laurent

112 posts

laurent

laurent

@lsim99

Open source security @Google

Katılım Haziran 2021
58 Takip Edilen144 Takipçiler
laurent retweetledi
OpenSSF
OpenSSF@openssf·
Discover the power of Structured Results in the #OpenSSF blog: hubs.la/Q02t84mF0 Tailor your security approach with detailed insights for precise policy enforcement. 🛡️✨
OpenSSF tweet media
English
0
6
8
4.4K
laurent
laurent@lsim99·
Amazing community collaboration: GitHub's Dependency review action now supports displaying and blocking PRs based on OpenSSF scorecard results github.com/actions/depend…
English
0
4
11
667
laurent retweetledi
Abhishek Arya
Abhishek Arya@infernosec·
Announcing the general availability of the V3 deps.dev API (All your OSS transitive dependencies belong to you!). Lot of new features like batch support, purl support, querying capabilities for new things like name similarity, SLSA attestations, etc! Check it out at blog.deps.dev/api-v3/
English
0
13
24
6.7K
laurent
laurent@lsim99·
Refining our notion of "critical projects" by augmenting the dependency graph with authorship information blog.deps.dev/combining-depe… What other insights can we glean with dependency and git information? Let us know if you have ideas!
English
0
1
3
255
laurent retweetledi
Abhishek Arya
Abhishek Arya@infernosec·
Excited to announce the big milestone on #OSV: We have now enriched 30K vulns from NVD CVE DB and added first-class support for C/C++ ecosystem inside OSV-Scanner. Check out osv.dev/blog/posts/int…! One-stop community DB and scanner for all your OSS vulnerability scanning needs!
English
1
9
22
3K
laurent retweetledi
Vijay Bolina
Vijay Bolina@vijaybolina·
second, @Google is expanding our open source security work with the @openssf by releasing new tools to protect the overall integrity of AI supply chains. (3/3) Sigstore for Models and Model Provenance. github.com/google/model-t…
English
0
3
4
821
laurent
laurent@lsim99·
Join us for the first SLSA Bay Area meet-up on Nov 16 in SF. You'll learn about the latest news on the #slsa standard for supply-chain and how to use it to secure your SDLC and AI pipelines. Register and propose a talk tinyurl.com/bay-area-meetu…
English
0
6
13
3.3K
laurent retweetledi
Marcela Melara, PhD
Marcela Melara, PhD@mas0mel·
5 days left to submit your papers or security-in-practice talks to the SCORED ‘23 workshop!
English
0
5
3
608
laurent retweetledi
JamieDavis
JamieDavis@TheDavisJam·
The deadline for the SCORED'23 workshop on software supply chain security is in about 2 weeks. That's enough time to put together a nice submission! scored.dev/call_for_paper…
English
0
3
7
974
laurent retweetledi
Marcela Melara, PhD
Marcela Melara, PhD@mas0mel·
Reminder: The call for papers/talks for the 2nd ACM SCORED workshop on SW Supply Chain security is open until June 30! Security-in-practice talks and short research papers welcome! Call for papers/talks: scored.dev/call_for_paper… Submission site: scored2023.hotcrp.com
English
0
8
8
3.7K
laurent retweetledi
Mihai Maruseac
Mihai Maruseac@mihaimaruseac·
Each dep brings others. Understanding the supply chain is as difficult as understanding universe. Now we have a telescope: GUAC reaches its v0.1 release. Find more on Google's security blog and come and join us in solving swaths of supply chain problems: security.googleblog.com/2023/05/announ…
English
0
6
10
759
laurent retweetledi
Abhishek Arya
Abhishek Arya@infernosec·
Thanks @github for featuring @theopenssf Scorecard project on ReadME blog-"In Scorecard we trust" by @snaveen(Endor) & Brian Russell(GOSST)."If you’re looking to start improving your software supply chain security, adopting Scorecard is a great first step" github.com/readme/guides/…
English
0
7
22
3.3K
laurent retweetledi
Abhishek Arya
Abhishek Arya@infernosec·
Announcing OSV-Scanner: a tool that gives OSS developers easy access to vulnerability info relevant to their project using OSV.dev DB (16 ecosystems, 39K+ vulns). Also, integrated with Scorecards vulns check to give vulns in dependencies - security.googleblog.com/2022/12/announ…
English
1
17
67
0
laurent retweetledi
Abhishek Arya
Abhishek Arya@infernosec·
Excited to welcome another builder to higher SLSA level compliance. Check out the #SLSA community blog post going into the details on how @googlecloud build can help you with SLSA L3 compliance - slsa.dev/blog/2022/12/g…
English
1
9
22
0
laurent
laurent@lsim99·
Super excited to announce another milestone for SLSA: Google GCB level 3 provenance for your containers can now be verified via the open-source, community-developed github.com/slsa-framework…. Check out the blog post slsa.dev/blog/2022/12/g…!. Stay tuned, more coming up soon!
English
0
6
18
0