Tracy Miranda(@tracymiranda) 's Twitter Profileg
Tracy Miranda

@tracymiranda

Making open source secure by default.

Previously at @chainguard_dev, @cdeliveryfdn, @cloudbees.

Open source powered.
🇨🇦 🇬🇧 🇰🇪

ID:67430296

linkhttps://tracymiranda.com calendar_today20-08-2009 21:29:45

7,7K Tweets

4,0K Followers

3,7K Following

Anne Currie(@anne_e_currie) 's Twitter Profile Photo

This thread resonates. Better stuff (vaccines, platforms) comes along and if you are smart you move to it. That doesn't mean you made a bad initial decision. It just means that you always need to be open to change.

The same is very true of green platforms - greener stuff comes…

account_circle
Tracy Miranda(@tracymiranda) 's Twitter Profile Photo

Merkle Town is a great visualisation dashboard from Cloudflare for Certificate Transparency.

It's a fun way to understand the CT ecosystem: ct.cloudflare.com

The folks at Cloudflare are looking to revamp the dashboard. Please share any feedback you may have!

Merkle Town is a great visualisation dashboard from Cloudflare for Certificate Transparency. It's a fun way to understand the CT ecosystem: ct.cloudflare.com The folks at Cloudflare are looking to revamp the dashboard. Please share any feedback you may have!
account_circle
Héctor Fernández 💾💾💾💾 -- @hectorj2f@hachyderm(@hectorj2f) 's Twitter Profile Photo

Tracy Miranda I'm not sure how reliable is this info to be honest. But I'm part of the on-call rotation and I'm a Chainguard employee. I also know another organization which is part of the on call rotation and it isn't mentioned either in that paragraph 🤔.

account_circle
Tracy Miranda(@tracymiranda) 's Twitter Profile Photo

Oh, it really is a shame Chainguard no longer help operate the Sigstore public good instance.

Like open source maintenance, open source SRE is very challenging and the more hands, the better.

Many thanks to all those orgs who are keeping this very important service running!👏

Oh, it really is a shame Chainguard no longer help operate the Sigstore public good instance. Like open source maintenance, open source SRE is very challenging and the more hands, the better. Many thanks to all those orgs who are keeping this very important service running!👏
account_circle
Pete Wagner(@meofthecloud) 's Twitter Profile Photo

Early adopters of github attestions:
github.com/search?q=path%… (shout out stacklok !)

I don't see anyone signing a .deb yet, I was hoping to adapt some `cosign verify-blob` based stuff.

account_circle
Anaïs Urlichs(@urlichsanais) 's Twitter Profile Photo

This is so cool!! Kelly Shortridge

'in-browser security decision tree tool Deciduous can be used to generate these attack trees as code.'

Andrew Martin ⚡☸️ Michael Hausenblas Hacking Kubernetes (p. 31). O'Reilly Media.

kellyshortridge.com/blog/posts/dec…

account_circle
Matija Sosic(@MatijaSosic) 's Twitter Profile Photo

With Ⓞrbit shutting down, the importance of open-source is even more obvious. People who used it (including us at Wasp) are left with only a JSON.

It seems like there is a gap for a good, modern open-source community tracker. Anybody care to build one?

account_circle
Cyber Statecraft(@CyberStatecraft) 's Twitter Profile Photo

Key takeaways:  More general funding moderately correlates with better security practices in open source projects 🔓

This trend occurs across multiple Scorecard checks, not just a single security practice. Also cool? More funders backing a project, stronger correlation!

account_circle
Cyber Statecraft(@CyberStatecraft) 's Twitter Profile Photo

🚨NEW ISSUE BRIEF🚨: Can money help open source software security? A new Cyber Statecraft paper by John Speed Meyers, Sara Ann Brackett, and Stew Scott looks at the funding and @OpenSSF Scorecard scores of top npm and Python packages. 💵🔐💻

account_circle