GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Notices by Josh Bressers (joshbressers@infosec.exchange)

  1. Embed this notice
    Josh Bressers (joshbressers@infosec.exchange)'s status on Thursday, 09-Oct-2025 11:21:41 JST Josh Bressers Josh Bressers

    OK open source security nerds, I need your help

    I have a podcast youtube show thing called Open Source Security

    https://opensourcesecurity.io/

    I'm always looking for guests. Back when I changed formats in January I had a pretty large list of people sent to me as suggestions. I've made it through the list (it took me 10 months)

    If you know someone (or are someone) doing open source security work I would love a suggestion. DMs are open and there are other contact things on the website

    I especially like guests who are unsung heroes

    In conversation about 2 months ago from infosec.exchange permalink
  2. Embed this notice
    Josh Bressers (joshbressers@infosec.exchange)'s status on Monday, 15-Sep-2025 03:21:09 JST Josh Bressers Josh Bressers
    in reply to
    • Ryan Castellucci :nonbinary_flag:
    • lemon

    @ryanc @lemonlolita the lower decks tuvix episode is solid gold. You should watch it after this

    In conversation about 3 months ago from infosec.exchange permalink
  3. Embed this notice
    Josh Bressers (joshbressers@infosec.exchange)'s status on Thursday, 28-Aug-2025 14:42:53 JST Josh Bressers Josh Bressers

    The Register wrote a story about a single maintainer open source project, I think it's shameful and upsetting. So I wrote a blog post about it

    An absolutely ridiculous amount of open source is one person projects. I have the data to prove it

    https://opensourcesecurity.io/2025/08-oss-one-person/

    In conversation about 3 months ago from infosec.exchange permalink
  4. Embed this notice
    Josh Bressers (joshbressers@infosec.exchange)'s status on Monday, 21-Jul-2025 23:16:56 JST Josh Bressers Josh Bressers
    in reply to
    • Adam Shostack :donor: :rebelverified:

    @adamshostack This post has been living for free in my head for a few days

    The part I'm most pondering is how not just anyone can build a bridge. We have a very defined field for who is allowed to design and build bridges

    And when it does fail, there are incredibly detailed investigations

    And those investigations end up changing the rules for future bridges (and might even result in existing bridges getting an upgrade)

    While in cybersecurity, I think we are basically at the "random person build bridge out of stuff they found in the woods" stage of bridge building

    It's also worth noting, it took hundred (probably thousands) of years to get to the place we are with bridge building

    In conversation about 5 months ago from infosec.exchange permalink
  5. Embed this notice
    Josh Bressers (joshbressers@infosec.exchange)'s status on Wednesday, 16-Apr-2025 15:56:23 JST Josh Bressers Josh Bressers

    There's a discord server a bunch of vulnerability nerds hang out in I run. We'll be talking about what's happening with #CVE for the foreseeable future (good, bad, and ugly)

    Everyone is welcome to join, feel free to lurk, ask questions, or suggest ideas

    https://discord.gg/gSCrXxMuPx

    In conversation about 8 months ago from infosec.exchange permalink
  6. Embed this notice
    Josh Bressers (joshbressers@infosec.exchange)'s status on Thursday, 03-Apr-2025 04:09:18 JST Josh Bressers Josh Bressers
    in reply to
    • sjvn
    • Greg K-H
    • The New Stack
    • badger

    @gregkh @TheNewStack @badger @sjvn

    Working to fix the CVE problems should be applauded

    But we need to keep in mind there are open source projects that are one person who spends two hours every other Saturday

    Expecting that person to become a CNA is 🍌

    They should be able to control their CVE data also, but today they can't

    In conversation about 8 months ago from infosec.exchange permalink
  7. Embed this notice
    Josh Bressers (joshbressers@infosec.exchange)'s status on Thursday, 03-Apr-2025 04:08:58 JST Josh Bressers Josh Bressers
    in reply to
    • sjvn
    • The New Stack

    @sjvn @TheNewStack

    Ugh, please don't normalize "every open source projects needs to be a CNA"

    Most open source projects don't have the resources to be a CNA and shouldn't need to be a CNA

    Curl and the Kernel became CNAs because the CVE process is broken

    In conversation about 8 months ago from infosec.exchange permalink
  8. Embed this notice
    Josh Bressers (joshbressers@infosec.exchange)'s status on Tuesday, 25-Feb-2025 23:09:00 JST Josh Bressers Josh Bressers

    This episode #OpenSourceSecurity talks to @sheogorath about forking open source projects

    It's a lot more complicated than you think it is, and Sheogorath has some first hand experience from one of the most complicated forks I've ever seen in HedgeDoc

    It's a fun chat filled with lessons

    https://opensourcesecurity.io/2025/2025-02-fork_open_source_sheogorath/

    In conversation about 9 months ago from infosec.exchange permalink
  9. Embed this notice
    Josh Bressers (joshbressers@infosec.exchange)'s status on Tuesday, 21-Jan-2025 00:18:13 JST Josh Bressers Josh Bressers
    • Gary "grim" Kramlich

    I had a chat with @grimmy on #OpenSourceSecurity about maintaining an open source project for more than 20 years (Gary maintains Pidgin)

    It's a fun conversation that brought back many memories as well as some lessons for everyone involved in open source

    https://opensourcesecurity.io/2025/01-open_source_maintenance_with_gary_kramlich/

    In conversation about 11 months ago from infosec.exchange permalink
  10. Embed this notice
    Josh Bressers (joshbressers@infosec.exchange)'s status on Friday, 17-Jan-2025 00:46:35 JST Josh Bressers Josh Bressers

    Being on the "Top 10 CVE assigners of 2025" list probably isn't something fortinet is very excited about :)

    In conversation about 11 months ago from infosec.exchange permalink

    Attachments


    1. https://media.infosec.exchange/infosec.exchange/media_attachments/files/113/838/357/344/242/430/original/0ae3d1fb04d5d6c3.png
  11. Embed this notice
    Josh Bressers (joshbressers@infosec.exchange)'s status on Wednesday, 01-Jan-2025 23:57:53 JST Josh Bressers Josh Bressers

    Now that 2025 is here, it's time to wind down the #osspodcast

    It was a fun run, but it was time to be done.

