Brandon Lum (@lumjjb) 's Twitter Profile
Brandon Lum

@lumjjb

🔑CNCF Security TAG Co-Chair Emiritus
💻Google Engineer
🎸Musician/Guitarist

All things Containers + Security... Opinions are my own...

ID: 118322028

calendar_today28-02-2010 08:50:04

784 Tweet

1,1K Followers

635 Following

Brandon Lum (@lumjjb) 's Twitter Profile Photo

Minor milestone unlocked: 1k followers!! Just in time to move to LinkedIn… 😂jk. Looking forward to sharing more about security and open source! And the occasional music related post!!! Cheers! 🎉

Brandon Lum (@lumjjb) 's Twitter Profile Photo

Someone thought it’d be funny to put two flights leaving at EXACTLY the same time (to similar places) next to each other. This should be fun. 😂

Someone thought it’d be funny to put two flights leaving at EXACTLY the same time (to similar places) next to each other. This should be fun. 😂
Brandon Lum (@lumjjb) 's Twitter Profile Photo

🎉🥑🍅🧅I'm really excited as GUAC joins the OpenSSF community, allowing the project to continue to grow, and join forces with other partners and members in the OpenSSF in developing an open source knowledge graph! Looking forward to this next step in our journey!

Royal Hansen (@royalhansen) 's Twitter Profile Photo

Great news today that GUAC has joined OpenSSF as an Incubating Project. Google and industry peers created GUAC as an open source security project that provides dependency management & insights into the security of software supply chains: openssf.org/blog/2024/03/0…… #OSSSecurity

Brandon Lum (@lumjjb) 's Twitter Profile Photo

Come get your signed copy of select chapters of the manning supply chain security book at the kusaridev booth during the booth crawl at 6pm! With Michael Lieberman and I!

Come get your signed copy of select chapters of the manning supply chain security book at the <a href="/kusaridev/">kusaridev</a> booth during the booth crawl at 6pm! With <a href="/mlieberman85/">Michael Lieberman</a> and I!
Brandon Lum (@lumjjb) 's Twitter Profile Photo

Yes we need more accurate and complete sboms and it’s great to see ecosystems be part of this effort. Since the “sausage factory” is the best place to know how the sausage is made.

OpenSSF (@openssf) 's Twitter Profile Photo

🥑 Join us for our FREE virtual Tech Talk on June 6, where we'll cover everything you need to know about #GUAC from both the maintainers' and implemented organizations' perspectives! Discover GUAC's recent release, roadmap plans, and ways to contribute. openssf.org/blog/2024/05/1…

🥑 Join us for our FREE virtual Tech Talk on June 6, where we'll cover everything you need to know about #GUAC from both the maintainers' and implemented organizations' perspectives! Discover GUAC's recent release, roadmap plans, and ways to contribute. openssf.org/blog/2024/05/1…
OpenSSF (@openssf) 's Twitter Profile Photo

💬 Meet our speakers: Rose Judge, Brandon Lum, Parth Patel, Umang Jain, and our moderator, David A. Wheeler! As we count down to GUAC Tech Talk, we're excited to introduce our lineup. Join us to hear their insights on GUAC and #OSSSecurity! Register now: openssf.org/resources/tech…

💬 Meet our speakers: Rose Judge, Brandon Lum, Parth Patel, Umang Jain, and our moderator, David A. Wheeler! As we count down to GUAC Tech Talk, we're excited to introduce our lineup. Join us to hear their insights on GUAC and #OSSSecurity!
Register now: openssf.org/resources/tech…
OpenSSF (@openssf) 's Twitter Profile Photo

🥑 Missed the OpenSSF Tech Talk on GUAC? Catch up now! GUAC enhances SBOM and #OSSSecurity by analyzing software components and identifying vulnerabilities. Read this blog for a summary of the Tech Talk highlights: openssf.org/blog/2024/06/1…

🥑 Missed the OpenSSF Tech Talk on GUAC? Catch up now! GUAC enhances SBOM and #OSSSecurity by analyzing software components and identifying vulnerabilities. Read this blog for a summary of the Tech Talk highlights: openssf.org/blog/2024/06/1…
Brandon Lum (@lumjjb) 's Twitter Profile Photo

Hi All! I’ll be talking about SBOMs and how Google produces and uses them for EO 14028 and beyond at this webinar tomorrow! Hope to see you there!

Brandon Lum (@lumjjb) 's Twitter Profile Photo

It's so awesome hearing about the multiple shoutouts to 🥑GUAC during the Kubecon_ keynotes!!! Really wished I could be there in person! Appreciate the call outs and looking forward to engaging with new community members! See you in slack! guac.sh/community/

Mihai Maruseac (@mihaimaruseac) 's Twitter Profile Photo

Yesterday we launch v1.0 of model signing library, taming the wild west of model formats and deserialization vulnerabilities. You can read more about why this is needed and why we picked Sigstore as main signing method at security.googleblog.com/2025/04/taming…