TestifySec @testifysec
Joined July 2021-
Tweets73
-
Followers139
-
Following39
-
Likes81
As a seasoned Go developer our CTO, Mikhail Swift, recently explored the transformative impact of the much-awaited generics feature in Go 1.18 through a compelling use case within our Witness project. See what he learned in the full blog post: buff.ly/3S5BvmM
Make sure to head over and star it today to ensure you stay updated with project updates and information. We have room for more "relationships". 😉 Join the #witness community - buff.ly/3JFu7tG #supplychain #cybersecurity #repo #github
At TestifySec, we're passionate about #softwaresecurity and #supplychainsecurity. But we're also passionate about our families. As the holiday season approaches, remember to prioritize the people who matter most. #familytime
Great blog post by @colek42c published on @testifysec website about comparing #intoto and @projectsigstore; you will find very niche details about them; don't forget to read it 👇 testifysec.com/blog/sigstore-…
Introducing Archivista, a server-side app that helps businesses securely manage their software supply chain data. Protect your supply chain and make confident, informed decisions. Visit our website or contact us to schedule a demo. testifysec.com/blog/secure-su…
In the land of TestifySec, Our products do protect, Witness and Archivista, Together a perfect pair, To help secure your software, From source to production fair, And Judge to enforce the rules, With policies that we can share, So come and try our tools, And join us in our quest
At @TestifySec we know that getting compromised can seriously affect organizations. That's why we're dedicated to securing the software supply chain and ensuring the integrity of the software being developed. Don't let your software become a vulnerability - trust TestifySec.
There needs to be more clarity in the Software Supply Chain Security space In our latest blog article, We talk about the differences between in-toto and @projectsigstore, and when it is appropriate to use each. testifysec.com/blog/sigstore-…
In-toto vs. sigstore: what are they and how do they differ? 🧵 👇 @projectsigstore @torresariass #intoto
You can now generate in-toto metadata via a GitHub action, thanks to @colek42c's work at @KubeCon_'s in-toto + TUF + @projectsigstore ContribFest! github.com/marketplace/ac…
Petition to start calling these GUESSBOMs! 💣💣💣
One under-appreciated problem with software bill-of-materials (SBOM) is that SBOMs that are recreated after build time - e.g. by software composition analysis [SCA] tools - are typically incomplete and have to make a best guess of the 'ingredients' of the software artifacts.
We just landed initial @witness_dev support for @github. This uses a preview build of Witness with #Archivist support. A GitHub attestor, and Keyless signing should drop before Kubecon. Let me know if you give it a whirl. github.com/testifysec/wit…
Have you ever wondered how to inventory all the dependencies in a software build? In this talk, I will showcase how end users can create and use #BPF traces to minimize #CVE false positives and negatives with @witness_dev and @ciliumproject #tetragon sched.co/1AOie
We are working on making supply chain security and compliance easy. Learn more at witness.dev @witness_dev
preview of our backend for @witness_dev. Amazing work by @mikhailswift/@ffkiv
We had a user post an issue that hit an edge case we didn't test for. Our team fixed the issue the next business day, along with unit and integration tests. I couldn't be more proud of our engineering team led by @mikhailswift
I started adding support for the SPIRE delegated identity API to @witness_dev today. This lets us sign attestations based on the shasum of the CI command being run. Great work on this powerful API @SPIFFEio team!
We use @SPIFFEio as a way to distribute trust, using remote attestation in our Judge platform. However, we don't expect our users to understand Spire, and spire registrations. We are making great progress on federating SPIRE and making registration easy. asciinema.org/a/ieVRO9nQ3AZx…
Tracebit @tracebit_com
364 Followers 5K Following The Assume Breach platform that detects intrusions in seconds. Also on https://t.co/T4VNPGjS2O
Jonathan Plott @JHPlott_
253 Followers 1K Following
aditya @akasaudhan02
115 Followers 564 Following founding engineer ● gsoc’26 mentor, gsoc’25 contibutor @zulip ● prev: @trybrowzer, @firstworkhr (yc s’24), clickpe (yc w’23), @smallcaseHQ
rahulxf @rahulxf_
1K Followers 3K Following oss | gsoc'24 @submitty | lfx @ cncf | oss @ https://t.co/cfeTPYIPnC
Luke O'Libre @Luke_OLibre
2K Followers 1K Following Rights are shaped by law. Law is shaped by expectations. Culture and technology change expectations. Let's build our escape 🟣 GME, defi, law, esports, MMAkumareshsomi @kumareshsomi
208 Followers 735 Following Dev | Engineering | Security | Netherlands | India. RT ≠ Endorsement.
Vuyo Soci @vuyo_soci
96 Followers 1K Following 4IR 🤗 ✌V.S Code. #systems #development #technology #ai #science #mathematics #innovation #process #data_science #programming #design #workflows
Bearsoft Inc. @BearsoftInc
26 Followers 364 Following With more than 30+ years of experience in recruitment and staff augmentation, Bearsoft offers a new approach to recruitment.
