Sign in

Xavier Rene-Corail

@xcorail.bsky.social
227 followers 357 following 62 posts

Open source security at GitHub. I don’t believe in perfection, but in continuous improvement. Opinions here are mine.

PostsRepliesMedia
Xavier Rene-Corail @xcorail.bsky.social · 09/08/2026
Finally watching Cape Fear. I still prefer the movies, but the series is not bad either. And seeing Javier Bardem and Ron Perlman in the same frame is priceless!
020
Xavier Rene-Corail @xcorail.bsky.social · 21/04/2026
Hey 👋🏾 les amis! Si vous êtes à Paris pour @devoxx.fr, passez me voir sur le stand GitHub!
010
Reposted by Xavier Rene-Corail
Abby Cabunoc Mayes @abbycabs.dev · 02/03/2026
“AI is destroying my humanity.” @mitchellh.com (HashiCorp; Ghostty, Vouch). From a conversation @helen.blog and I had with him. Not an anti-AI take. A maintainer capacity take. Creation got cheaper. Review didn’t. Maintainers: what’s helped you keep mentoring sustainable?
1183
Xavier Rene-Corail @xcorail.bsky.social · 19/02/2026
Come say hi 👋 at DeveloperWeek.
000
Reposted by Xavier Rene-Corail
GitHub @github.com · 17/02/2026
Who knows how to secure open source better than the maintainers themselves? 🛡️
4277
Xavier Rene-Corail @xcorail.bsky.social · 16/02/2026
RIP Robert Duvall 😢
media.tenor.com
Godfather Tom Hagen GIF
Alt: Gif from the godfather where Mike tells Tom Hagen (played by Robert Duvall) that he is out. Tom answers “why am I out”
000
Xavier Rene-Corail @xcorail.bsky.social · 29/01/2026
Not a Waymo forcing the passage and cutting the line in a In-n-Out drive in 🤦‍♂️
Cars are lined up in a fast food drive in and a self-driving Waymo car is trying to cut the line and insert into it.
100
Xavier Rene-Corail @xcorail.bsky.social · 21/01/2026
This is amazing. Use a SAST to detect security issues, and then triage those alerts with LLMs, to remove false positives and focus on real and exploitable issues. And of course, the framework is open source.
031
Reposted by Xavier Rene-Corail
GitHub Security Lab @securitylab.github.com · 11/11/2025
🚀 GitHub is making Actions more secure by default We recently announced upcoming changes to the pull_request_target event and environment protection rules to make GitHub Actions more secure by default. We’ve opened a discussion to gather feedback 👇 🔗 github.com/orgs/communi...
github.com
Towards a secure by default GitHub Actions · community · Discussion #179107
Why are you starting this discussion? Product Feedback What GitHub Actions topic or product is this about? Workflow Configuration Discussion Details Today, GitHub announced upcoming changes to the ...
064
Reposted by Xavier Rene-Corail
GitHub @github.com · 20/10/2025
The internet was on fire. 🔥 One small library affecting billions of systems. Log4Shell was the biggest security vulnerability of all time. Now, Log4J maintainer, Christian Grobmeier tells us what it felt like inside the flames 👉 github.blog/open-source/...
510918
Reposted by Xavier Rene-Corail
GitHub Education @githubeducation.bsky.social · 20/10/2025
“Ignorance will break all software.” Log4Shell’s one line of code broke the internet, and taught us all a lesson we can’t ignore. As Christian Grobmeier, maintainer of Log4J puts it: "Learning is the only cure for ignorance. So just keep learning."
001
Xavier Rene-Corail @xcorail.bsky.social · 12/10/2025
😭
media.tenor.com
a woman in a striped coat is standing in front of a man
ALT: a woman in a striped coat is standing in front of a man
000
Reposted by Xavier Rene-Corail
GitHub @github.com · 30/09/2025
We're taking action to make the npm supply chain stronger and harder to attack. 🛡️ Check out our plan to create a more secure future for the JavaScript community.👇 github.blog/security/supply-chain-s…
github.blog
Our plan for a more secure npm supply chain
GitHub is strengthening npm's security with stricter authentication, granular tokens, and enhanced trusted publishing.
12910
Reposted by Xavier Rene-Corail
GitHub Security Lab @securitylab.github.com · 23/09/2025
Recent account takeovers and attacks on package registries are a wake-up call: it's time to raise the bar on authentication and secure publishing practices. Find out what npm is doing—and what steps you can take—to help secure the open source supply chain: github.blog/security/sup...
github.blog
Our plan for a more secure npm supply chain
GitHub is strengthening npm's security with stricter authentication, granular tokens, and enhanced trusted publishing.
