Mikael Barbero

@mikael.barbero.tech

Head of Security @ Eclipse Foundation We build our computers (systems) the way we build our cities: over time, without a plan, on top of ruins — Ellen Ullman

AI-assisted vulnerability reports should not just include polished findings. They should include the prompt, model details, context, tools, repo state, and validation method. For maintainers, provenance is the new reproduction step. Start with the prompt! mikael.barbero.tech/blog/post/20...

The Vulnerability Report Is Dead. Long Live the Prompt!

For years, maintainers have asked security reporters for a fairly reasonable thing: reproduction steps. Not a vibe. Not a screenshot from a scanner. Not a majestic wall of speculative prose explaining...

mikael.barbero.tech

“I will NOT sacrifice the Oxford comma. We've made too many compromises already; too many retreats. They assimilate the em dash and we fall back. They capture ‘not just X but y’ and we fall back. Not again. The line must be drawn here! This far, no further!”

I know the tweet is Al generated when they use " ," before and.

From curl | bash off the internet… …to docker run some random image… …to /plugin install in coding agents. Same vibes, bigger blast radius. Supply chain management for plugins, anyone? :)

I had a great time chatting with @josh.bressers.name! Go check out what’s happening on the security front at the Eclipse Foundation (@eclipse.org)

Josh Bressers@josh.bressers.name · 10mo ago

I chat with @mikael.barbero.tech about security happenings at the Eclipse Foundation My favorite project they have is helping projects generate #SBOMs, but there's a lot happening. If you want to see some public examples of how to do security right, give it a listen!

To implement robust mitigations across Geomys, I did a survey of open source project compromises in 2024/2025. Three root causes dominate: phishing, control handoff, and unsafe GitHub Actions triggers. All three can be systematically avoided. words.filippo.io/compromise-s...

A Retrospective Survey of 2024/2025 Open Source Supply Chain Compromises

Project compromises have common root causes we can mitigate: phishing, control handoff, and unsafe GitHub Actions triggers.

words.filippo.io

🏷️ Reason #3.7.2 why it's critical to clearly and publicly define your #OpenSource project #Governance, for code, distributions, trademarks, and domain names. And, of course, not breaking norms and cosplaying a public charity while bowing to a sole sponsor over the community. 😢

Joel Drapper 🇬🇧🇺🇦@joel.drapper.me · 11mo ago

After listening to about a dozen first-hand accounts, I’ve published what I know about the RubyGems takeover.

The Register wrote a story about a single maintainer open source project, I think it's shameful and upsetting So I wrote a blog post about it An absolutely ridiculous amount of open source is one person projects. I have the data to prove it opensourcesecurity.io/2025/08-oss-...

Open Source is one person

The Register recently published a story titled Putin on the code: DoD reportedly relies on utility written by Russian dev. They should be ashamed of this story, and the company behind the ambulance ch...

opensourcesecurity.io