr.karwasz.org · 16/04/2025
Backward compatible alternative to CVE:
gcve.eu
GCVE - Global CVE Allocation System Announced
Introducing the Global CVE (GCVE) Allocation System (https://gcve.eu), a new decentralized approach to identifying and numbering security vulnerabilities. GCVE empowers independent GCVE Numbering Auth...
010
Reposted by Piotr P. Karwasz
Tib3rius @tib3rius.bsky.social · 16/04/2025
"CVE Foundation Launched to Secure the Future of the CVE Program" Please note this is not an official CVE Board action, but the action of a rogue group within the CVE Board to try and save the CVE Program. www.linkedin.com/in/... bsky.app/profile/cve...
85023
Piotr P. Karwasz @piotr.karwasz.org · 16/04/2025
Let us analyze the exploitability of vulnerabilities in OSS together. In collaboration with OpenRefactory, we developed a prototype to analyze the exploitability of CVEs all along the dependency chain and submit that data to the OSS projects themselves. More info soon at: github.com/copernik-eu/...
youtube.com
VEX Generation at Scale
YouTube video by Piotr P. Karwasz
000
Piotr P. Karwasz @piotr.karwasz.org · 16/04/2025
NVD stopped working one year ago. They do not review and enrich CVE records with CPE identifiers any more. They only copy the records from the CVE database.
000
Reposted by Piotr P. Karwasz
Tib3rius @tib3rius.bsky.social · 15/04/2025
BREAKING. From a reliable source. MITRE support for the CVE program is due to expire tomorrow. The attached letter was sent out to CVE Board Members.
35672409
Piotr P. Karwasz @piotr.karwasz.org · 20/03/2025
@apache.org Kafka has released version 4.0.0 and is now using Log4j Core 2 as logging backend! @logging.apache.org
010
Piotr P. Karwasz @piotr.karwasz.org · 15/03/2025
They might be right: AI will write 90% of the software, but only the remaining 10% will work.
010
Piotr P. Karwasz @piotr.karwasz.org · 05/03/2025
How do you generate the attestations? I can not find a relevant section in your `release` workflow.
100
Piotr P. Karwasz @piotr.karwasz.org · 05/03/2025
Is NVD still funded at all?
100
Piotr P. Karwasz @piotr.karwasz.org · 22/02/2025
See all the talks of ASF contributors at FOSDEM
011
Piotr P. Karwasz @piotr.karwasz.org · 20/02/2025
Unfortunately AI is not limited to e-mails. We are receiving an increasing number of AI-generated issue reports and we would need an AI to close those reports automatically… 😀
021
Reposted by Piotr P. Karwasz
OpenForum Europe @openforumeurope.org · 13/02/2025
On 11 June, OFE will be in Warsaw to host the next edition of the Capital Series. We would like to extend our sincere gratitude to our sponsor and partners: APELL, Apache Software Foundation, Linux Professional Institute, PIIT, Red Hat. Register: openforumeurope.org/event/capita... #Poland25EU
001
Reposted by Piotr P. Karwasz
OpenForum Europe @openforumeurope.org · 10/02/2025
We’re excited to announce that our upcoming Capital Series Poland will be hosted under the auspices of the Polish presidency of the Council of the European Union on 11 June in Warsaw. Register here to secure a spot and read more: openforumeurope.org/event/capita... #Poland25EU
012
Piotr P. Karwasz @piotr.karwasz.org · 10/02/2025
Did you miss my talk at FOSDEM? Are you wondering what you should do when Log5Shell comes out? The video has been published: video.fosdem.org/2025/ub4132/...
video.fosdem.org
000
Piotr P. Karwasz @piotr.karwasz.org · 10/02/2025
The taximeter was not working either, right? I guess you just got scammed.
110
Piotr P. Karwasz @piotr.karwasz.org · 09/02/2025
It is interesting to see that 49% of your responders is still experiencing security vulnerabilities from #log4j in 2024. I am really curious what does it mean. Since fixes for all known vulnerabilities are also available for Java 6 and 7, didn't they upgrade in 2021?
