Blog Posts

    New SLSA++ Survey Reveals Real-World Developer Approaches to Software Supply Chain Security

    Wednesday, March 15, 2023 - 08:00 by Mikaël Barbero
    Answering even basic questions about software supply chain security has been surprisingly hard. For instance, how widespread are the different practices associated with software supply chain security? And do software professionals view these practices as useful or not? Easy or hard? To help answer these and related questions, Chainguard, the...

    Hashtag Jakarta EE #167

    Sunday, March 12, 2023 - 06:59 by Ivar Grimstad
    Welcome to issue number one hundred and sixty-seven of Hashtag Jakarta EE! This is the second vacation edition of Hashtag Jakarta EE and the last for this time as I will be back in full force at the end of next week. The monthly Jakarta EE Platform Architecture call was held...

    Hashtag Jakarta EE #166

    Sunday, March 5, 2023 - 05:59 by Ivar Grimstad
    Welcome to issue number one hundred and sixty-six of Hashtag Jakarta EE! After a fairly busy start to 2023 with regard to conferences and travel, I am now taking some take off for vacation. And what better thing to do on your vacation than travel some more? Since I have switched...

    March 2023 Update on Security improvements at the Eclipse Foundation

    Friday, March 3, 2023 - 04:00 by Mikaël Barbero
    Thanks to financial support from the OpenSSF’s Alpha-Omega project, the Eclipse Foundation is glad to have made significant improvements in the last couple of months. Two Factor Authentication Eclipse Tycho, Eclipse m2e, and Eclipse RAP have all enforced 2FA for all their committers on GitHub: https://gitlab.eclipse.org/eclipsefdn/helpdesk/-/issues/2701 https://gitlab.eclipse.org/eclipsefdn/helpdesk/-/issues/2702 https://gitlab.eclipse.org/eclipsefdn/helpdesk/-/issues/2611 Meanwhile, we’ve...

    Shell Hole: How Advanced Prompts are Putting Software Developers at Risk

    Wednesday, March 1, 2023 - 03:00 by Mikaël Barbero
    Advanced shell prompts, such as those provided by theme engines like oh-my-zsh and oh-my-posh, have become increasingly popular among software developers due to their convenience, versatility, and customizability. However, the use of plugins that are executed outside of any sandbox and have full access to the developer shell environment, presents...

    Migrating to Google Analytics 4: Recommendations for Eclipse Project Websites

    Tuesday, February 28, 2023 - 14:20 by Christopher Guindon
    As part of our commitment to providing support to our community, we would like to take a moment to share some recommendations regarding the use of Google Analytics (GA) for Eclipse project websites. As you may be aware, Google Analytics 4 is being rolled out as a replacement for Universal...