133
Xavier Rene-Corail @xcorail.bsky.social · 02/09/2025
RIP Graham Greene.
media.tenor.com
a close up of a man with the words we come far
Alt: a close up of a dialogue between Greene and Costner in “Dance with wolves”: Greene: we come far you and me - Costner: I will not forget you
010
Xavier Rene-Corail @xcorail.bsky.social · 05/08/2025
Hey security people, if you’re in Las Vegas, say hi! If you want to talk open source security, or GitHub security products, I’d be happy to chat!
000
Reposted by Xavier Rene-Corail
GitHub Security Lab @securitylab.github.com · 05/08/2025
Are you at Security BSides Las Vegas? Our very own Madison Oliver is joining a panel on the evolving role of the CVE Program — from funding challenges to global coordination and new governance models. ℹ️ pretalx.com/security-bsi... 🗓️ August 5 | ⏰ 13:00–13:45 PT
lnkd.in
LinkedIn
This link will take you to a page that’s not on LinkedIn
011
Xavier Rene-Corail @xcorail.bsky.social · 23/06/2025
Anyone else going to #ossna and flight to Denver is delayed, without visibility?
000
Reposted by Xavier Rene-Corail
kat cosgrove @kat.lol · 22/06/2025
If you, a business, are reliant on an open source project to function it is YOUR responsibility to assess and ensure the health of that project by either contributing to it yourself or by using an alternative if project health cannot be guaranteed.
736470
Xavier Rene-Corail @xcorail.bsky.social · 04/06/2025
It’s free. It’s fun. It’s easy. Learn about secure coding with the GitHub secure code game.
010
Reposted by Xavier Rene-Corail
GitHub @github.com · 28/05/2025
Is your open source project built on a foundation of trust and security? 🛡️ Strengthen its future with essential practices like MFA, code scanning, safe dependency management, and private vulnerability reporting. 🔐 Learn how to implement these to protect your project and users with this guide. ⬇️
opensource.guide
Security Best Practices for your Project
Strengthen your project’s future by building trust through essential security practices — from MFA and code scanning to safe dependency management and private vulnerability reporting.
0387
Reposted by Xavier Rene-Corail
GitHub Security Lab @securitylab.github.com · 09/05/2025
Season 3 of the GitHub Secure Code Game is coming — AI enters the chat 🤖🔥 Catchup with Season 1 and 2 at gh.io/secure-code-game
0106
Reposted by Xavier Rene-Corail
Matt Mitovich @mattmitovich.bsky.social · 26/04/2025
Star Wars has released one hour of Mon Mothma dancing. #Andor www.youtube.com/watch?v=y6wL...
youtube.com
ONE HOUR OF DANCING MON MOTHMA | Andor Season 2 | Disney+
YouTube video by Star Wars
092
Xavier Rene-Corail @xcorail.bsky.social · 15/04/2025
Finally watched the first episode of The Studio. OMG this is hilarious. I must admit I had a hard time with the disrespect of my hero Marty … I’ll get over it, but it was a difficult moment.
000
Xavier Rene-Corail @xcorail.bsky.social · 03/04/2025
So … Heat or Tombstone tonight? 😢 RIP Val Kilmer
media.tenor.com
a man with a mustache wearing a cowboy hat and saying say when
ALT: a man with a mustache wearing a cowboy hat and saying say when
010
Reposted by Xavier Rene-Corail
Peter Stöckli @ulldma.bsky.social · 13/03/2025
In this demonstration I show the impact of CVE-2025-25291/CVE-2025-25292, an authentication bypass in ruby-saml used by high profile OSS projects such as GitLab. My team coordinated with both the ruby-saml maintainer and GitLab to get this vulnerability fixed and patches are available at gh.io/glfx
1223
Reposted by Xavier Rene-Corail
GitHub Security Lab @securitylab.github.com · 14/02/2025
Happy Friday folks! Here is a throwback to our 2nd most popular research post of 2024, "Gaining kernel code execution on an MTE-enabled Pixel 8" by Man yue Mo github.blog/security/vul...
github.blog
Gaining kernel code execution on an MTE-enabled Pixel 8
In this post, I’ll look at CVE-2023-6241, a vulnerability in the Arm Mali GPU that allows a malicious app to gain arbitrary kernel code execution and root on an Android phone. I’ll show how this vulne...
032
Reposted by Xavier Rene-Corail
Martin Woodward @martin.social · 14/02/2025
Sure, chocolates are nice and all but why not show your favourite open source projects how much you love them by sponsoring them today! github.blog/open-source/...
github.blog
Support the open source projects you love this Valentine’s Day
You can help provide much-needed support to the critical but often underfunded projects that keep your infrastructure running smoothly.