    I have a new project I'm calling "Open Source Security" (the domain is too good to not do something with it)

    I want to chat with people securing the use and creating of open source. I explain a lot more in the blog post (which also has audio)

    If you're one of these people, let me know! There are a lot of lessons for us all, and the people doing the best work aren't being listened to

    https://opensourcesecurity.io/posts/2025-01-the_future_of_open_source_security/

    In conversation about a year ago from infosec.exchange permalink
  12. Embed this notice
    Josh Bressers (joshbressers@infosec.exchange)'s status on Tuesday, 10-Dec-2024 22:05:05 JST Josh Bressers Josh Bressers
    in reply to
    • Cory Doctorow
    • daniel:// stenberg://

    @bagder @pluralistic the solution is obviously more AI

    It’s the one trick THEY don’t want you to know!!!

    In conversation about a year ago from infosec.exchange permalink
  13. Embed this notice
    Josh Bressers (joshbressers@infosec.exchange)'s status on Tuesday, 10-Dec-2024 12:26:10 JST Josh Bressers Josh Bressers
    in reply to
    • Seth Larson
    • Ecosyste.ms

    @sethmlarson Ooohhh, actually, I wonder if it's the fault of @ecosystems

    They had some data issues around that time I think

    In conversation about a year ago from infosec.exchange permalink
  14. Embed this notice
    Josh Bressers (joshbressers@infosec.exchange)'s status on Tuesday, 10-Dec-2024 10:47:23 JST Josh Bressers Josh Bressers
    • Seth Larson

    @sheogorath @sethmlarson

    Goodness no. This is pretty confusing stuff, the questions help me double check I'm not missing something

    I appreciate the questions

    In conversation about a year ago from infosec.exchange permalink
  15. Embed this notice
    Josh Bressers (joshbressers@infosec.exchange)'s status on Tuesday, 10-Dec-2024 10:42:40 JST Josh Bressers Josh Bressers
    • Seth Larson

    @sheogorath @sethmlarson

    I will accept that as the spike, but there are over 2 years of 1000 (give or take) removals per month, then it drops to 100

    In conversation about a year ago from infosec.exchange permalink
  16. Embed this notice
    Josh Bressers (joshbressers@infosec.exchange)'s status on Tuesday, 10-Dec-2024 10:38:30 JST Josh Bressers Josh Bressers
    • Seth Larson

    Hey @sethmlarson

    I'm doing some investigation on how often the various ecosystems are removing packages. Do you know why PyPI had this decrease in the number of removed packages in the middle of May?

    In conversation about a year ago from infosec.exchange permalink

    Attachments


    1. https://media.infosec.exchange/infosec.exchange/media_attachments/files/113/625/963/913/324/005/original/0d0e97b521d94ab6.png
  17. Embed this notice
    Josh Bressers (joshbressers@infosec.exchange)'s status on Monday, 09-Dec-2024 09:16:18 JST Josh Bressers Josh Bressers
    in reply to
    • 🌱 Ligniform :donor:​

    @ligniform So most of that 80% have dependencies

    One thing I'm very interested in are the lone wolf packages, that depend on nothing and nothing depends on them

    In conversation about a year ago from infosec.exchange permalink
  18. Embed this notice
    Josh Bressers (joshbressers@infosec.exchange)'s status on Monday, 09-Dec-2024 08:53:41 JST Josh Bressers Josh Bressers
    in reply to
    • 🌱 Ligniform :donor:​

    @ligniform That's the ultimate goal

    One of the wild problems is the hilarious number of things that have 0 dependents (it's like 80% of open source packages)

    In conversation about a year ago from infosec.exchange permalink
  19. Embed this notice
    Josh Bressers (joshbressers@infosec.exchange)'s status on Monday, 09-Dec-2024 08:43:21 JST Josh Bressers Josh Bressers

    I'm doing some data analysis on open source dependency relationships this evening (quite the exciting Sunday night!)

    There are more Ruby GEMS with 5 dependents (the number of packages that depend on this one) than there are with 2

    No other open source ecosystem has this pattern

    In conversation about a year ago from infosec.exchange permalink
  20. Embed this notice
    Josh Bressers (joshbressers@infosec.exchange)'s status on Sunday, 08-Dec-2024 11:45:33 JST Josh Bressers Josh Bressers

    Lately reality seems to be some sort of cosmic battle between the onion and black mirror

    In conversation about a year ago from infosec.exchange permalink
  • Before

User actions

    Josh Bressers

    Josh Bressers

    VP of Security at Anchore - Podcaster (http://opensourcesecuritypodcast.com http://hackerhistory.com) - Blogger (http://opensourcesecurity.io) - He/Him

    Tags
    • (None)

    Following 0

      Followers 0

        Groups 0

          Statistics

          User ID
          138318
          Member since
          20 Jun 2023
          Notices
          87
          Daily average
          0

          Feeds

          • Atom
          • Help
          • About
          • FAQ
          • TOS
          • Privacy
          • Source
          • Version
          • Contact

          GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

          Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.