Always telling that discussions of “securing OSS” never seems to involve funding and resourcing the maintainers.
Fucking vampires.
Security Architect | Power Platform and Dynamics
I do some things slightly better than poorly, but where I truly excel is at failing tasks successfully.
Always telling that discussions of “securing OSS” never seems to involve funding and resourcing the maintainers.
Fucking vampires.
If this was a person, they would face civil or criminal liability. If your tools harm people, you are harming people
An important skill for a senior level engineer in a very large organization is to know who are the broad architectural authorities. These authorities typically out last reorgs, layoffs, and loss of interest in foundational work.
The reason why this "rolodex" is an important skill is cuz the senior will toil on a hard project only to have that work defunded resulting in toil with no impact. The architectural authority can be a bridge to organization leaders who may not understand the full impact of a reprioritization. The bridge to the architect enables the senior to stay focused on their work and deliver results without getting mired in political debates that occur above their pay grade.
Visual Studio Code Extensions lack a means of enforcing a minimum age to protect against updates that spread worms. There is a feature request to compel Microsoft to add this festure functionality, it only has 212 likes today.
Please help give it a BIG signal boost!

In the last years, supply chain attacks have increased dramatically. A few examples in the VS Code extension ecosystem: AI-Slop ransomware test sneaks on to VS Code marketplace - BleepingComputer M...
We regret to inform you that yet another GitHub attack is underway—this time compromising GitHub Actions with infostealer scripts.
https://discourse.ifin.network/t/5600-github-accounts-compromised-in-megalodon-attack/490