Skip to main content
Eclipse Foundation
    • Log in
    • Manage Cookies
  • Download
  • Join us
    • Membership
      • Become a member
      • Review membership fees
      • Access member portal
    • Sponsorship
      • Support us as a sponsor
    • Contribute
      • How to contribute
      • Committer training
    • Collaborate with us
      • Join an existing industry collaboration
      • Start a new collaboration
  • What we do
    • Projects
      • Explore projects
      • View specifications
    • Industry collaborations
      • Explore collaborations
      • Join a working group
      • Join an interest group
      • Read success stories
    • Core services
      • Explore core services
      • Ensure project security
    • Key initiatives
      • Embedded & IoT
      • Enterprise Java
      • Data sovereignty
      • Security & privacy
      • Developer tools & IDEs
      • AI & emerging technologies
      • Automotive & mobility
      • Policy & compliance
    • Strategic services
      • Transform research into open source
      • Engage professional services
      • Build your OSPO
  • Resources
    • What's happening
      • Read our blog
      • Join mailing lists
      • Get news updates
      • Subscribe to newsletter
    • Events
      • Explore events
      • Join a community meetup
      • Attend a webinar
      • Join OCX
    • Developer resources
      • Explore projects hub
      • Attend office hours
      • Report a vulnerability
      • View known vulnerabilities
      • Use the security handbook
    • Industry insights
      • View case studies
      • View whitepapers
      • View surveys & reports
    • Marketplaces
      • Adoptium
      • Eclipse IDE
      • Open VSX
  • About us
    • The Foundation
      • About
      • Meet the team
      • Board & governance
    • Our members
      • Become a member
      • View member directory
      • Access member portal
    • Sponsorship
      • Become a sponsor
      • Sponsor directory
    • More
      • Join our team
      • Explore our brand
      • Contact us

Membership

  • Become a member
  • Review membership fees
  • Access member portal

Sponsorship

  • Support us as a sponsor

Contribute

  • How to contribute
  • Committer training

Collaborate with us

  • Join an existing industry collaboration
  • Start a new collaboration

Projects

  • Explore projects
  • View specifications

Industry collaborations

  • Explore collaborations
  • Join a working group
  • Join an interest group
  • Read success stories

Core services

  • Explore core services
  • Ensure project security

Key initiatives

  • Embedded & IoT
  • Enterprise Java
  • Data sovereignty
  • Security & privacy
  • Developer tools & IDEs
  • AI & emerging technologies
  • Automotive & mobility
  • Policy & compliance

Strategic services

  • Transform research into open source
  • Engage professional services
  • Build your OSPO

What's happening

  • Read our blog
  • Join mailing lists
  • Get news updates
  • Subscribe to newsletter

Events

  • Explore events
  • Join a community meetup
  • Attend a webinar
  • Join OCX

Developer resources

  • Explore projects hub
  • Attend office hours
  • Report a vulnerability
  • View known vulnerabilities
  • Use the security handbook

Industry insights

  • View case studies
  • View whitepapers
  • View surveys & reports

Marketplaces

  • Adoptium
  • Eclipse IDE
  • Open VSX

The Foundation

  • About
  • Meet the team
  • Board & governance

Our members

  • Become a member
  • View member directory
  • Access member portal

Sponsorship

  • Become a sponsor
  • Sponsor directory

More

  • Join our team
  • Explore our brand
  • Contact us
Picture of Mikaël Barbero

Mikaël Barbero

Head of Security at Eclipse Foundation

Mikaël currently serves as Head of Security at the Eclipse Foundation. He leads the security team at the EU’s largest open source software foundation, developing best practices and programs to protect its members and the open-source projects governed by the Foundation. He is a seasoned technologist passionate about open source, software engineering, and creating user-centered software and solutions. His diverse experience spans everything from software architecture to team management, and of course, cybersecurity. Find me on other websites: https://linktr.ee/mbarbero

  1. Home
  2. Blogs
  3. Blog Posts

    Stop trusting mutable references: how Eclipse Foundation projects should harden GitHub Actions after the Trivy compromise

    Mikaël Barbero

    On March 19, 2026, an attacker used compromised credentials to publish a malicious Trivy v0.69.4 release, force-push 76 of 77...

    Open VSX security update, October 2025

    Mikaël Barbero

    Over the past few weeks, the Open VSX team and the Eclipse Foundation have been responding to reports of leaked...

    Eclipse Open VSX Registry Security Advisory

    Mikaël Barbero

    This security advisory provides additional technical details following our initial statement and the corresponding CVE record. TL;DR A vulnerability in...

    Vulnerability in Eclipse Open VSX Registry extension publication process

    Mikaël Barbero

    On May 4th, the Eclipse Foundation (EF) Security Team received a notification from researchers at Koi Security regarding a potential...

    Strengthening Open Source Security: Eclipse Foundation Selected by the Sovereign Tech Agency for a New Service Agreement

    Mikaël Barbero

    We are pleased to announce that the Eclipse Foundation has been selected by the Sovereign Tech Agency for a new...

    Eclipse Foundation Security Statement: JARsigner Abuse by Malicious Actors

    Mikaël Barbero

    Recent reports indicate that cybercriminals are exploiting the Windows DLL side-loading technique using the legitimate jarsigner.exe executable to propagate malware...

    Introducing the Updated Eclipse Foundation Security Policy

    Mikaël Barbero

    On November 20, 2024, the Board of Director of the Eclipse Foundation approved version 1.2 of its Security Policy. This...

    Exploring the Future of Open Source Security at OCX 2024

    Mikaël Barbero

    In the fast-paced world of software development, open source has emerged as a catalyst for innovation. But with this rapid...

    Securing the Future: 2FA Now Mandatory for Eclipse Foundation Committers

    Mikaël Barbero

    The Eclipse Foundation is pleased to announce the successful implementation of two-factor authentication (2FA) for all committers on both gitlab.eclipse.org...

    Understanding Software Provenance Attestation: The Roles of SLSA and in-toto

    Mikaël Barbero

    A software provenance attestation is a signed document that associates metadata with an artifact, encompassing details like the artifact’s origin...

    Understanding Software Provenance

    Mikaël Barbero

    In the ever-evolving landscape of open-source software development, the creation and distribution of artifacts—such as compiled binaries, libraries, and documentation—represent...

    Eclipse Foundation Embraces Sigstore

    Mikaël Barbero

    As part of our ongoing commitment to fortifying the security of our software development processes, we’re excited to announce a...

    Pagination

    • Current page 1
    • Page 2
    • Page 3
    • Next page ›
    • Last page »

    Back to the top

    • Eclipse Foundation
      • About
      • Projects
      • Collaborations
      • Membership
      • Sponsor
    • Legal
      • Privacy Policy
      • Terms of Use
      • Compliance
      • Code of Conduct
      • Legal Resources
    • More
      • Report a Vulnerability
      • Service Status
      • Contact Us
      • Support

    See what we're up to

    Stay up to date

    Subscribe to our newsletter

    Eclipse Foundation

    Copyright © Eclipse Foundation AISBL. All rights reserved.

    • Privacy policy
    • Terms of use
    • Compliance
    • Legal