Paul Arah 🐝🐝 @ArahPaul
944 Followers 1K Following Security-focused Community Builder 🐝 l Cloud Native Networking, Observability, & Security with Tech Consultant • Cyclist🚴♂️
Michael Winser @michaelwinser
199 Followers 135 Following Wing foiling - Security - Strategy - Ambassador Working with @AlphaOmegaOSS, @EclipseFdn, @OpenSSF
Chris Clarkson @ClarksonCJ
697 Followers 4K Following Passionate about Hacking, AppSec and CloudSec. #AppSec #CloudSec #Hacker #Hardware #InfoSec Views are my own. Mastodon: @[email protected]
Luke Hinds @decodebytes
3K Followers 753 Following CEO of @nolabshq - Creator of https://t.co/T8htHI6XS3 , now building https://t.co/OBABqFv9Ou - the agent security platform.
Andrew Drake @spamfordrake
0 Followers 16 Following
OpenSSF @openssf
6K Followers 29 Following Open Source Security Foundation (OpenSSF) Together, we're securing the #opensource ecosystem #OSSSecurity https://t.co/uUpbn44G4Q https://t.co/adjLU8dbk0
@[email protected] @fridex
212 Followers 674 Following Life is about priorities. @[email protected] 🐘
VULK COOP 🐺 @vulkcoop
568 Followers 3K Following Digital Product Design, Development & DevOps #Kubernetes #CloudNative consulting. We are a wolfpack, stronger as a team 📧[email protected] ▶https://t.co/pMPgLo3atN
Cloud Native Telecom ... @lfncnti
1K Followers 3K Following 📞📱☎️📡🌐LF Networking's Cloud Native Telecom Initiative (CNTi) - see more at https://t.co/er51c5WqCm
Platform Security Sum... @platformsec
985 Followers 4K Following Conference on composable software supply chain integrity and hardware-assisted platform security, with OpenEmbedded, OpenXT and other ecosystems
Peter Eltgroth @peltgroth
237 Followers 996 Following Software Engineer, Leader, Mentor, Father, Husband, Musician Opinions are my own.
Mostafa Hussein @duk3fl33d
185 Followers 3K Following A superhero with supervillain tendencies. Automation junkie and Open Source Enthusiast. I convert muggles into Containers. 🐳 🧙🏼
Moosa Zafar Khan @MoosaZk
77 Followers 357 Following 🧑💻 Full-Stack Dev | React & Next.js lover | Building clean UIs & smart apps | Cloud (AWS) & DevOps curious | Startup energy ⚡ | Learning, shipping, evolving
Beltran Rueda @beltranrubo
745 Followers 926 Following Father of two and Sr Engineering Manager at Broadcom (previously Bitnami). Opinions are on my own.
Radoslav Dimitrov @radoslav_dimitr
113 Followers 403 Following #opensource #supplychain #tuf #sigstore #golang #kubernetes @StackLokHQ ex-@VMware
Alexis-Maurer Fortin ... @amfortin4
32 Followers 598 Following Senior Product Security Engineer @boostsecurityio
Richard @richarddaly
3K Followers 5K Following
Andrew Martin ⚡☸�... @sublimino
10K Followers 2K Following Hacker // CEO @controlplaneio | Cloud Native Security | CISO @OpenUK_UK | AI @FINOS | Hacking Kubernetes @OReillyMedia | Ex @cncfsecurityTAG @SANSInstitute 🦋
Marlow W. @copperflame
137 Followers 167 Following NVIDIAN & CNCF Batch Subproject Chair. Optimizes. Likes books, plants, octopuses, rocks, fountain pens, & naps. All opinions are my own.
