Sign in

Xavier Rene-Corail

@xcorail.bsky.social
228 followers 357 following 62 posts

Open source security at GitHub. I don’t believe in perfection, but in continuous improvement. Opinions here are mine.

PostsRepliesMedia
Xavier Rene-Corail @xcorail.bsky.social · 09/08/2026
Finally watching Cape Fear. I still prefer the movies, but the series is not bad either. And seeing Javier Bardem and Ron Perlman in the same frame is priceless!
020
Xavier Rene-Corail @xcorail.bsky.social · 28/06/2026
Beautiful camera, and big virtual hugs. The person was clearly frustrated at many things and took it in you. ❤️
010
Xavier Rene-Corail @xcorail.bsky.social · 21/04/2026
Hey 👋🏾 les amis! Si vous êtes à Paris pour @devoxx.fr, passez me voir sur le stand GitHub!
010
Xavier Rene-Corail @xcorail.bsky.social · 08/03/2026
Yes. Definitely. It was mocking the bigotry more than the gays. And it was the case also with the real original birdcage (la cage aux folles), that was a French play, before being transposed into the movie.
070
Reposted by Xavier Rene-Corail
Abby Cabunoc Mayes @abbycabs.dev · 02/03/2026
“AI is destroying my humanity.” @mitchellh.com (HashiCorp; Ghostty, Vouch). From a conversation @helen.blog and I had with him. Not an anti-AI take. A maintainer capacity take. Creation got cheaper. Review didn’t. Maintainers: what’s helped you keep mentoring sustainable?
1183
Xavier Rene-Corail @xcorail.bsky.social · 19/02/2026
Come say hi 👋 at DeveloperWeek.
000
Reposted by Xavier Rene-Corail
GitHub @github.com · 17/02/2026
Who knows how to secure open source better than the maintainers themselves? 🛡️
4277
Xavier Rene-Corail @xcorail.bsky.social · 16/02/2026
RIP Robert Duvall 😢
media.tenor.com
Godfather Tom Hagen GIF
Alt: Gif from the godfather where Mike tells Tom Hagen (played by Robert Duvall) that he is out. Tom answers “why am I out”
000
Xavier Rene-Corail @xcorail.bsky.social · 29/01/2026
Apparently it decided that the drive-in line was the best place to stop for picking up the rider 😂
010
Xavier Rene-Corail @xcorail.bsky.social · 29/01/2026
Not a Waymo forcing the passage and cutting the line in a In-n-Out drive in 🤦‍♂️
Cars are lined up in a fast food drive in and a self-driving Waymo car is trying to cut the line and insert into it.
100
Xavier Rene-Corail @xcorail.bsky.social · 25/01/2026
Thanks for what you’re doing for all of us Ian.
000
Xavier Rene-Corail @xcorail.bsky.social · 21/01/2026
This is amazing. Use a SAST to detect security issues, and then triage those alerts with LLMs, to remove false positives and focus on real and exploitable issues. And of course, the framework is open source.
031
Xavier Rene-Corail @xcorail.bsky.social · 14/12/2025
Ooooh, subscribing to this thread! My son is 16 and is also about to get his DL!
000
Xavier Rene-Corail @xcorail.bsky.social · 08/12/2025
But same: I rewatch a lot of movies … I use my kids, and their artistic education, as an excuse.
010
Xavier Rene-Corail @xcorail.bsky.social · 08/12/2025
media.tenor.com
a man in a tuxedo is talking to another man in a room with the words some day and that day may never come
Alt: The godfather (Marlon Brando) in a tuxedo is talking to another man in a room with the words some day and that day may never come, I’ll ask a service of you
110
Xavier Rene-Corail @xcorail.bsky.social · 08/12/2025
Oh hell no! … I saw it once, and I am never watching it again! lol 😂 Too realistic, too scarily probable. I haven’t ever looked at mushrooms the same way.
110
Reposted by Xavier Rene-Corail
GitHub Security Lab @securitylab.github.com · 11/11/2025
🚀 GitHub is making Actions more secure by default We recently announced upcoming changes to the pull_request_target event and environment protection rules to make GitHub Actions more secure by default. We’ve opened a discussion to gather feedback 👇 🔗 github.com/orgs/communi...
github.com
Towards a secure by default GitHub Actions · community · Discussion #179107
Why are you starting this discussion? Product Feedback What GitHub Actions topic or product is this about? Workflow Configuration Discussion Details Today, GitHub announced upcoming changes to the ...
