Dan Lorenc(@lorenc_dan) 's Twitter Profileg
Dan Lorenc

@lorenc_dan

OSS Supply Chain Security. Founder/CEO/Primary Ariba Admin at https://t.co/sGmuUU9JbG

Sigstore: https://t.co/dWKlyYu6kv

ID:2474676878

linkhttp://dlorenc.medium.com calendar_today02-05-2014 23:47:30

12,9K Tweets

9,4K Followers

2,0K Following

Abhishek Arya(@infernosec) 's Twitter Profile Photo

OSV.dev, the community vulnerability database aggregation service for open source crosses the 100k mark (115,054 vulns), thanks to the OpenSSF OSV schema (github.com/ossf/osv-schema) standardization across 24 language and distro ecosystems!

account_circle
Ed Targett(@editortargett) 's Twitter Profile Photo

Bloody oath can someone fix , say 50+ pros incl. Dan Lorenc (or words to that effect)

One source tells me a CNA punted NVD a bunch of borked CVE data/files and it's still cleaning up the mess because... legacy tech. Couldn't confirm

thestack.technology/nvd-crisis-vul…

account_circle
Wiz(@wiz_io) 's Twitter Profile Photo

is just around the corner...

Time to unveil our star-studded speaker line-up 📢

🎤 Corey Quinn from The Duckbill Group
🎤 Christopher Hughes
🎤 Tyler Waldo from Salesforce
🎤 Dan Lorenc from Chainguard ⛓️

Secure your spot below! 🔍
wiz.io/events/misconf…

#MisCONfigured is just around the corner... Time to unveil our star-studded speaker line-up 📢 🎤 @QuinnyPig from @DuckbillGroup 🎤 @ResilientCyber 🎤 Tyler Waldo from @salesforce 🎤 @lorenc_dan from @chainguard_dev Secure your spot below! 🔍 wiz.io/events/misconf…
account_circle
@msw@mstdn.social 🐍🦀🐪💎☕️🐧🐘🌲(@_msw_) 's Twitter Profile Photo

Bogus CVE of the day, in which the only concession for the maintainer is a “** DISPUTED **” tag that doesn’t even show up on the imported record on the NVD website.

account_circle
OpenSSF(@openssf) 's Twitter Profile Photo

Hayden Blauzvern from Google's open source security team discusses how Sigstore is prioritizing package managers as the main avenue for Sigstore adoption.
Learn more about Sigstore: openssf.org/projects/sigst…

Hayden Blauzvern from Google's open source security team discusses how Sigstore is prioritizing package managers as the main avenue for Sigstore adoption. Learn more about Sigstore: openssf.org/projects/sigst… #SOSSCommunity
account_circle
Eric Geller(@ericgeller) 's Twitter Profile Photo

The U.S. government has a Microsoft problem.

Market dominance, inertia, and savvy PR have almost completely insulated the hack-plagued company from meaningful oversight, even as Biden officials preach corporate accountability.

My new WIRED story: wired.com/story/the-us-g…

The U.S. government has a Microsoft problem. Market dominance, inertia, and savvy PR have almost completely insulated the hack-plagued company from meaningful oversight, even as Biden officials preach corporate accountability. My new @WIRED story: wired.com/story/the-us-g…
account_circle
Dan Lorenc(@lorenc_dan) 's Twitter Profile Photo

We've been tuning bincapz to reduce false positives after scanning it across all the packages in Wolfi OS.

Give it a try, the results are getting really good: github.com/chainguard-dev…

account_circle
Abhishek Arya(@infernosec) 's Twitter Profile Photo

'Those sources said the breach appears to have started when the attackers somehow gained access to the company’s Gitlab code repository, and in that repository was a token or credential that gave the bad guys access to Sisense’s Amazon S3 buckets in the cloud.' - Bearer…

account_circle
Jim Jagielski(@jimjag) 's Twitter Profile Photo

When it was alleged that OpenTofu 'stole' HashiCorp's code, it was all over the IT news. Now that OpenTofu has proved that those allegations were false and self serving, I hope that the news is just as widespread.

account_circle
Dan Lorenc(@lorenc_dan) 's Twitter Profile Photo

Really impressed by how quickly the valkey community has come together and established a place to continue work.

Looking forward to their first release! github.com/valkey-io/valk…

account_circle
Dan Lorenc(@lorenc_dan) 's Twitter Profile Photo

'fauxpen source' is perfect.

The LF's work here often goes unseen, but they're a huge force protecting OSS, even when it's not popular.

theregister.com/2024/04/12/lin…

account_circle