#OSSF

2025-12-03

Just shipped a new newsletter to my GitHub Sponsors! 🎁

This one includes my latest talk, secure publishing research, #Expressjs updates, #OSSF #Scorecard improvements, and a bunch of ecosystem news.

It will be public soon, but you can read it early and support my OSS work here:
github.com/sponsors/UlisesGasc

Screenshot of a GitHub Sponsors email update titled β€˜Wrapping Up the Year with Talks, Security Work and Big Releases 🎁.’ It shows the beginning of the newsletter: greeting, introduction, and the first section called β€˜What Comes After Chaos?’ with a YouTube embed preview underneath.
2025-10-27

πŸš€ Recent #Lodash updates focus on stronger #CI & #security posture!

βœ… CI support expanded (Node 4 β†’ 25)

🌐 New browser tests via #Playwright

πŸ“ Docs now have dedicated CI

πŸ”’ Added #OpenJS #CNA escalation policy

πŸ“Š Reporting #OSSF #Scorecard

🧯 New Incident Response Plan (#IRP)

🧠 Threat Model inspired by #Express & #Webpack

More details: blog.ulisesgascon.com/the-futu

Stalwart Labsstalwartlabs
2025-08-11

πŸ”’ Stalwart joins GitHub's Open Source Secure Fund! Learn how the program is helping us strengthen our defenses and improve performance at stalw.art/blog/github-ossf

2024-06-10

I am very proud to announce that the #OSSF #Scorecard Monitor tool that I created, it will be part of the @openssf as I donated the project.

I will continue working on it, so be ready for the next release!

More details about the journey: github.com/ossf/scorecard-moni

2024-06-04

Yes! I am very proud to announce that the #OSSF #Scorecard Monitor tool that I created, it will be part of the @openssf as I donated the project.

I will continue working on it, so be ready for the next release!

More info: github.com/marketplace/actions

2024-05-26

A big positive shout out to the #OSSF openssf.org/ for their fantastic guide on compiler security options. If you compile code please read!

best.openssf.org/Compiler-Hard

#clang #c #compiler #programming

Sven Ruppertsvenruppert
2023-02-21

Guide to implementing a coordinated vulnerability disclosure process for open source projects - github.com/ossf/oss-vulnerabil

Client Info

Server: https://mastodon.social
Version: 2025.07
Repository: https://github.com/cyevgeniy/lmst