Matt "msw" Wilson

@msw.bsky.social

“For a successful technology, reality must take precedence over public relations, for Nature cannot be fooled.”

when it comes to addressing newly discovered flaws in your software dependencies (some of which might be classified as "security vulnerabilities") ... pruning > patching That's it. That's the post.

Personally, I miss the days of Free and Open Source when folks debated if NDAs were compatible (at minimum, in spirit) with the conditions of the GPL. Now, I see the slight possibility of a world where folks rush to share fixes for vulnerabilities in a private club. And if that software is GPL?

Some folks in and around Free and Open Source Software (FOSS) are asking, "does AI change everything?" If you think that FOSS only exists because software is expensive to write, reuse is efficiency, and AI shifts the economics ("we rewrote Next.js in a week with AI!"), you may be worried. I'm not.

Unpopular opinion: a vulnerability that was disclosed privately by researchers and had a coordinated response from vendors and service operators under an (albeit short) embargo is not a “0-day”.

"As adoption has grown, so has our responsibility to ensure the project remains sustainable and continues to thrive. That’s why, with the release of Liquibase 5.0, we are updating the license for Liquibase Community." www.liquibase.com/blog/liquiba...

Strengthening Liquibase Community for the Future

Liquibase Community now uses the Functional Source License (FSL). Learn what this means for developers, contributors, and enterprises, and how it protects sustainability.

liquibase.com

It’s really hard for OSS projects too. Imagine a leaked GH access token from a project maintainer who is not responding, and who is not an employee because OSS isn’t a company. How do you the project get that token revoked? You can’t. You have to de-list the maintainer from your GH org.

From my POV, the most important message for everyone who is doing the hazardous work of developing software in public on platforms like GitHub: you have to pay *close attention* to GitHub token permission scoping. It’s not well known outside of security research circles how often GitHub tokens leak.

Corey Quinn@quinnypig.com · last yr.

It's kinda "good news / bad news." Good news: No one at AWS (human or AI) merged in a dodgy PR, because... Bad news: It was an exciting new exploited vulnerability in CodeBuild.

There's much to agree with in Dan's piece on defending the definition of Open Source. On details, I quibble. "Today, Valkey is maintained by a neutral foundation, ensuring no one company can take it away from open source." Linux Foundation doesn't maintain Valkey. thenewstack.io/open-source-...

Open Source Is Too Important To Dilute

The definition of "open source" is quietly eroding. When these lines blur, trust breaks — and open source doesn’t work without trust.

thenewstack.io

Thrilled for the launch of @kiro.dev today! We started with two main ideas that led to Kiro's spec-driven development features: 1) AI can help us build better products through rapid prototyping 2) Devs can declare their app's requirements to get better results from AI, close to production-grade code

A ghost nightlight with the word Kiro