Brian_Fox Profile Banner
Brian Fox @brian_fox@fosstodon.org Profile
Brian Fox @[email protected]

@Brian_Fox

Followers
1K
Following
233
Media
80
Statuses
3K

Co-Founder & CTO, Sonatype. Former Chair, Apache Maven, BSA Scoutmaster, Amateur Radio Operator Creator of Maven-dependency-plugin and Maven-enforcer-plugin

NH, United States
Joined May 2008
Don't wanna be here? Send us removal request.
@Brian_Fox
Brian Fox @[email protected]
2 years
Well, the CRA passed through committee in a way that will avoid further discussion. There's zero chance they knew there were still significant issues and yet here we are. Read more: Current status:
Tweet media one
2
9
20
@Brian_Fox
Brian Fox @[email protected]
4 months
Day 3. No fix.
@Brian_Fox
Brian Fox @[email protected]
4 months
Get at @Hyatt is down now for two days. It’s clearly an ssl certificate that likely expired. Shouldn’t be such a long outage….
1
0
1
@Brian_Fox
Brian Fox @[email protected]
4 months
Get at @Hyatt is down now for two days. It’s clearly an ssl certificate that likely expired. Shouldn’t be such a long outage….
0
0
2
@Brian_Fox
Brian Fox @[email protected]
6 months
RT @ForbesTechCncl: How Attackers Became The Protagonists Of The Software Supply Chain Written by @brian_fox of @S….
0
2
0
@Brian_Fox
Brian Fox @[email protected]
6 months
RT @LonnieDoingCode: After 6 hours with Artifactory: I can't pull the artifacts that I just pushed, and I can't do anything at all except o….
0
1
0
@Brian_Fox
Brian Fox @[email protected]
9 months
It’s a wrap on AllDayDevOps’ 24 hours of live-streamed content hosted by Sonatype! The good news is that all sessions are now available on demand. I had the privilege of joining three fantastic panels of experts to explore the recent "trifecta" of research into open source.
0
1
3
@Brian_Fox
Brian Fox @[email protected]
9 months
RT @gradle: #BuildPropulsionLab at #CommunityOverCode 2024 with Brian Fox @Brian_Fox on the 10th annual State of the Supply Chain Security….
0
2
0
@Brian_Fox
Brian Fox @[email protected]
10 months
Why is X spying on me? Every time I open the page today, my mac tells me my mic is being used. I close the X tab and it goes away. This has happened multiple times today.
1
0
0
@Brian_Fox
Brian Fox @[email protected]
10 months
RT @jasonrohrer: The circle just shrank. The treasure is still there. Now worth over $38,000
Tweet media one
Tweet media two
0
5
0
@Brian_Fox
Brian Fox @[email protected]
1 year
Recent incidents combine to provide a stark discrepancy in share of risk from consumers and vendors. Also, what does shipping and a bridge disaster have to do with a global IT outage grounding airlines?. Read on:.
Tweet media one
0
0
0
@Brian_Fox
Brian Fox @[email protected]
1 year
I’ve spent much time thinking about why organizations struggle to understand the implications of the rise in malicious oss compared to typical vulnerabilities. It ultimately comes down to psychology. In this article, I explore the psychological barriers that prevent effective.
2
4
7
@Brian_Fox
Brian Fox @[email protected]
1 year
I had a great time talking with @SecurityCRob about the world of vulnerabilities on the @openssf podcast "What’s in the SOSS?" My episode is live now — check it out!
0
0
0
@Brian_Fox
Brian Fox @[email protected]
1 year
Sustainability of critical oss infrastructure is a pressing issue we must address. Shockingly, only 1% of Maven Central users consume 83% of the bandwidth, many being large organizations that should have better supply chain practices. Taking steps to curb this abuse is crucial.
1
15
18
@Brian_Fox
Brian Fox @[email protected]
1 year
RT @sonatype: Sonatype’s two decades of experience have shaped our unique perspective on software development. Dive into our latest blog, "….
Tweet card summary image
sonatype.com
Learn about how astronauts and the overview effect relate to Sonatype's ongoing mission to lead and transform software security and compliance
0
2
0
@Brian_Fox
Brian Fox @[email protected]
1 year
#Malware alert! #Sonatype researchers found a new malicious #PyPI crypto-stealer targeting Windows users. We're committed to protecting the software supply chain while empowering developers to build secure software. Read more on our blog. #cybersecurity
Tweet card summary image
share.sonatype.social
Discovery of a malicious PyPI package 'pytoileur' indicates 2023's 'Cool package' crypto-stealing campaign has been revived....
0
2
0
@Brian_Fox
Brian Fox @[email protected]
1 year
Join us on June 12th at 10 AM for an exclusive webinar on adopting AI/ML/LLM into a firm’s software development strategy. Jaime Whitehouse, Product Manager at Sonatype, leads the session, supported by FINOS. Save your spot now!
Tweet card summary image
share.sonatype.social
Financial Services Open Source Optimization Webinar Series...
0
0
0
@Brian_Fox
Brian Fox @[email protected]
1 year
Sonatype is thrilled to be recognized as Top Rated by TrustRadius in SIX categories:.🌟 SCA.🌟 Application Security.🌟 DevSecOps.🌟 Container Security.🌟 Software Repositories.🌟 Static Code Analysis . See for yourself why our customers are choosing Sonatype.
0
1
1
@Brian_Fox
Brian Fox @[email protected]
1 year
RT @sonatype: 📢 Today marks a new era! Introducing SBOM Manager - the industry's first integrated system of record for managing SBOMs! A po….
0
4
0
@Brian_Fox
Brian Fox @[email protected]
1 year
Dive into the latest #DevSecOps trends and discover best practices for SBOM compliance at our upcoming Lunch & Learn! Hear from experts at @Sonatype, @northropgrumman, and ARKA Group. Space is limited, so register now:
Tweet card summary image
share.sonatype.social
Lunch And Learn With Carahsoft...
0
0
0