064
Reposted by Xavier Rene-Corail
GitHub @github.com · 20/10/2025
The internet was on fire. 🔥 One small library affecting billions of systems. Log4Shell was the biggest security vulnerability of all time. Now, Log4J maintainer, Christian Grobmeier tells us what it felt like inside the flames 👉 github.blog/open-source/...
510918
Reposted by Xavier Rene-Corail
GitHub Education @githubeducation.bsky.social · 20/10/2025
“Ignorance will break all software.” Log4Shell’s one line of code broke the internet, and taught us all a lesson we can’t ignore. As Christian Grobmeier, maintainer of Log4J puts it: "Learning is the only cure for ignorance. So just keep learning."
001
Xavier Rene-Corail @xcorail.bsky.social · 19/10/2025
Oh, congrats Kara!
010
Xavier Rene-Corail @xcorail.bsky.social · 12/10/2025
😭
media.tenor.com
a woman in a striped coat is standing in front of a man
ALT: a woman in a striped coat is standing in front of a man
000
Reposted by Xavier Rene-Corail
GitHub @github.com · 30/09/2025
We're taking action to make the npm supply chain stronger and harder to attack. 🛡️ Check out our plan to create a more secure future for the JavaScript community.👇 github.blog/security/supply-chain-s…
github.blog
Our plan for a more secure npm supply chain
GitHub is strengthening npm's security with stricter authentication, granular tokens, and enhanced trusted publishing.
12910
Reposted by Xavier Rene-Corail
GitHub Security Lab @securitylab.github.com · 23/09/2025
Recent account takeovers and attacks on package registries are a wake-up call: it's time to raise the bar on authentication and secure publishing practices. Find out what npm is doing—and what steps you can take—to help secure the open source supply chain: github.blog/security/sup...
github.blog
Our plan for a more secure npm supply chain
GitHub is strengthening npm's security with stricter authentication, granular tokens, and enhanced trusted publishing.
133
Xavier Rene-Corail @xcorail.bsky.social · 03/09/2025
Yay!
010
Xavier Rene-Corail @xcorail.bsky.social · 02/09/2025
RIP Graham Greene.
media.tenor.com
a close up of a man with the words we come far
Alt: a close up of a dialogue between Greene and Costner in “Dance with wolves”: Greene: we come far you and me - Costner: I will not forget you
010
Xavier Rene-Corail @xcorail.bsky.social · 12/08/2025
When we see your smile for 2001 vs. Twilight, we know what the final result will be 😂
060
Xavier Rene-Corail @xcorail.bsky.social · 05/08/2025
Hey security people, if you’re in Las Vegas, say hi! If you want to talk open source security, or GitHub security products, I’d be happy to chat!
000
Reposted by Xavier Rene-Corail
GitHub Security Lab @securitylab.github.com · 05/08/2025
Are you at Security BSides Las Vegas? Our very own Madison Oliver is joining a panel on the evolving role of the CVE Program — from funding challenges to global coordination and new governance models. ℹ️ pretalx.com/security-bsi... 🗓️ August 5 | ⏰ 13:00–13:45 PT
lnkd.in
LinkedIn
This link will take you to a page that’s not on LinkedIn
011
Xavier Rene-Corail @xcorail.bsky.social · 23/06/2025
Anyone else going to #ossna and flight to Denver is delayed, without visibility?
000
Xavier Rene-Corail @xcorail.bsky.social · 23/06/2025
Throw them a volleyball and see what happens. We need to know.
010
Reposted by Xavier Rene-Corail
kat cosgrove @kat.lol · 22/06/2025
If you, a business, are reliant on an open source project to function it is YOUR responsibility to assess and ensure the health of that project by either contributing to it yourself or by using an alternative if project health cannot be guaranteed.
736470
Xavier Rene-Corail @xcorail.bsky.social · 16/06/2025
I am curious now … which one?
010
Xavier Rene-Corail @xcorail.bsky.social · 04/06/2025
It’s free. It’s fun. It’s easy. Learn about secure coding with the GitHub secure code game.
