Parth Patel

149 posts

Parth Patel banner
Parth Patel

Parth Patel

@pxp928

Kusari - Software Supply Chain Security

Katılım Kasım 2021
120 Takip Edilen113 Takipçiler
Parth Patel retweetledi
Brandon Lum
Brandon Lum@lumjjb·
It's so awesome hearing about the multiple shoutouts to 🥑GUAC during the @KubeCon_ keynotes!!! Really wished I could be there in person! Appreciate the call outs and looking forward to engaging with new community members! See you in slack! guac.sh/community/
English
0
1
3
191
Parth Patel retweetledi
Mihai Maruseac
Mihai Maruseac@mihaimaruseac·
GUAC, SLSA and Sigstore mentioned several times at first keynote of #sossfusion (and other similar high quality projects)
English
0
2
7
272
Parth Patel retweetledi
Brandon Lum
Brandon Lum@lumjjb·
Hi All! I’ll be talking about SBOMs and how Google produces and uses them for EO 14028 and beyond at this webinar tomorrow! Hope to see you there!
Anchore@anchore

📝 SBOMs are critical for a handful of reasons: #visibility into dependencies, enhance #security, meet #compliance and streamline development. Learn how Google is using our Syft #SBOM #opensource #SBOM tool in our upcoming webinar. get.anchore.com/how-sboms-prot…

English
1
4
5
593
Parth Patel retweetledi
Michael Lieberman
Michael Lieberman@mlieberman85·
I know everyone wants to work on the cool thing or save/make a ton of money by throwing AI at a problem but it's extraordinarily dangerous. How many folks are verifying that the provenance and that the code/training data isn't malicious or vulnerable?
Mihai Maruseac@mihaimaruseac

Model storage under attack (techcrunch.com/2024/05/31/hug…). Models are uninspectable, so the only solution to prevent tampering is to sign them. OpenSSF has a model signing SIG as part of the AI/ML WG. Both biweekly meetings are in the OpenSSF calendar. Also, github.com/sigstore/model…

English
0
2
6
406
Parth Patel retweetledi
Mihai Maruseac
Mihai Maruseac@mihaimaruseac·
We are happy to publish a whitepaper on how we're thinking on securing the AI supply chain both internally and for OSS. This is a culmination of nearly a year of thinking about this space, from people working on AI or security, across multiple Google PAs. research.google/pubs/securing-…
Mihai Maruseac@mihaimaruseac

Since all model serialization formats are vulnerable, it is better to sign models on training (or upload) and verify signatures before use. Much better to also record the entire supply chain provenance. Will have more on this, soon

English
0
4
22
2.2K
Parth Patel retweetledi
Brandon Lum
Brandon Lum@lumjjb·
🎉🥑🍅🧅I'm really excited as GUAC joins the OpenSSF community, allowing the project to continue to grow, and join forces with other partners and members in the OpenSSF in developing an open source knowledge graph! Looking forward to this next step in our journey!
OpenSSF@openssf

GUAC has joined the OpenSSF as an Incubating Project 🎉 GUAC is an open source supply chain security project that provides dependency management and actionable insights into the security of software supply chains. Read the announcement: openssf.org/blog/2024/03/0… #OSSSecurity

English
0
2
10
438
Parth Patel retweetledi
OpenSSF
OpenSSF@openssf·
GUAC has joined the OpenSSF as an Incubating Project 🎉 GUAC is an open source supply chain security project that provides dependency management and actionable insights into the security of software supply chains. Read the announcement: openssf.org/blog/2024/03/0… #OSSSecurity
English
0
13
30
2.3K
Parth Patel retweetledi
Michael Lieberman
Michael Lieberman@mlieberman85·
I’m out in Tokyo for talks at @openssf day and @linuxfoundation open source summit Japan. For folks who want to chat cybersecurity and GUAC hit me up.
English
0
2
10
252
Parth Patel retweetledi
Brandon Lum
Brandon Lum@lumjjb·
Increase your mental health on CVE drop days (I.e. recent curl vuln) by being prepared! Go in knowing your blast radius and prepared to patch and mitigate! In this blogpost @pxp928 , @mihaimaruseac and I use GUAC to do this for last week’s CURL CVE. kusari.dev/blog/terror-of…
English
0
3
5
834
Parth Patel retweetledi
Brandon Lum
Brandon Lum@lumjjb·
🥑+🤖🧠=🔐 We got a super exciting GUAC community meeting coming up this week... which may or may not feature some LLMs!! Come join us and see some cool demos from @ridhoq @sozercan and more! Meeting invite details at guac.sh/community
English
0
9
12
2.3K