01714
Reposted by Xavier Rene-Corail
Steven Beschloss @stevenbeschloss.bsky.social · 09/02/2025
Don’t just say DEI as if it’s a bad word. Spell it out. Say diversity, which is the lifeblood of American society & culture & innovation. Say equity, which a just society should pursue. Say inclusion, because decent people believe in increasing belonging, not isolating people who are different.
874283258793
Reposted by Xavier Rene-Corail
GitHub @github.com · 09/02/2025
Security researchers are digital detectives, safeguarding the internet by uncovering vulnerabilities. 🔍 Start your journey in cybersecurity research today. ⬇️ github.blog/security/vul...
github.blog
Cybersecurity researchers: Digital detectives in a connected world
Discover the exciting world of cybersecurity research: what researchers do, essential skills, and actionable steps to begin your journey toward protecting the digital world.
723631
Reposted by Xavier Rene-Corail
GitHub Security Lab @securitylab.github.com · 06/02/2025
Hello from the GitHub Security Lab! We are a team of security experts who cultivate a collaborative community where developers and security professionals come together to secure open source software.
2105
Reposted by Xavier Rene-Corail
Patrick C Miller @patrickcmiller.bsky.social · 04/02/2025
768 CVEs Exploited in the Wild in 2024
buff.ly
768 CVEs Exploited in the Wild in 2024
VulnCheck observed 768 public reports of CVEs exploited in the wild for the first time in 2024, a 20% rise compared to 2023
001
Xavier Rene-Corail @xcorail.bsky.social · 10/01/2025
Jacques Audiard is a genius, Zoe Saldana is a queen. #emilaperez
000
Reposted by Xavier Rene-Corail
GitHub @github.com · 17/12/2024
Prepare to take flight 👀
1817119
Reposted by Xavier Rene-Corail
Abby Cabunoc Mayes @abbycabs.dev · 10/12/2024
Excited to see Ecosyste.ms data guiding funding with the launch of Ecosystem Funds! This helps support critical open source projects that often fly under the radar. Congrats to Open Source Collective & Ecosyste.ms on the launch! 🎉 opencollective.com/opensource/u... #OpenSource #Funding
opencollective.com
Ecosystem Funds: Curated Support For Your Critical Software Dependencies - Open Source Collective
Today Open Source Collective is launching Ecosystem Funds, making it easier to support your critical software dependencies. st...
0114
Xavier Rene-Corail @xcorail.bsky.social · 05/12/2024
Just watched Possession (A. Zulawski, 1983) for the first time. What a shock! It hurts, almost physically. Adjani’s acting is out of this world.
010
Reposted by Xavier Rene-Corail
Martin Woodward @martin.social · 03/12/2024
Achtung Freunde - GitHub is expanding our DevRel team, and we'd love to hire an amazing Senior Developer Advocate based out of Munich, Germany! If you know someone who would be perfect, please share this with them! #jobs #hiring githubinc.jibeapply.com/jobs/3760
githubinc.jibeapply.com
Senior Developer Advocate in Germany | GitHub, Inc.
GitHub, Inc. is hiring a Senior Developer Advocate in Germany. Review all of the job details and apply today!
48225
Xavier Rene-Corail @xcorail.bsky.social · 01/12/2024
Saw Wicked with the family, and everyone loved it! Cynthia and Ariana are soooo good!
010
Xavier Rene-Corail @xcorail.bsky.social · 30/11/2024
We (French) are so lucky! The new us ambassador in France is Trump’s son-in-law’s father, also a convicted felon, with no background in diplomacy! Yay! www.bfmtv.com/internationa...
bfmtv.com
Donald Trump nomme Charles Kushner, le père de son gendre, comme ambassadeur des États-Unis en France
Le prochain ambassadeur des États-Unis en France est le père de Jared Kushner. Ce dernier est marié à Ivanka Trump, la fille de Donald Trump.
100
Xavier Rene-Corail @xcorail.bsky.social · 25/11/2024
Watching « Dream scenario ». We need more Nicolas Cage in all the movies!
010
Xavier Rene-Corail @xcorail.bsky.social · 19/11/2024
A new initiative to help open source projects be more secure, with funds from partners and training from the GitHub Security Lab and other experts t.co/oshXlcwdmX
t.co
https://github.blog/news-insights/company-news/announcing-github-secure-open-source-fund/
021
Xavier Rene-Corail @xcorail.bsky.social · 18/11/2024
Finished « the penguin ». Great show! Great actors, tight writing.
110
Xavier Rene-Corail @xcorail.bsky.social · 18/11/2024
Just came back from the #ekoparty conference in Argentina. It was great to meet this great #infosec community! See you next year!
020