pxp928 Profile Banner
Parth Patel Profile
Parth Patel

@pxp928

Followers
113
Following
319
Media
6
Statuses
149

Kusari - Software Supply Chain Security

Joined November 2021
Don't wanna be here? Send us removal request.
@lumjjb
Brandon Lum
1 year
It's so awesome hearing about the multiple shoutouts to 🥑GUAC during the @KubeCon_ keynotes!!! Really wished I could be there in person! Appreciate the call outs and looking forward to engaging with new community members! See you in slack! https://t.co/R9hg1uF7ff
guac.sh
Welcome to the GUAC community! If you’re looking for an issue to get starting on, check the “good first issue” and “help wanted” tags in GitHub. If you don’t know where to start, introduce yourself...
0
1
3
@mihaimaruseac
Mihai Maruseac
1 year
GUAC, SLSA and Sigstore mentioned several times at first keynote of #sossfusion (and other similar high quality projects)
0
2
8
@TradeTalks
TradeTalks
1 year
.@PRODAFT @WinstonLaw & J2 Ventures join @JillMalandrino on @Nasdaq #TradeTalks to discuss comprehensive solutions for cyber teams to play offense and defensive and how privacy and security regulation is advancing. #CybersecurityAwarenessMonth
1
3
4
@lumjjb
Brandon Lum
1 year
Hi All! I’ll be talking about SBOMs and how Google produces and uses them for EO 14028 and beyond at this webinar tomorrow! Hope to see you there!
@anchore
Anchore
1 year
📝 SBOMs are critical for a handful of reasons: #visibility into dependencies, enhance #security, meet #compliance and streamline development. Learn how Google is using our Syft #SBOM #opensource #SBOM tool in our upcoming webinar. https://t.co/5kvTeyO5hm
1
4
5
@mlieberman85
Michael Lieberman
1 year
I know everyone wants to work on the cool thing or save/make a ton of money by throwing AI at a problem but it's extraordinarily dangerous. How many folks are verifying that the provenance and that the code/training data isn't malicious or vulnerable?
@mihaimaruseac
Mihai Maruseac
1 year
Model storage under attack ( https://t.co/gFgDfQqqkE). Models are uninspectable, so the only solution to prevent tampering is to sign them. OpenSSF has a model signing SIG as part of the AI/ML WG. Both biweekly meetings are in the OpenSSF calendar. Also,
0
2
7
@lumjjb
Brandon Lum
2 years
Mark your calendars! Join us for our first ever GUAC @openssf tech talk on June 6th! https://t.co/uiwOdW3NHz
0
1
2
@lumjjb
Brandon Lum
2 years
Awesome piece on supply chain security! Shout out to sigstore and GUAC!!!
@openssf
OpenSSF
2 years
🔒 The vast majority of the world's software runs on open source code. Read this article by @Gizmodo to discover how OpenSSF's initiatives, such as Sigstore and GUAC, are shaping a more secure open source software ecosystem. https://t.co/L3ipCvE0xn #OSSSecurity
0
1
7
@mihaimaruseac
Mihai Maruseac
2 years
We are happy to publish a whitepaper on how we're thinking on securing the AI supply chain both internally and for OSS. This is a culmination of nearly a year of thinking about this space, from people working on AI or security, across multiple Google PAs. https://t.co/gdoV5HVSrG
Tweet card summary image
research.google
@mihaimaruseac
Mihai Maruseac
2 years
Since all model serialization formats are vulnerable, it is better to sign models on training (or upload) and verify signatures before use. Much better to also record the entire supply chain provenance. Will have more on this, soon
0
4
22
@lumjjb
Brandon Lum
2 years
🎉🥑🍅🧅I'm really excited as GUAC joins the OpenSSF community, allowing the project to continue to grow, and join forces with other partners and members in the OpenSSF in developing an open source knowledge graph! Looking forward to this next step in our journey!
@openssf
OpenSSF
2 years