320
Reposted by Piotr P. Karwasz
Sovereign Tech Agency @sovereign.tech · 06/02/2025
Jan Kowalleck, Sarah Hoffmann, @hugovk.dev, @mklu.bsky.social, Stefan Eissing und Denis Ovsienko sind der erste Jahrgang des Sovereign Tech Fellowship. Wir heißen die sechs Maintainer*innen willkommen, die am einjährigen Pilotprogramm 1/2
Sovereign Tech Fellowship Wortmarke
152
Reposted by Piotr P. Karwasz
Alros @alros.bsky.social · 04/02/2025
This is gold! An AI pretends to be an old confused lady and wastes scammers time. www.theguardian.com/technology/v...
theguardian.com
'I'm a bit lost now': Daisy the AI bot speaks to scammer – video
O2 has introduced “AI granny” Daisy for a short period to show what could be done with artificial intelligence to counter the scourge of scammers
021
Reposted by Piotr P. Karwasz
Jarek Potiuk @jarekpotiuk.fosstodon.org.ap.brid.gy · 26/01/2025
Outlier AI. You are doing it wrong. Hiring people to post completely nonsenese or copy&pasted issues in reputable open-source repositories - and make maintainers train your AI on it ? not good. There are 50 such issues in last few days in @airflow repo [1] and counting. More details in [2] […]
fosstodon.org
Original post on fosstodon.org
02017
Piotr P. Karwasz @piotr.karwasz.org · 20/01/2025
In Poland, nothing is more uncertain than the past!
010
Piotr P. Karwasz @piotr.karwasz.org · 17/01/2025
I don't want to scare you, but you'll hit another shading-related snug, when you try to generate a CycloneDX SBOM for `jackson-core`. Currently there is no support for shading.
github.com
support for `maven-shade-plugin` · Issue #472 · CycloneDX/cyclonedx-maven-plugin
When using maven-shade-plugin, the sbom should likely somehow encode which dependencies are 'embedded' in the jar, and which are 'regular' dependencies. AFAIK there is no convention on how to expre...
110
Piotr P. Karwasz @piotr.karwasz.org · 16/01/2025
⸘They probably never saw such a key on their keyboard‽
Compose key on LK201 keyboard
000
Piotr P. Karwasz @piotr.karwasz.org · 11/01/2025
Not sure about Moditect, but the BND Maven Plugin should be able to do it. You probably need to unpack the shaded JAR to a directory first and give it to BND to process.
github.com
110
Piotr P. Karwasz @piotr.karwasz.org · 11/01/2025
If I had to guess, some JVM argument in .mvn/jvm.config or Surefire's argLine is missing (--add-opens, etc.)
110
Reposted by Piotr P. Karwasz
OpenForum Europe @openforumeurope.org · 08/01/2025
Capital Series is heading to Warsaw on June 11th! 🌍 Join us to explore how #OpenSource can drive Poland's digitalization & security goals during its EU Presidency. 🤝 In partnership with Red Hat Poland, APELL, PIIT, LPI & Apache Software Foundation. More to come! 👉 lnkd.in/e8SeArqb #Poland25eu
132
Piotr P. Karwasz @piotr.karwasz.org · 08/01/2025
Nice guide to navigate through all the events of the EU Open Source week.
opensourceweek.eu
Home - EU Open Source Week
021
Piotr P. Karwasz @piotr.karwasz.org · 06/01/2025
In the Roman Rite, Christmastide is rounded up to next Sunday, so you could still go on! 😉
en.wikipedia.org
Christmastide - Wikipedia
110
Piotr P. Karwasz @piotr.karwasz.org · 04/01/2025
I assume this means that critical and security bugs will result in a "last-last-last" 3.x release? 😉
100
Piotr P. Karwasz @piotr.karwasz.org · 04/01/2025
Since AssertJ is not versioned semantically, what does "final-final" 3.x release mean?