010
Xavier Rene-Corail @xcorail.bsky.social · 29/05/2025
Depends. It would take me too long to arrive … I would make long pauses on the grass!
010
Reposted by Xavier Rene-Corail
GitHub @github.com · 28/05/2025
Is your open source project built on a foundation of trust and security? 🛡️ Strengthen its future with essential practices like MFA, code scanning, safe dependency management, and private vulnerability reporting. 🔐 Learn how to implement these to protect your project and users with this guide. ⬇️
opensource.guide
Security Best Practices for your Project
Strengthen your project’s future by building trust through essential security practices — from MFA and code scanning to safe dependency management and private vulnerability reporting.
0387
Reposted by Xavier Rene-Corail
GitHub Security Lab @securitylab.github.com · 09/05/2025
Season 3 of the GitHub Secure Code Game is coming — AI enters the chat 🤖🔥 Catchup with Season 1 and 2 at gh.io/secure-code-game
0106
Xavier Rene-Corail @xcorail.bsky.social · 02/05/2025
It’s a long time wish. I remember when he was invited by Macron to the French military parade (Bastille day) in 2017 he said he wanted to do a similar parade in the US.
010
Xavier Rene-Corail @xcorail.bsky.social · 27/04/2025
So relatable. Thank you Ashley ❤️
010
Reposted by Xavier Rene-Corail
Matt Mitovich @mattmitovich.bsky.social · 26/04/2025
Star Wars has released one hour of Mon Mothma dancing. #Andor www.youtube.com/watch?v=y6wL...
youtube.com
ONE HOUR OF DANCING MON MOTHMA | Andor Season 2 | Disney+
YouTube video by Star Wars
092
Xavier Rene-Corail @xcorail.bsky.social · 20/04/2025
Agree. I think the best (worst?) episodes are when the plot is so plausible.
010
Xavier Rene-Corail @xcorail.bsky.social · 17/04/2025
There is one sentence in all this non-sense that I agree with: « this film has to happen » - please DO IT!
010
Xavier Rene-Corail @xcorail.bsky.social · 15/04/2025
Finally watched the first episode of The Studio. OMG this is hilarious. I must admit I had a hard time with the disrespect of my hero Marty … I’ll get over it, but it was a difficult moment.
000
Xavier Rene-Corail @xcorail.bsky.social · 03/04/2025
So … Heat or Tombstone tonight? 😢 RIP Val Kilmer
media.tenor.com
a man with a mustache wearing a cowboy hat and saying say when
ALT: a man with a mustache wearing a cowboy hat and saying say when
010
Reposted by Xavier Rene-Corail
Peter Stöckli @ulldma.bsky.social · 13/03/2025
In this demonstration I show the impact of CVE-2025-25291/CVE-2025-25292, an authentication bypass in ruby-saml used by high profile OSS projects such as GitLab. My team coordinated with both the ruby-saml maintainer and GitLab to get this vulnerability fixed and patches are available at gh.io/glfx
1223
Xavier Rene-Corail @xcorail.bsky.social · 25/02/2025
Alright but can you bring your image out of the room, or does it get wiped out in the elevator?
110
Xavier Rene-Corail @xcorail.bsky.social · 24/02/2025
Does your outie code work on your innie’s machine?
1110
Xavier Rene-Corail @xcorail.bsky.social · 21/02/2025
Thanks for sharing this gem Alyssa! Added!
010
Xavier Rene-Corail @xcorail.bsky.social · 19/02/2025
media.tenor.com
two men hugging each other with the words " i know it was you fredo " on the bottom
ALT: two men hugging each other with the words " i know it was you fredo " on the bottom
010
Xavier Rene-Corail @xcorail.bsky.social · 16/02/2025
What? Where is Bad taste?
020
Reposted by Xavier Rene-Corail
GitHub Security Lab @securitylab.github.com · 14/02/2025
Happy Friday folks! Here is a throwback to our 2nd most popular research post of 2024, "Gaining kernel code execution on an MTE-enabled Pixel 8" by Man yue Mo github.blog/security/vul...
github.blog
Gaining kernel code execution on an MTE-enabled Pixel 8
In this post, I’ll look at CVE-2023-6241, a vulnerability in the Arm Mali GPU that allows a malicious app to gain arbitrary kernel code execution and root on an Android phone. I’ll show how this vulne...
032