José Miguel Parrella (JMP)

1.8K posts

José Miguel Parrella (JMP) banner
José Miguel Parrella (JMP)

José Miguel Parrella (JMP)

@bureado

Working on 🐧 and open source software

Katılım Haziran 2007
708 Takip Edilen2.3K Takipçiler
Jon Masters 🏴‍☠️
Jon Masters 🏴‍☠️@jonmasters·
Has anyone tried fingerprinting specific devices based solely on precisely timed packet responses? I bet that’s doable
English
7
1
5
2.1K
Gonza Alcaraz ⚡
Gonza Alcaraz ⚡@glcrzdev·
@kelseyhightower What's the solution though? In order to keep building modern software in the way we've been doing it, it seems we have to accept there's gonna be vulns like the xzutils backdoor every once in a while - many of which we won't find.
English
1
0
2
1.5K
José Miguel Parrella (JMP)
@brunoborges Adding machine-readable EOL annotations, but no one might be listening, and that’s why yanking the image might still be game.
English
1
0
1
128
Bruno Borges
Bruno Borges@brunoborges·
Scenario: the container image that your app is using is no longer supported, and it is outdated/insecure. But you don't know that. And the image maker can't update the software within. What should the maker of said image do to help you become aware of this problem?
English
15
2
1
8.9K
José Miguel Parrella (JMP) retweetledi
Rita Zhang
Rita Zhang@ritazzhang·
Live demoing how to use ⁦@OpenPolicyAgent⁩ Gatekeeper external data feature together with Ratify to validate license and vulnerabilities on app deployment. ⁦@jrrickard
Rita Zhang tweet mediaRita Zhang tweet mediaRita Zhang tweet mediaRita Zhang tweet media
English
2
7
45
6.3K
Rui Santos
Rui Santos@elrui·
@phenobarbital Pienso mas o menos lo mismo. Pero la verdad no sabemos si los apoyan o no, o si ellos mismos están aportando, no? Al menos hasta ahora no he sabido ni qué paquete es, pero puedo estar atrasado en la noticia 😜
Español
1
0
1
110
Jesus Lara
Jesus Lara@phenobarbital·
Durante la pandemia, el único developer de un paquete python que usaba murió, tuve que adoptarlo y darle mantenimiento hasta que otro entusiasta le hizo un fork y lo ha mejorado. Pero una *billion-dollar company* Hace blame de un open-source library sin siquiera apoyar al creador
Jesus Lara tweet media
Sam Altman@sama

we had a significant issue in ChatGPT due to a bug in an open source library, for which a fix has now been released and we have just finished validating. a small percentage of users were able to see the titles of other users’ conversation history. we feel awful about this.

Español
3
23
157
23.8K
José Miguel Parrella (JMP)
@hlalvesbr @brunoborges This is what I thought, too. There are plenty of tools that check if the templates are valid, but few that check if they are consistent with architecture or business goals.
English
0
2
2
708
Bruno Borges
Bruno Borges@brunoborges·
We need less Infrastructure as Code, and more Infrastructure Project Definition. We need tools that help *define* infrastructure, not IaC. Tools that can evaluate if the *definition* is valid. Tools that can help user easily versionize, compare, and debug. Less IaC, more IML.
English
9
4
39
13.8K
José Miguel Parrella (JMP)
@puerco @nscur0 Honest Q: isn’t the first part of strcat(“this is my SBOM”, “schema, verify it with this”) what we have today? If so, does this help get clueboms to the guessboms?
English
1
0
1
21
puerco
puerco@puerco·
@nscur0 Right in the Siemens example, they were using a subset of CDX to simplify things. I think it's fine because it's a subset and as u said @nscur0, internal. I'm terrified at the prospect of "this is my SBOM schema, verify it with this" everywhere.
English
1
0
1
46
Arkadiy Tetelman
Arkadiy Tetelman@arkadiyt·
@lorenc_dan "It's supposed to be much more than SCA" Can you give some examples? What do you think SBOM will be doing in the future? Even insofar as new functionality is added it still feels like an extension of SCA to me - a rebranding to sell products like @travismcpeak mentioned
English
2
0
2
172
Arkadiy Tetelman
Arkadiy Tetelman@arkadiyt·
Anyone else feel this way? Why do we need new terms for everything?
Arkadiy Tetelman tweet media
English
2
1
15
2.3K
José Miguel Parrella (JMP)
@jdorfman @fedora ...full applications like OpenERP, Drupal, Alfresco, etc. But pep8 brought more Plone and Trac into focus. OBS got me thinking about Koji so at the intersection of all of that was Bodhi. Confirmed by Dockerfile :) (2/x)
English
0
0
1
33
José Miguel Parrella (JMP)
@jdorfman @fedora This was a fun puzzle. Of course I built upon other's suspicions of Python and OBS. Seeing the shift in filetype prevalence first made me think of a project that changed its templating on a major release so I was going to look it up on CHANGELOG and I thought of... (1/x)
English
1
0
2
92
Justin Dorfman
Justin Dorfman@jdorfman·
Guess the open source project, and you'll win a Hoodie.
Justin Dorfman tweet media
English
15
1
19
6.3K
José Miguel Parrella (JMP) retweetledi
Lachlan Evenson
Lachlan Evenson@LachlanEvenson·
🎉🎉🎉 So excited to see this land. It's been great collaborating with @OCI_ORG on getting the specs updated to facilitate the storage and distribution of signatures, SBOMs and software supply chain security artifacts. Try it out today on ACR techcommunity.microsoft.com/t5/apps-on-azu…
English
1
12
36
8.6K
Jeff Wilcox
Jeff Wilcox@jeffwilcox·
I'm bummed that every day I just have to go through and report my entire personal Outlook dot com inbox as spam/phishing attempts/etc. There are some filters working, too - I have 80 junk mails that were flagged on top of these.
Jeff Wilcox tweet media
English
12
0
19
0
José Miguel Parrella (JMP) retweetledi
OCI Registry As Storage (ORAS)
OCI Registry As Storage (ORAS)@orasproject·
ORAS 0.15 has evolved into a fully functional OCI registry client. It provides fine-grained capabilities to alter the content of @OCI_ORG supply chain artifacts. Check out this blog by @FeynmanZhou and Yi to learn how to convert Docker image to OCI image: oras.land/blog/oras-0.15…
OCI Registry As Storage (ORAS) tweet media
English
0
7
18
0
José Miguel Parrella (JMP) retweetledi
MIT CSAIL
MIT CSAIL@MIT_CSAIL·
This MIT CS class teaches you things that all the other classes don't teach you, like... 🖥️ Shell tools and scripting 🖥️ Vim 🖥️ Data wrangling 🖥️ Command-line environment 🖥️ Version control Watch all 11 lectures for free here: bit.ly/MissSemester
MIT CSAIL tweet media
English
39
598
2.3K
0