Xavier Rene-Corail

@xcorail.bsky.social

Open source security at GitHub. I don’t believe in perfection, but in continuous improvement. Opinions here are mine.

Hey 👋🏾 les amis! Si vous êtes à Paris pour @devoxx.fr, passez me voir sur le stand GitHub!

GitHub Security Lab@securitylab.github.com · 4mo ago

Building with AI? 🤖 Then you won’t want to miss tomorrow’s @devoxx.fr workshop with @xcorail.bsky.social and @jkcso.bsky.social — all about how to build robust AI-powered applications. Shall we play a Game? LLM Security in Practice m.devoxx.com/events/devox... 📍 Paris 142 🗓️ April 22, 10.30am CET

🚀 GitHub is making Actions more secure by default We recently announced upcoming changes to the pull_request_target event and environment protection rules to make GitHub Actions more secure by default. We’ve opened a discussion to gather feedback 👇 🔗 github.com/orgs/communi...

Towards a secure by default GitHub Actions · community · Discussion #179107

Why are you starting this discussion? Product Feedback What GitHub Actions topic or product is this about? Workflow Configuration Discussion Details Today, GitHub announced upcoming changes to the ...

github.com

The internet was on fire. 🔥 One small library affecting billions of systems. Log4Shell was the biggest security vulnerability of all time. Now, Log4J maintainer, Christian Grobmeier tells us what it felt like inside the flames 👉 github.blog/open-source/...

“Ignorance will break all software.” Log4Shell’s one line of code broke the internet, and taught us all a lesson we can’t ignore. As Christian Grobmeier, maintainer of Log4J puts it: "Learning is the only cure for ignorance. So just keep learning."

Recent account takeovers and attacks on package registries are a wake-up call: it's time to raise the bar on authentication and secure publishing practices. Find out what npm is doing—and what steps you can take—to help secure the open source supply chain: github.blog/security/sup...

Our plan for a more secure npm supply chain

GitHub is strengthening npm's security with stricter authentication, granular tokens, and enhanced trusted publishing.

github.blog

If you, a business, are reliant on an open source project to function it is YOUR responsibility to assess and ensure the health of that project by either contributing to it yourself or by using an alternative if project health cannot be guaranteed.

Is your open source project built on a foundation of trust and security? 🛡️ Strengthen its future with essential practices like MFA, code scanning, safe dependency management, and private vulnerability reporting. 🔐 Learn how to implement these to protect your project and users with this guide. ⬇️

Security Best Practices for your Project

Strengthen your project’s future by building trust through essential security practices — from MFA and code scanning to safe dependency management and private vulnerability reporting.

opensource.guide

In this demonstration I show the impact of CVE-2025-25291/CVE-2025-25292, an authentication bypass in ruby-saml used by high profile OSS projects such as GitLab. My team coordinated with both the ruby-saml maintainer and GitLab to get this vulnerability fixed and patches are available at gh.io/glfx

Don’t just say DEI as if it’s a bad word. Spell it out. Say diversity, which is the lifeblood of American society & culture & innovation. Say equity, which a just society should pursue. Say inclusion, because decent people believe in increasing belonging, not isolating people who are different.