Optional Identity Verification for Eclipse Foundation Committers Launches June 2 Mikaël Barbero 27 May 2026 Trust is a core part of open source collaboration. At the Eclipse Foundation, we have always required committers to provide...
Frontier AI and the next phase of software vulnerability defence Mike Milinkovich 18 May 2026 As advanced AI lowers the cost of discovering and exploiting software vulnerabilities, Europe must treat open source security and rapid...
Don't become the next Trivy: how to make your releases, tags, and automation resistant to compromise Mikaël Barbero 26 March 2026 This is Part 2 of our response to the Trivy supply-chain compromise. Part 1 covered how to consume GitHub Actions...
Stop trusting mutable references: how Eclipse Foundation projects should harden GitHub Actions after the Trivy compromise Mikaël Barbero 24 March 2026 On March 19, 2026, an attacker used compromised credentials to publish a malicious Trivy v0.69.4 release, force-push 76 of 77...
Security Training on Vulnerability Management and SBOMs from November 2025 - Videos are Online! Marta Rybczynska 26 November 2025 In early November 2025, the Eclipse Foundation Security Team delivered the second part of our security training for developers for...
Understanding Open Source Stewards and the Cyber Resilience Act Marta Rybczynska 18 November 2025 The “Open Source Stewards and the Cyber Resilience Act” white paper explores a new role introduced by the EU Cyber...
Open VSX security update, October 2025 Mikaël Barbero 27 October 2025 Over the past few weeks, the Open VSX team and the Eclipse Foundation have been responding to reports of leaked...
The Eclipse Foundation announces a new edition of its security training Marta Rybczynska 14 October 2025 Do you want to know more about vulnerability management? As a developer, you might receive reports, or need to create...
Eclipse Open VSX Registry Security Advisory Mikaël Barbero 2 July 2025 This security advisory provides additional technical details following our initial statement and the corresponding CVE record. TL;DR A vulnerability in...
Security Training on Vulnerability Management and SBOMs - Videos are Online! Marta Rybczynska 1 July 2025 In early June 2025, the Eclipse Foundation Security Team delivered the second part of our security training for developers. The...