Fewer keys under the doormat: why trusted publishing matters for Open VSX
Every software registry eventually learns the same lesson: the most valuable thing in a publishing pipeline is not the code...
Head of Security at Eclipse Foundation
Mikaël currently serves as Head of Security at the Eclipse Foundation. He leads the security team at the EU’s largest open source software foundation, developing best practices and programs to protect its members and the open-source projects governed by the Foundation. He is a seasoned technologist passionate about open source, software engineering, and creating user-centered software and solutions. His diverse experience spans everything from software architecture to team management, and of course, cybersecurity. Find me on other websites: https://linktr.ee/mbarbero
Every software registry eventually learns the same lesson: the most valuable thing in a publishing pipeline is not the code...
For the last several years, the Eclipse Foundation Security Team has worked alongside our project communities to keep the software...
Between 12 and 14 September 2026, our GitLab instance was affected by CVE-2026-85706, a critical vulnerability in GitLab that allowed...
For years, maintainers have asked security reporters for a fairly reasonable thing: reproduction steps. Not a vibe. Not a screenshot...
Trust is a core part of open source collaboration. At the Eclipse Foundation, we have always required committers to provide...
This is Part 2 of our response to the Trivy supply-chain compromise. Part 1 covered how to consume GitHub Actions...
On March 19, 2026, an attacker used compromised credentials to publish a malicious Trivy v0.69.4 release, force-push 76 of 77...
Over the past few weeks, the Open VSX team and the Eclipse Foundation have been responding to reports of leaked...
This security advisory provides additional technical details following our initial statement and the corresponding CVE record. TL;DR A vulnerability in...
On May 4th, the Eclipse Foundation (EF) Security Team received a notification from researchers at Koi Security regarding a potential...
We are pleased to announce that the Eclipse Foundation has been selected by the Sovereign Tech Agency for a new...
Recent reports indicate that cybercriminals are exploiting the Windows DLL side-loading technique using the legitimate jarsigner.exe executable to propagate malware...