GUAC has joined the OpenSSF as an Incubating Project 🎉 GUAC is an open source supply chain security project that provides dependency management and actionable insights into the security of software supply chains. Read the announcement: https://t.co/IrJQwyZQpN #OSSSecurity
0
2
10
@openssf
OpenSSF
2 years
GUAC has joined the OpenSSF as an Incubating Project 🎉 GUAC is an open source supply chain security project that provides dependency management and actionable insights into the security of software supply chains. Read the announcement: https://t.co/IrJQwyZQpN #OSSSecurity
0
14
31
@ManningBooks
Manning Publications
2 years
📣Deal of the Day📣 Feb 8 SAVE 45% on Securing the Software Supply Chain & selected titles: https://t.co/DcpsoLASzY @mlieberman85 @lumjjb #SupplyChainSecurity Secure your entire #softwaresupplychain, including the code you write, libraries you use & the platforms you run on.
0
2
4
@weiliendang
Wei Lien Dang
2 years
Congratulations to @timsaprogrammer, @mlieberman85, @pxp928 & the @Kusari team on your seed round! It's been a privilege to work with you since the earliest days of your journey to tackle one of the biggest challenges in security today. https://t.co/N9vo1JkhIG
1
4
10
@software_daily
Software Engineering Daily
2 years
Software Supply Chain Security with Michael Lieberman Michael Lieberman is the Co-Founder and CTO of Kusari and has an extensive background in software security. Michael joins the show today to talk about challenges and strategies in software supply chain security.
0
3
10
@mlieberman85
Michael Lieberman
2 years
I’m out in Tokyo for talks at @openssf day and @linuxfoundation open source summit Japan. For folks who want to chat cybersecurity and GUAC hit me up.
0
2
10
@ManningBooks
Manning Publications
2 years
📣Deal of the Day📣 Nov 18 Securing the Software Supply Chain & selected titles are 45% OFF: https://t.co/DcpsoLASzY @mlieberman85 @lumjjb Secure your entire #softwaresupplychain, including the code you write, the libraries you use, and the platforms you run on. #SBOM #AppSec
0
4
15
@infernosec
Abhishek Arya
2 years
Excited to see GUAC landing as an @openssf incubating project, with the set of initial contributors - @Citi @kusaridev @torresariass(Purdue) @Google and quotes from some early adopters - @RedHat @Yahoo ClearAlpha @Guidewire_PandC
0
5
16
@lumjjb
Brandon Lum
2 years
Increase your mental health on CVE drop days (I.e. recent curl vuln) by being prepared! Go in knowing your blast radius and prepared to patch and mitigate! In this blogpost @pxp928 , @mihaimaruseac and I use GUAC to do this for last week’s CURL CVE. https://t.co/iDc6AGqv7O
Tweet card summary image
kusari.dev
Learn how to use GUAC for mitigating high-severity CVEs like the recent cURL vulnerability. Discover Kusari's proactive approach to software supply chain security.
0
3
5
@lumjjb
Brandon Lum
2 years
For those that didn't catch the LLM's response to "where's the vulns?", catch the recording up now!
@lumjjb
Brandon Lum
2 years
🥑+🤖🧠=🔐 We got a super exciting GUAC community meeting coming up this week... which may or may not feature some LLMs!! Come join us and see some cool demos from @ridhoq @sozercan and more! Meeting invite details at
1
3
9
@lumjjb
Brandon Lum
2 years
🥑+🤖🧠=🔐 We got a super exciting GUAC community meeting coming up this week... which may or may not feature some LLMs!! Come join us and see some cool demos from @ridhoq @sozercan and more! Meeting invite details at
guac.sh
Welcome to the GUAC community! If you’re looking for an issue to get starting on, check the “good first issue” and “help wanted” tags in GitHub. If you don’t know where to start, introduce yourself...
0
9
12
@mlieberman85
Michael Lieberman
2 years
Deal of the Day September 12: New MEAP! Save 45% on my book Securing the Software Supply Chain and other selected titles @ManningBooks #SupplyChainSecurity #SBOM #AppSec:
0
3
11