Here comes the recording of my talk about @pypi and the security aspects of publishing and maintaining open-source packages. Wanna learn what you can do to protect yourselves? Then you are welcome to my talk:
Check out my new research about the state of starjacking! Spoiler: It’s still present in some package repositories. A huge shoutout to @pypi for a tremendous investment in the verification of package metadata. Wanna know more? Here is the blog: checkmarx.com/blog/falling-s…
The Checkmarx Security Research Team recently investigated the open source CDP #Apache#Unomi, discovering two critical RCE vulnerabilities. Read up: chkmrx.co/3kIPvhL#OpenSource#OSS