Hardware scarcity is our new reality — and spells growing difficulty for mid-sized businesses, managed hosting providers, and many open source communities.
Big Cloud is poised to corner the market for enterprise hardware
Mikael Barbero
@mikael.barbero.tech
Head of Security @ Eclipse Foundation We build our computers (systems) the way we build our cities: over time, without a plan, on top of ruins — Ellen Ullman
Hardware scarcity is our new reality — and spells growing difficulty for mid-sized businesses, managed hosting providers, and many open source communities.
Big Cloud is poised to corner the market for enterprise hardware
I'm joining Jenn Gile and Paul McCarty on The @opensourcemalware.bsky.social Show to talk about securing Open VSX and the Eclipse Foundation! 🗓️ Thu, July 9, 2:35pm PST LinkedIn event: www.linkedin.com/events/74785... YouTube livestream: youtube.com/live/l3YE9Yi...
The OpenSourceMalware Show - #12
YouTube video by OpenSourceMalware
youtube.com
Go learn, for free, what the CRA entails with this great resource. It should be your top learning priority for the summer!
The EU Cyber Resilience Act (CRA) is changing software development and distribution. 📅 Mandatory reporting starts 11 September 2026, now is the time to prepare. Get up to speed with free, practical training from the new ORC Learning Hub: orcwg.org/training/ #CyberResilienceAct #OpenSource
Who am I, if not a wetware agent running legacy autonomy software?
AI-assisted vulnerability reports should not just include polished findings. They should include the prompt, model details, context, tools, repo state, and validation method. For maintainers, provenance is the new reproduction step. Start with the prompt! mikael.barbero.tech/blog/post/20...
The Vulnerability Report Is Dead. Long Live the Prompt!
For years, maintainers have asked security reporters for a fairly reasonable thing: reproduction steps. Not a vibe. Not a screenshot from a scanner. Not a majestic wall of speculative prose explaining...
mikael.barbero.tech
On June 2, the Eclipse Foundation will make optional identity verification generally available for Eclipse Foundation committers. Read more in this blog by Mikaël Barbero 👉 blogs.eclipse.org/post/mika%C3... #opensource #security #committers
We've been part of the Glasswing Project since its inception. To our knowledge, we're the only EU-domiciled organisation participating in the initiative, giving us a unique vantage point on how frontier AI capabilities are reshaping software security. Read more 👉 blogs.eclipse.org/post/mike-mi...
Open source maintainers at profitable companies: stop asking permission to fix what your employer already depends on. No paperwork. No programme. No manager’s blessing. Just maintain it on the clock.
Open Source Resistance
A direct-action manifesto for maintainers keeping open source alive on company time.
ossresistance.com
“I will NOT sacrifice the Oxford comma. We've made too many compromises already; too many retreats. They assimilate the em dash and we fall back. They capture ‘not just X but y’ and we fall back. Not again. The line must be drawn here! This far, no further!”
I just published part 2! Don't become the next Trivy: how to make your releases, tags, and automation resistant to compromise mikael.barbero.tech/blog/post/20... #security #supplychain
Don't become the next Trivy: how to make your releases, tags, and automation resistant to compromise
This is Part 2 of our response to the Trivy supply-chain compromise. Part 1 covered how to consume GitHub Actions safely. This post covers the other side: how to publish safely, so your project doesn’...
mikael.barbero.tech
I published a blog post that lists recommendations and outlines concrete steps that open source projects can (should?) take to reduce the risk of supply chain breaches similar to the recent Trivy incident: mikael.barbero.tech/blog/post/20...
I published a blog post that lists recommendations and outlines concrete steps that open source projects can (should?) take to reduce the risk of supply chain breaches similar to the recent Trivy incident: mikael.barbero.tech/blog/post/20...
Stop trusting mutable references: how Eclipse Foundation projects should harden GitHub Actions after the Trivy compromise
On March 19, 2026, an attacker used compromised credentials to publish a malicious Trivy v0.69.4 release, force-push 76 of 77 version tags in aquasecurity/trivy-action, and replace all 7 tags in aquas...
mikael.barbero.tech
R.I.P. Tony Hoare (11 January 1934 - 5 March 2026). It's a good day to read (or re-read) his wonderful 1980 Turing Award lecture. It's every bit as relevant today as it was in 1980. dl.acm.org/doi/10.1145/...
The emperor's old clothes | Communications of the ACM
dl.acm.org
I've been working on a unified cli that works for github, gitlab, gitea/forgejo and bitbucket. So you (or a coding agent) doesn't need to learn 4 different sets of commands for what are basically all doing the same things: github.com/git-pkgs/forge
GitHub - git-pkgs/forge: Go library and CLI for working with git forges. Supports GitHub, GitLab, Gitea/Forgejo, and Bitbucket Cloud through a single interface.
