Don't become the next Trivy: how to make your releases, tags, and automation resistant to compromise
This is Part 2 of our response to the Trivy supply-chain compromise. Part 1 covered how to consume GitHub Actions...
Head of Security at Eclipse Foundation
Mikaël currently serves as Head of Security at the Eclipse Foundation. He leads the security team at the EU’s largest open source software foundation, developing best practices and programs to protect its members and the open-source projects governed by the Foundation. He is a seasoned technologist passionate about open source, software engineering, and creating user-centered software and solutions. His diverse experience spans everything from software architecture to team management, and of course, cybersecurity. Find me on other websites: https://linktr.ee/mbarbero
This is Part 2 of our response to the Trivy supply-chain compromise. Part 1 covered how to consume GitHub Actions...
On March 19, 2026, an attacker used compromised credentials to publish a malicious Trivy v0.69.4 release, force-push 76 of 77...
Over the past few weeks, the Open VSX team and the Eclipse Foundation have been responding to reports of leaked...
This security advisory provides additional technical details following our initial statement and the corresponding CVE record. TL;DR A vulnerability in...
On May 4th, the Eclipse Foundation (EF) Security Team received a notification from researchers at Koi Security regarding a potential...
We are pleased to announce that the Eclipse Foundation has been selected by the Sovereign Tech Agency for a new...
Recent reports indicate that cybercriminals are exploiting the Windows DLL side-loading technique using the legitimate jarsigner.exe executable to propagate malware...
On November 20, 2024, the Board of Director of the Eclipse Foundation approved version 1.2 of its Security Policy. This...
In the fast-paced world of software development, open source has emerged as a catalyst for innovation. But with this rapid...
The Eclipse Foundation is pleased to announce the successful implementation of two-factor authentication (2FA) for all committers on both gitlab.eclipse.org...
A software provenance attestation is a signed document that associates metadata with an artifact, encompassing details like the artifact’s origin...
In the ever-evolving landscape of open-source software development, the creation and distribution of artifacts—such as compiled binaries, libraries, and documentation—represent...