Michael Prescott @ Sonatype

149 posts

Michael Prescott @ Sonatype banner
Michael Prescott @ Sonatype

Michael Prescott @ Sonatype

@devcasing

Product Director, Nexus Repository

Toronto, Ontario 加入时间 Kasım 2017
46 关注72 粉丝
Michael Prescott @ Sonatype
Michael Prescott @ Sonatype@devcasing·
@ecammtweets Ok, good to know! I can move to the next stage of grief now. Let me know if there are any former user meetups where we can all stare glumly at the punch bowl. :P
English
1
0
0
10
Ecamm #EcammFam
Ecamm #EcammFam@ecammtweets·
@devcasing Hi Michael! No, we don't have any plans to update iGlasses, unfortunately.
English
1
0
1
8
Michael Prescott @ Sonatype
Michael Prescott @ Sonatype@devcasing·
@ecammtweets Big fan of iGlasses. Any plans to update it to work with recent Mac OS versions? Mine loads but does nothing, and no apps seem to find it as a camera.
English
1
0
0
21
Michael Prescott @ Sonatype
Michael Prescott @ Sonatype@devcasing·
@Zoom Please add an affordance to this invisible button, every time I move the Zoom window on my desktop I turn off screen sharing without realizing it.
Michael Prescott @ Sonatype tweet media
English
0
0
1
18
Michael Prescott @ Sonatype 已转推
Brian Fox @brian_fox@fosstodon.org
I’ve spent much time thinking about why organizations struggle to understand the implications of the rise in malicious oss compared to typical vulnerabilities. It ultimately comes down to psychology. In this article, I explore the psychological barriers that prevent effective action against these threats. forbes.com/sites/forbeste…
English
2
4
7
837
Michael Prescott @ Sonatype 已转推
Ilkka Turunen
Ilkka Turunen@llkkaT·
🚨 an example of an adversary trying to push their malware as a coding solution. Please be careful with any dependencies
Ax Sharma@Ax_Sharma

A threat actor is now advising StackOverflow devs seeking debugging help to install a 'pytoileur' #Python package as a "solution" to their code troubles. 🛑DO NOT fall for this, it's a trap—the package has encoded code hidden on line 17 via whitespaces and infects Windows users with #trojan as soon as it's installed! sonatype.com/blog/pypi-cryp… #opensource #malware

English
0
1
2
236
Michael Prescott @ Sonatype 已转推
Ilkka Turunen
Ilkka Turunen@llkkaT·
The NVD backlog just went over 10,000 unanalysed issues
Ilkka Turunen tweet media
English
0
2
4
169
Michael Prescott @ Sonatype 已转推
Ilkka Turunen
Ilkka Turunen@llkkaT·
A stark reminder from the attack on XZ & libzma: It's more than a vulnerability, it's a calculated assault on the stretched open-source infrastructure of our digital world. Read my full take on the implications, actions you can take and the urgent call for collective vigilance blog.sonatype.com/cve-2024-3094-…
English
1
4
4
276
Michael Prescott @ Sonatype
Michael Prescott @ Sonatype@devcasing·
make direct, unprotected public registry access a real risk. Older supply chain attacks were trying to sneak a bad library into production, but newer attacks are targeting development secrets and infrastructure. Hard to develop securely when half the dev boxes have been owned!
English
0
0
0
14
Michael Prescott @ Sonatype
Michael Prescott @ Sonatype@devcasing·
We've changed our stance over the years, we now recommend actually blocking developer access to public registries and force everyone through the proxy. We used to think of that as draconian, but the explosion of supply chain attacks in volume and variety—
English
1
0
0
19
Michael Prescott @ Sonatype 已转推
Sonatype
Sonatype@sonatype·
📢 Today marks a new era! Introducing SBOM Manager - the industry's first integrated system of record for managing SBOMs! A powerful, one-stop shop for easy, cost-effective, and compliant #SBOM management, monitoring, and distribution. bit.ly/4cnJpPU
Sonatype tweet media
English
0
4
8
570
Michael Prescott @ Sonatype 已转推
Maury Cupitt
Maury Cupitt@maurycupitt·
How to get started with Repository Health Check (RHC) 2.0, available in Sonatype Nexus Repository Manager 3.3: share.sonatype.social/nfjeu
English
0
1
2
54
Michael Prescott @ Sonatype
Michael Prescott @ Sonatype@devcasing·
I don't cry that often, but every now and again I hit ⌘ + Option + m to add a comment to a Google doc in view-only mode. Chrome handles that as a request to minimize all fifty of my browser windows across five desktops and dump them in the Dock bar. T_T
English
0
0
1
42
Michael Prescott @ Sonatype 已转推
Brian Fox @brian_fox@fosstodon.org
Well, the CRA passed through committee in a way that will avoid further discussion. There's zero chance they knew there were still significant issues and yet here we are. Read more: devops.com/the-cyber-resi… Current status:
Brian Fox @brian_fox@fosstodon.org tweet media
English
2
9
19
3.1K