Like

Liked Daniel Appelquist (@torgo@mastodon.social)
Post details
Attached: 1 image On my way home from Open Source Summit EU in Prague. So much global cyber policy! If the attendance at sessions and workshops is any measure, CRA and how it impacts the open source ecosystem has become a very hot topic. Guides available at https://policy.openssf.org and free training available here https://openssf.org/tag/cra-training-course/ by the way.

 Listen

Listened to Open Source Security: Dependency attacks in 2026 with James Matchett
Post details
Josh chats with Jeff Matchett from Cloudsmith about a new report they put out. It has some scary looking statistics in it about how organizations are using dependencies. There are some surprising numbers in there, but the story is really one of defense in depth. There's no single thing we can do here, it's all about knowing what you have every step of the way. It's easy to say, but certainly a challenge to do right. James is a ton of fun to chat with and filled with energy and knowledge. The show notes and blog post for this episode can be found at https://opensourcesecurity.io/2026/2026-10-james-cloudsmith  

 Listen

Listened to Serenity: LIVE! (w/ Nick Kroll) - Earwolf
Post details
HDTGM All-star Nick Kroll (Big Mouth) joins Paul, June, and Jason to discuss the 2019 neo-noir thriller Serenity. Recorded live from Austin City Limits at the Moody Theater, they talk about the big twist that comes way too early, McConaughey being so wet in the movie, the sex scene on the boat, and more. This episode is brought to you by Squarespace (www.squarespace.com/BONKERS), CNN original series: The Movies, Simplisafe (www.simplisafe.com/bonkers), and Allbirds (www.allbirds.com). Subscribe to Unspooled with Paul Scheer and Amy Nicholson here: http://www.earwolf.com/show/unspooled/ Check out our tour dates over at www.hdtgminfo.com! Check out new HDTGM merch over at https://www.teepubli…wdidthisgetmade Where to Find Jason, June & Paul: @PaulScheer on Instagram & Twitter @Junediane on IG and @MsJuneDiane on Twitter

 Like

Liked Kostas Konstantinidis (@codesennin.com)
Post details
Automatic dependency update PR-raising tooling! We actually introduced Renovate recently in our azure devops CICD pipeline setup and it works pretty well. For years we didn’t have a dependabot- like solution and I am glad that we now have Renovate to cover that gap! [contains quote post or other embedded content]