Go library and CLI for working with git forges. Supports GitHub, GitLab, Gitea/Forgejo, and Bitbucket Cloud through a single interface. - git-pkgs/forge
github.com
today’s one-sentence horror: sudo has been largely maintained by a single person for ~30+ years
+10000 the safety rules to manage this new ecosystem isn’t here yet and is critical. We’ll need safe ways to share these new artifacts (skills, plugins, MCP …)
From curl | bash off the internet… …to docker run some random image… …to /plugin install in coding agents. Same vibes, bigger blast radius. Supply chain management for plugins, anyone? :)
From curl | bash off the internet… …to docker run some random image… …to /plugin install in coding agents. Same vibes, bigger blast radius. Supply chain management for plugins, anyone? :)
This is an insightful but deeply upsetting article about why everyone in the US feels poor, and why the current political situation emerges as a direct result. www.yesigiveafig.com/p/part-1-my-...
Part 1: My Life Is a Lie
How a Broken Benchmark Quietly Broke America
yesigiveafig.com
So I wrote a thing redmonk.com/jgovernor/on...
On Cursor, Erich Gamma, VS Code forks and the surprising role of the Eclipse Foundation
I was writing this post today when the news dropped that Cursor has just raised a new round. > We’re pleased to announce a new round of financing: our Series D of $2.3B at a $29.3B post-money valuat...
redmonk.com
The recording is available and, as expected, it is exceptionally good! It will genuinely ignite (or re-ignite) your enthusiasm for being an engineer! Thank you, @bcantrill.bsky.social www.youtube.com/watch?v=Cum5...
The Complexity of Simplicity
YouTube video by Oxide Computer Company
youtube.com
I can’t wait for the video of this one, the deck is already so bonkers! Love it! Also, no mention of LLM ;)
Single most desirable feature from Supply Chain Security PoV
Immutable releases announced at GitHub Universe! Once tagged, releases can’t be changed. No more worrying about malicious actors swapping out assets or moving tags. Single-use version tags with signed attestations. This is the supply chain protection open source really needs 🔒 #GitHubUniverse
I had a great time chatting with @josh.bressers.name! Go check out what’s happening on the security front at the Eclipse Foundation (@eclipse.org)
I chat with @mikael.barbero.tech about security happenings at the Eclipse Foundation My favorite project they have is helping projects generate #SBOMs, but there's a lot happening. If you want to see some public examples of how to do security right, give it a listen!
And it gets even worse when the metrics are averages rather than percentiles!
You’re (probably) measuring application performance wrong. Humans have a strong bias for throughput. "I can handle X requests per second." Real capacity engineers use response-time curves.
I can’t wait for the video of this one, the deck is already so bonkers! Love it! Also, no mention of LLM ;)
Slides for my #taloscon2025 keynote, "The Complexity of Simplicity" (video to come): speakerdeck.com/bcantrill/th...
🎙 Just wrapped a fantastic conversation with @josh.bressers.name. We dive deep into enhancing open source security and how we do it at the @eclipse.org Can't wait for you to hear the full episode, coming soon!
To implement robust mitigations across Geomys, I did a survey of open source project compromises in 2024/2025. Three root causes dominate: phishing, control handoff, and unsafe GitHub Actions triggers. All three can be systematically avoided. words.filippo.io/compromise-s...
A Retrospective Survey of 2024/2025 Open Source Supply Chain Compromises
Project compromises have common root causes we can mitigate: phishing, control handoff, and unsafe GitHub Actions triggers.
words.filippo.io
🏷️ Reason #3.7.2 why it's critical to clearly and publicly define your #OpenSource project #Governance, for code, distributions, trademarks, and domain names. And, of course, not breaking norms and cosplaying a public charity while bowing to a sole sponsor over the community. 😢
After listening to about a dozen first-hand accounts, I’ve published what I know about the RubyGems takeover.
The future of digital innovation depends on sustainable #opensource infrastructure. Learn how businesses can help ensure long-term sustainability in #EclipseFdn Executive Director Mike Milinkovich’s latest blog: hubs.la/Q03Kz6D50 #PreserveOpenSource #SoftwareSupplyChain #OpenSourceResponsibility
#OCX26 is where the future of open source takes shape. Do you want to be part of it? As an #OCX26 sponsor, you get to align your brand with the communities shaping tomorrow’s tech all in one place. 👉 Get the prospectus or get in touch with our team directly: www.ocxconf.org/event/2026/b...