Tracy Miranda(@tracymiranda) 's Twitter Profileg
Tracy Miranda

@tracymiranda

Making open source secure by default.

Previously at @chainguard_dev, @cdeliveryfdn, @cloudbees.

Open source powered.
🇨🇦 🇬🇧 🇰🇪

ID:67430296

linkhttps://tracymiranda.com calendar_today20-08-2009 21:29:45

7,6K Tweets

4,0K Followers

3,7K Following

Matija Sosic(@MatijaSosic) 's Twitter Profile Photo

With Ⓞrbit shutting down, the importance of open-source is even more obvious. People who used it (including us at Wasp) are left with only a JSON.

It seems like there is a gap for a good, modern open-source community tracker. Anybody care to build one?

account_circle
Cyber Statecraft(@CyberStatecraft) 's Twitter Profile Photo

Key takeaways:  More general funding moderately correlates with better security practices in open source projects 🔓

This trend occurs across multiple Scorecard checks, not just a single security practice. Also cool? More funders backing a project, stronger correlation!

account_circle
Cyber Statecraft(@CyberStatecraft) 's Twitter Profile Photo

🚨NEW ISSUE BRIEF🚨: Can money help open source software security? A new Cyber Statecraft paper by John Speed Meyers, Sara Ann Brackett, and Stew Scott looks at the funding and @OpenSSF Scorecard scores of top npm and Python packages. 💵🔐💻

account_circle
William Woodruff (1.3.6.1.4.1.55738)(@8x5clPW2) 's Twitter Profile Photo

PyPI now has three new Trusted Publishing, thanks (in part) to our work at Trail of Bits! This realizes our goal of expanding Trusted Publishing to compute environments outside of GitHub Actions:

blog.pypi.org/posts/2024-04-…

account_circle
Tracy Miranda(@tracymiranda) 's Twitter Profile Photo

🥳Great to see the many familiar and fresh faces ready to commit their energy to help improve the industry's delivery practices.

account_circle
puerco(@puerco) 's Twitter Profile Photo

This has been one of the most exciting projects I've worked on. Thanks to Cybersecurity and Infrastructure Security Agency and DHS S&T for enabling its development with such a wonderful initiative. And to OpenSSF, our new home 😊

account_circle
Tracy Miranda(@tracymiranda) 's Twitter Profile Photo

Gotta love Madelyn Olson's choice of Taylor Swift's 'We Are Never Ever Getting Back Together' as the walk on music for the Valkey keynote 🤣🤣🤣

Valkey

Gotta love @reconditerose's choice of Taylor Swift's 'We Are Never Ever Getting Back Together' as the walk on music for the Valkey keynote 🤣🤣🤣 #OSSummit @valkey_io
account_circle
🦊 Michael Friedrich 🌈(@dnsmichi) 's Twitter Profile Photo

Reading the HashiCorp Cease & Desist letter in opentofu.org/blog/our-respo… makes me sad.

The response from OpenTofu is fair and kind. A project and community well worth contributing to IMHO.

account_circle
Aurélie Vache 🥑🐳🦸‍♀️✏️(@aurelievache) 's Twitter Profile Photo

Breaking news n°2 🥳

The 8th of May for CloudNativeCanada I will be at Montreal to present my brand new talk 'Understanding Kubernetes in a visual way' at OVHcloud Canada office ❤️

Breaking news n°2 🥳 The 8th of May for @CloudNativeCA I will be at Montreal to present my brand new talk 'Understanding Kubernetes in a visual way' at @OVHcloud_CA office ❤️
account_circle
Tracy Miranda(@tracymiranda) 's Twitter Profile Photo

Ooh a new foundation, welcome! Excited to learn more.

I like the emphasis on succession planning - that is incredibly difficult to achieve in OSS and look forward to seeing how this is approached.

account_circle
Abhishek Arya(@infernosec) 's Twitter Profile Photo

Thoughts on xz backdoor. 1) Lack of a robust identity system on github (except when there is a tie-in to an organization which is slightly better). Anyone can create as many sock puppets accounts to do code reviews, nudge maintainers to add someone malicious as co-maintainers,…

account_circle
Richard Seroter(@rseroter) 's Twitter Profile Photo

You can always count on killer recaps from Daniel Bryant.

In this Syntasso post, he looks back at Kubecon and sees a lot of focus on 'platform as product.'

syntasso.io/post/kubecon-e…

account_circle