Shanie Weissman @ Work (@shaniewss) 's Twitter Profile
Shanie Weissman @ Work

@shaniewss

PLG Marketing @mend_io. Mostly listening in and sharing news about #free #developertools like @renovatebot. This is my work account.

ID: 1354003230112575488

calendar_today26-01-2021 09:48:33

81 Tweet

48 Takipçi

422 Takip Edilen

Shanie Weissman @ Work (@shaniewss) 's Twitter Profile Photo

Security research can be confusing to the open source user community. This blog post has some best practices for safely #PenTesting without raising unnecessary alarms. #malware #npm

Mend.io (@mend_io) 's Twitter Profile Photo

With "Entitlements," access to historical NVD advisories and enhanced secret scanning with redirect.pizza, developers can improve workflows, ensure security and focus on coding. Guy Bar-Gil explores GitHub's new features in our latest blog: go.mend.io/3xXiwR1

With "Entitlements," access to historical NVD advisories and enhanced secret scanning with redirect.pizza, developers can improve workflows, ensure security and focus on coding.

<a href="/GuyBarGil/">Guy Bar-Gil</a> explores <a href="/github/">GitHub</a>'s new features in our latest blog: go.mend.io/3xXiwR1
Sean Trantalis (@strantalis) 's Twitter Profile Photo

Check out this post Artem and I wrote how we took advantage of Renovate Bot to help us manage patching our ArgoCD Applications. #gitops #argocd #renovatebot Virtru virtru.com/blog/automate-…

Mend.io (@mend_io) 's Twitter Profile Photo

🚨Mend Supply Chain Defender blocked a massive dependency confusion attack by a single author who uploaded 168 packages to npm. Discover what happened, the list of malicious packages, and how to protect your organization from such attacks. go.mend.io/39JuXGx

🚨Mend Supply Chain Defender blocked a massive dependency confusion attack by a single author who uploaded 168 packages to npm. 
Discover what happened, the list of malicious packages, and how to protect your organization from such attacks. 
go.mend.io/39JuXGx
Mend.io (@mend_io) 's Twitter Profile Photo

Take a look at this Renovate Bot tutorial for insights on how to leverage the tool to reduce risk by automating dependency updates in software projects. go.mend.io/3tEFZUa #opensource Towards Dev

kcd_berlin (@kcd_berlin) 's Twitter Profile Photo

Welcoming Léon Dawert and Christian Hörl, Kubernetes Solution Architects from SysEleven, to KCD Berlin! They will demonstrate automating dependencies using Renovate Bot. Join them next week in Berlin! 🌞 🎟️: eventbrite.de/e/kubernetes-c…

Welcoming Léon Dawert and Christian Hörl, Kubernetes Solution Architects from <a href="/SysEleven/">SysEleven</a>, to KCD Berlin! They will demonstrate automating dependencies using <a href="/renovatebot/">Renovate Bot</a>.

Join them next week in Berlin! 🌞

🎟️: eventbrite.de/e/kubernetes-c…
Maciej Mensfeld (@maciejmensfeld) 's Twitter Profile Photo

💥 As we speak, someone is uploading malicious crypto-mining packages to npm every 5 minutes. It seems the attacker aims at systems that automatically install/mirror packages and elevates that to mine Monero. Over 220 packages uploaded so far. #javascript #SupplyChain 🦠

Maciej Mensfeld (@maciejmensfeld) 's Twitter Profile Photo

Ok, at the moment npm is being flooded with hundreds of packages containing cryptocurrency mining software... All of them are being reported by us at Mend.io to npm #javascript #opensource #npmjs

Maciej Mensfeld (@maciejmensfeld) 's Twitter Profile Photo

SweetAlerts2 a popular #javascript popup boxes lib is now displaying a new call-for-peace message randomly to Russian users visiting Russian websites: my.diffend.io/npm/sweetalert… This changed message may be unexpected to at least part of the users/websites using it.

Stéphane Goetz (@onigoetz) 's Twitter Profile Photo

How Swissquote is keeping software dependencies up-to-date with Renovate | by Stéphane Goetz | Swissquote Tech Blog medium.com/swissquote-eng…

Maciej Mensfeld (@maciejmensfeld) 's Twitter Profile Photo

☠️💥🦠 Watch out for the fake Nasdaq Private Market Intuit Mailchimp marketing package. This one is a a brandjacking of the official one with a tracking code inside: my.diffend.io/npm/mailchimp-… Found thanks to Mend.io Supply Chain Defender. #supplychain #opensource #javascript #security #DevSecOps

☠️💥🦠 Watch out for the fake <a href="/NPM/">Nasdaq Private Market</a> <a href="/Mailchimp/">Intuit Mailchimp</a> marketing package. This one is a a brandjacking of the official one with a tracking code inside: my.diffend.io/npm/mailchimp-…

Found thanks to <a href="/Mend_io/">Mend.io</a> Supply Chain Defender.

#supplychain #opensource #javascript #security #DevSecOps
Shanie Weissman @ Work (@shaniewss) 's Twitter Profile Photo

Everything you need to know about #software #dependencies and how to manage them, in this post I wrote with Guy Bar-Gil on the Mend.io Free #DeveloperTools blog. Renovate Bot mend.io/free-developer…

Mend.io (@mend_io) 's Twitter Profile Photo

There are many ways to manage dependencies, but one of Harsha Vardhan’s of In Plain English’s favorite ways is with Renovate Bot. Get the lowdown on how to utilize Renovate presets to manage #npm projects in this blog from JavaScript in Plain English: go.mend.io/3RkJ5ar

There are many ways to manage dependencies, but one of Harsha Vardhan’s of <a href="/inPlainEngHQ/">In Plain English</a>’s favorite ways is with <a href="/renovatebot/">Renovate Bot</a>.

Get the lowdown on how to utilize Renovate presets to manage #npm projects in this blog from <a href="/JS_PlainEnglish/">JavaScript in Plain English</a>: go.mend.io/3RkJ5ar
アルミ (@schrotthaufen) 's Twitter Profile Photo

It’s been almost two years since we decided to give Renovate Bot a shot at keeping our Ansible, and docker things updated. Today it created its 1000th pull request🥳 Thanks for making my life _a lot_ easier.

PnL (@pnl63962200) 's Twitter Profile Photo

ראיון עבודה לחברת סייבר: "ומה החולשות שלך?" "יש את CVE-2019-6644 ובטח יש עוד שאני לא מכיר"