@becojo

65 Followers
133 Following
71 Posts
@g this landed in my inbox. An "AI native" staffing company mentioned one of your LinkedIn post 💀
catch us tomorrow morning at @NorthSec for an overview on finding vulnerable GitHub Actions workflows in open-source projects at scale, ways of living in a pipeline, and a new SAST tool to analyze CI workflows! #nsec #appsec #supplychain

really cool to see https://jsr.io adopt OIDC and Sigstore. Long-lived API keys are so cringe.

#appsec

JSR: the JavaScript Registry

JSR is the open-source package registry for modern JavaScript. JSR natively supports TypeScript, and works with all JS runtimes and package managers.

JSR