100
Piotr P. Karwasz @piotr.karwasz.org · 03/01/2025
C'est une jolie représentation de la métrique SNCF: la route plus courte entre deux villes françaises passe toujours par Paris.
000
Piotr P. Karwasz @piotr.karwasz.org · 03/01/2025
At my University we had two electrical installations: a type G installation attached to an UPS power supply for computers and a usual type F installation. All these was meant to prevent people from plugging their electric kettles into the UPS.
000
Piotr P. Karwasz @piotr.karwasz.org · 01/01/2025
Happy New Year to everyone! Now we have less than 1074 days until the Cyber Resilience Act obligations will apply.
timeanddate.com
Cyber Resilience Act
Countdown to Dec 11, 2027. Showing days, hours, minutes and seconds ticking down to 0
011
Piotr P. Karwasz @piotr.karwasz.org · 29/12/2024
The buffering behavior is currently implemented by SMTP appenders (both in Logback and Log4j Core): these appenders gather all events until an event (e.g. an ERROR) triggers the delivery. The logic can be easily adapted to forward the buffer to a different appender.
logging.apache.org
Network Appenders :: Apache Log4j
110
Piotr P. Karwasz @piotr.karwasz.org · 28/12/2024
Using special filters like `MutableContextMapFilter`, you can rapidly bump the log level for a particular customer/event/whatever to `DEBUG` as soon as you encounter a problem.
logging.apache.org
Filters :: Apache Log4j
210
Piotr P. Karwasz @piotr.karwasz.org · 20/12/2024
To log through #rsyslog, you can also use Log4j Core 2 on a per-application level: it supports both RFC 3164 and 5424 formatting (including structured data) and all kinds of transport (UDP, TCP, TLS).
logging.apache.org
Layouts :: Apache Log4j
000
Piotr P. Karwasz @piotr.karwasz.org · 20/12/2024
After another round of (automatically tested and merged) Dependabot upgrades, my thoughts return to the eternal question: How to inform `libfoo` users that `libfoo` only requires `libbar` 1.0.0 (or later), but I have successfully tested it with `libbar` version 1.23.45?
000
Piotr P. Karwasz @piotr.karwasz.org · 20/12/2024
You can actually choose between spending time with her and spending time with the kids? Lucky you!
110
Piotr P. Karwasz @piotr.karwasz.org · 20/12/2024
Do you mean a "try catch log" block? Personally I find that in 99% of the cases, there is nothing you can do with an exception, beyond describing the nature of the failure to the end-user. Logging the exception will provide additional info to the devs without overloading users.
110
Piotr P. Karwasz @piotr.karwasz.org · 20/12/2024
I need to start with Raspberry Pi too. I have been planning for years to use it as smart door bell to recognize the young men that visit my daughters.
010
Piotr P. Karwasz @piotr.karwasz.org · 18/12/2024
According to Github my first code contribution was in 2019. Until then I limited myself to bug reports and user support.
github.com
Improves MessageBuffer support for Java 11 by ppkarwasz · Pull Request #514 · msgpack/msgpack-java
Switches the MessageBuffer implementation to MessageBufferU for Java versions at least 9, which solves a couple of problems: On Java 11 (OpenJDK) jdk.internal.ref.Cleaner#clean is not open to ref...
010
Reposted by Piotr P. Karwasz
Olle E. Johansson @oej.edvina.net · 16/12/2024
Had a really good meeting with the #SCITT community today. I keep using their open meetings to get input for the #OWASP Transparency Exchange API - how to add transparency logs and monitor for abuse, changes and manipulation. Software transparency is a lot about trust. #SBOM #TEA
043
Piotr P. Karwasz @piotr.karwasz.org · 13/12/2024
@logging.apache.org, we have just released Apache Log4j `2.24.3`. Log4j API 2.24.3 will be used at the same time by future Log4j Core 2.x and Log4j Core 3.x releases.
logging.apache.org
Release Notes :: Apache Log4j
110