Billy Lynch
@wflynch
Followers
327
Following
968
Media
14
Statuses
153
Software Engineer @chainguard_dev | gitsign @projectsigstore | @tektoncd | Prev: @Google
New York, NY
Joined September 2012
gittuf, a security layer for Git repositories, has joined the OpenSSF as a sandbox project housed under the Supply Chain Integrity Working Group. 🎉 gittuf stands out by implementing an array of features dedicated to enhancing security. Learn more today:
0
12
35
Hey NYC Friends! We're doing another @chainguard_dev happy hour this Wednesday. Details here: https://t.co/ya2pd1YUtH
chainguard.dev
Chainguard provides trusted open source artifacts for every layer of your modern software stack—containers, language libraries, and VM images.
1
7
17
The future of security looks bright, you don't even need a key 🚫🔑 We partnered with @projectsigstore to help you move away from traditional keys to keyless signing. Learn how to do this by adding just a few lines in a yml file:
about.gitlab.com
Our partnership with Sigstore means that with just a few lines in a yml file, GitLab customers can make their development environment more secure.
2
10
31
Securing your source code just got simpler. Today, @chainguard_dev announced Enforce for @github - a GitHub App for public repositories that lets you define & enforce policy for @projectsigstore -based Git signatures. https://t.co/T40hjjiqMp
chainguard.dev
Read the latest software supply chain & open source security updates, from our opinions on security technologies to research & remedies for the biggest threats.
1
8
28
Dive into the world of code signing and supply chain security with Billy Lynch from @chainguard_dev With years of experience at Google, Billy brings unique insights into securing our digital ecosystems. Don't miss this episode: https://t.co/ceC6todKYX
#SupplyChainSecurity
0
2
7
Do you know about GitSign yet from sigstore and Chainguard??? We sat down with @wflynch for an episode of the Securty Repo podcast to talk about this and some other areas of supply chain security. Check it out https://t.co/QCsTFz72Im or https://t.co/aVDbozfqAL
lnkd.in
This link will take you to a page that’s not on LinkedIn
1
7
10
🆕 Chainguard Academy is live 💜 📗OSS: SLSA, SBOMs, Wolfi, apko, melange, sigstore, etc 📙Edu: glossary, recommendations & more 📘PDocs: Images, Enforce, chainctl 🔗 https://t.co/Swv54UL6BA
1
11
24
🟣Software Self-Attestation With @lorenc_dan: Industry Perspectives Feat. CRob 🟣Learn everything you need to know about SSDF and CISA's Software Self-Attestation Form! Tomorrow 👇 https://t.co/zupF8coBuc
0
7
10
👉🏼 "Sigstore: Secure and Scalable Infrastructure for Signing and Verifying #software" with @wflynch, Staff Software Engineer @chainguard_dev & Zack Newman, Research Scientist @chainguard_dev: https://t.co/2aXjczUjdf
#QConNY #SoftwareConference #SoftwareDevelopment #Software
0
7
14
📝 Billy Lynch from @chainguard_dev challenged us to rethink our trust in signed commits in git. Through his session on Gitsign, he explored why and how we need to ensure the integrity of our code in the face of escalating supply chain security issues. 5/7
1
3
6
0
6
15
📝“Being able to sign artifacts without needing to worry about keys goes a long way to help developers secure their supply chains without needing to worry about the complexities of key management”. @wflynch
https://t.co/l8rSOqhBSD
0
5
8
VANCOUVER🇨🇦 #OSSSummit NA‼️ 🍁5/9 | cdCon+GitOpsCon 12:40pm: Tekton Project Summit @wflynch 4:30pm: Identity-based Source Integrity w/ Gitsign @wflynch 🍁5/10 | OpenSSF Day 12:05pm: What's New w/ SBOMs? @puerco 1:40pm: Ask the Expert: @tracymiranda
https://t.co/cqm6dO4gQL
0
8
16
🎙️ #cdCon + #GitOpsCon Talk 🎙️ Identity-based Source Integrity with Gitsign by @wflynch from @Chainguard_dev Tuesday, May 9 at 4:30pm PDT Add to your schedule here:
0
4
6
Twitter spaces crashed on us so join us here!!
✨What comes to mind when you hear SLSA?✨ Software supply chain security levels, dancing or chips? We’re here to discuss it all. 🫶 https://t.co/3gSYptPc1x
0
3
7
👀 We found a vulnerability in GitHub Actions that bypasses allowed Workflow settings by using commits from forked repositories. Learn more about how this works & what to watch out for 🔍 @wflynch
https://t.co/CIRVzIMKvS
0
5
12
What the fork? Check out this amazing research from @wflynch on bypassing security controls in @github to execute arbitrary code in CI! https://t.co/nKKSj3PLpq
chainguard.dev
Chainguard found a vulnerability in GitHub Actions that bypasses allowed Workflow settings by using commits from forked repositories. Read the report.
0
11
41
By popular demand, we created: ✨S/MEME✨ a substack (commit)ted to security memes…signed, sealed & delivered right to your inbox! ✅ Our 1st issue drops on 2/21 so subscribe + send us your favorite memes below. We'll be sure to feature some. 💜 https://t.co/Zg8yniSKx0
0
7
12