Zach Steindler

260 posts

Zach Steindler banner
Zach Steindler

Zach Steindler

@steiza

Hacker, cooker, hiker

Ann Arbor, MI Katılım Aralık 2008
384 Takip Edilen502 Takipçiler
Zach Steindler
Zach Steindler@steiza·
Looking at push activity is so much better than individual commits. Pushes are authenticated, unlike commit author identity. Looking at pushes you can more easily verify security practices, like requiring reviews (see #source-track" target="_blank" rel="nofollow noopener">slsa.dev/spec/v1.0/futu…). Excited to see where this goes!
GitHub@github

It's now easier to understand changes to your repositories with the new activity view. This new activity view gives you the ability to self-serve insights to your favorite repository and all of its changes. github.blog/changelog/2023…

English
1
3
17
3.6K
Zach Steindler retweetledi
OpenSSF
OpenSSF@openssf·
We Want to Hear from You 🔊👂➡️ Take the OpenSSF Software Security Awareness Survey openssf.org/blog/2023/05/1…
OpenSSF tweet media
English
0
8
4
1.4K
Zach Steindler
Zach Steindler@steiza·
Big day for open source security! npm worked with the open source project Sigstore to put together a beta of provenance, verifiably tying npm packages back to their source code and build instructions: github.blog/2023-04-19-int…
English
0
14
36
4.2K
Zach Steindler retweetledi
OpenSSF
OpenSSF@openssf·
Today we're proud to announce the release of version 1.0 of SLSA 🎉 Supply-chain Levels for Software Artifacts is an OpenSSF project that provides specifications for software supply chain security, established by community expert consensus. #OSSecurity
OpenSSF tweet media
English
1
39
66
28.2K
Zach Steindler retweetledi
Clint Gibler
Clint Gibler@clintgibler·
🗒️ gh-sbom A gh CLI extension that outputs JSON SBOMs (in SPDX or CycloneDX format) for your GitHub repository github.com/advanced-secur…
English
0
6
17
1.3K
Zach Steindler retweetledi
sMyle (🦋 @myles.dev)
sMyle (🦋 @myles.dev)@MylesBorins·
Extremely excited about this. The npm team has been collaborating with GitHub's package security team for months putting together an RFC to improve the audibility and trust of npm packages using SigStore and trusted build infrastructure github.blog/2022-08-08-new…
English
3
50
179
0
Zach Steindler retweetledi
GitHub
GitHub@github·
Want to use GitHub-hosted Actions runners, but need to access resources on your private network? You’re in luck! We’ve documented 3 ways to do it ⬇️. github.co/3NbDkJE
English
0
15
64
0
Zach Steindler
Zach Steindler@steiza·
@bdimcheff @akgood Yeah, you run the SSH CA, so you can have it enforce whatever requirements you'd like! Maybe you could convince @akgood to open source a serverless SSH CA that runs on GCP 👀
English
0
0
2
0