Tracy Miranda(@tracymiranda) 's Twitter Profileg
Tracy Miranda

@tracymiranda

Making open source secure by default.

Previously at @chainguard_dev, @cdeliveryfdn, @cloudbees.

Open source powered.
🇨🇦 🇬🇧 🇰🇪

ID:67430296

linkhttps://tracymiranda.com calendar_today20-08-2009 21:29:45

7,7K Tweets

4,0K Followers

3,7K Following

Connor Mockett(@ConnorMockettWX) 's Twitter Profile Photo

Tornado reported north of Rigaud, Quebec at 5:40pm EST on the A-40. Report from Louise Power and Chantal MacKinnon. No damage reported.

Believe it was somewhere in the circled area.

account_circle
Stefan Prodan(@stefanprodan) 's Twitter Profile Photo

We are now publishing VEX documents for the enterprise distribution of Flux Project with the CVEs that do not affect the Flux controllers. github.com/controlplaneio…

Thanks OpenSSF for making maintainer's life easier with OpenVEX and vexctl 🤗

We are now publishing VEX documents for the enterprise distribution of @fluxcd with the CVEs that do not affect the Flux controllers. github.com/controlplaneio… Thanks @openssf for making maintainer's life easier with OpenVEX and vexctl 🤗
account_circle
Robin Bender Ginn(@rginn206) 's Twitter Profile Photo

Forming a commercial partnership program at our nonprofit was complicated yet necessary to help underwrite the development of our critical JavaScript technologies. Thanks to our OpenJS Board, CPC and @HeroDevs for breaking the mold on open source sustainability.

account_circle
miles ward(@milesward) 's Twitter Profile Photo

Okay! Many folks have pinged me for the ground truth on the UniSuper thing and I now better understand exactly what went down, and WHEW am I relieved. 

Punchline: this failure mode cannot affect other Google Cloud users.

Lemme explain:

account_circle
@olblak@fosstodon.org(@0lblak) 's Twitter Profile Photo

On the 19th of September, I am planning to attend the Continuous Delivery Foundation (CDF) mini summit in Vienna.
The CD mini summit is co-located with the Open Source summit Europe.

Submissions are open both for talk proposals and program committee members.

cd.foundation/blog/2024/05/0…

account_circle
William Woodruff (1.3.6.1.4.1.55738)(@8x5clPW2) 's Twitter Profile Photo

For the last 6 months, my team at Trail of Bits has been working with A-O and OpenSSF to bring build provenance to Homebrew.

Today, I'm pleased to announce that our work is in public beta! Read about our design and how you can verify bottles today:

blog.trailofbits.com/2024/05/14/a-p…

account_circle
Anne Currie(@anne_e_currie) 's Twitter Profile Photo

This thread resonates. Better stuff (vaccines, platforms) comes along and if you are smart you move to it. That doesn't mean you made a bad initial decision. It just means that you always need to be open to change.

The same is very true of green platforms - greener stuff comes

account_circle
Tracy Miranda(@tracymiranda) 's Twitter Profile Photo

Merkle Town is a great visualisation dashboard from Cloudflare for Certificate Transparency.

It's a fun way to understand the CT ecosystem: ct.cloudflare.com

The folks at Cloudflare are looking to revamp the dashboard. Please share any feedback you may have!

Merkle Town is a great visualisation dashboard from Cloudflare for Certificate Transparency. It's a fun way to understand the CT ecosystem: ct.cloudflare.com The folks at Cloudflare are looking to revamp the dashboard. Please share any feedback you may have!
account_circle
Héctor Fernández 💾💾💾💾 -- @hectorj2f@hachyderm(@hectorj2f) 's Twitter Profile Photo

Tracy Miranda I'm not sure how reliable is this info to be honest. But I'm part of the on-call rotation and I'm a Chainguard employee. I also know another organization which is part of the on call rotation and it isn't mentioned either in that paragraph 🤔.

account_circle
Tracy Miranda(@tracymiranda) 's Twitter Profile Photo

Oh, it really is a shame Chainguard no longer help operate the Sigstore public good instance.

Like open source maintenance, open source SRE is very challenging and the more hands, the better.

Many thanks to all those orgs who are keeping this very important service running!👏

Oh, it really is a shame Chainguard no longer help operate the Sigstore public good instance. Like open source maintenance, open source SRE is very challenging and the more hands, the better. Many thanks to all those orgs who are keeping this very important service running!👏
account_circle
Pete Wagner(@meofthecloud) 's Twitter Profile Photo

Early adopters of github attestions:
github.com/search?q=path%… (shout out stacklok !)

I don't see anyone signing a .deb yet, I was hoping to adapt some `cosign verify-blob` based stuff.

account_circle
Anaïs Urlichs(@urlichsanais) 's Twitter Profile Photo

This is so cool!! Kelly Shortridge

'in-browser security decision tree tool Deciduous can be used to generate these attack trees as code.'

Andrew Martin ⚡☸️ Michael Hausenblas Hacking Kubernetes (p. 31). O'Reilly Media.

kellyshortridge.com/blog/posts/dec…

account_circle