Joshua Ferrell @Josh__Ferrell
379 Followers 1K Following K8S SRE @Adobe ex: AWS & VMware. ADHD to the max. @[email protected] Tweets are my own.
Mariano M. del Río �... @mmdelrio
4K Followers 1K Following Founder (@securetech_arg) | vCISO | Security Executive | Security Advisor | vCISO Community Space Founder | SECURETECH⚡#HacerLasCosasBien
Jakub Stransky ⛅ @jak_sky
639 Followers 2K Following Passionate Tech Lead & Architect | Cloud native. & GCP certified | DevOps | Backend developer | Follow me on the cloud journey
French @nfFrenchie
4K Followers 5K Following InfoSec geek for Cloud/Clusters/Containers/things-starting-with-C ex: @BrexHQ & @Cruise. founder @ensignia_dev honk the planet
Ed Warnicke @edwarnicke
1K Followers 697 Following Co-founder/committer @omnibor/@nservicemesh , Distinguished Engineer @Cisco
Saaras.io @SaarasInc
1K Followers 2K Following EnRoute Ingress API Gateway - Secure APIs and Microservices in less than a minute #Microservices #Kubernetes #EnvoyProxy #WASM #APIs #Edge
Colton Dempsey @coltondempsey
336 Followers 3K Following partner @N47capital investing in infrastructure software, developer tools, cybersecurity, SaaS and robotics
Greg @cobra16319
141 Followers 506 Following
DefenseUnicorns @DefenseUnicorns
598 Followers 221 Following Helping mission innovators become heroes through continuous software delivery.
Andrew Nairn @ACNzederr
29 Followers 545 Following
Michael Wardrop @MichaelWardrop
426 Followers 3K Following Passionate about the intersection of Trust, Safety, Privacy, Security, and Technology.
David Coulthart @real_doctor_d
36 Followers 791 Following
Justin Hutchings @jhutchings0
2K Followers 2K Following Senior Director of PM @cloudflare | Formerly @github @microsoft. Mostly tech, security, Star Trek 🖖🏻, with a sprinkle of far left political outrage.
Fintan Ryan @fintanr
4K Followers 2K Following Competitive Insights at @github, much #AI, but still tracking #DevSecOps & #Cloud l recovering analyst (ex @Gartner_Inc, @redmonk) | 331 ppm
Santiago @torresariass
830 Followers 898 Following Assistant Professor of ECE and Security Bricoleur @PurdueEngineers | @arch_security | views are my own
Daniel Pacak @d_pacak
352 Followers 1K Following Threat Hunting, Threat Detection and Response, ADR, CDR, EDR, Kubernetes, Linux Containers and eBPF
Stability AI @StabilityAI
262K Followers 10 Following We’ll help you make it like nobody’s business. Multimodal media generation and editing tools to get your idea to production. Self-deploy? 👍 Need a partner? 🤝
Mira Murati @miramurati
1.0M Followers 644 Following Now building @thinkymachines. Previously CTO @OpenAI
Santiago @torresariass
830 Followers 898 Following Assistant Professor of ECE and Security Bricoleur @PurdueEngineers | @arch_security | views are my own
Rob Slaughter @RobCSlaughter
258 Followers 421 Following CEO & founder Defense Unicorns 🦄 @usairforce dropout
Brandon Lum @lumjjb
964 Followers 625 Following 🔑CNCF Security TAG Co-Chair Emiritus 💻Google Engineer 🎸Musician/Guitarist All things Containers + Security... Opinions are my own...
DefenseUnicorns @DefenseUnicorns
598 Followers 221 Following Helping mission innovators become heroes through continuous software delivery.
Justin Cormack @justincormack
12K Followers 5K Following Doing new things. Now over at bsky not here
Luis Saiz Gimeno HTTP... @lsaiz
3K Followers 5K Following Telecomm. Eng. - Cryptography - Sys.Sec - Info.Sec - Tech. Fraud Prevention - Fraud Prevention Tech. - Global Security Center - Innovation in Security @BBVA
🦊 GitLab @gitlab
173K Followers 626 Following Build software faster. The DevSecOps Platform enables your entire organization to collaborate around your code.
GitHub Security Lab @GHSecurityLab
27K Followers 15 Following GitHub Security Lab’s mission is to inspire and enable the community to secure the open source software we all depend on.
Caleb Queern @HttpSecHeaders
657 Followers 941 Following @KPMG_US | Co-author of Investments Unlimited | @losVerdesATX | BJJ black belt. Views expressed are my own.
SPDX @SPDXTeam
414 Followers 124 Following An open standard for communicating software bill of material (SBOM) information, including components, licenses, copyrights, and security references.
Grype @GrypeProject
1K Followers 256 Following Grype is an open source vulnerability scanner for Software Bills of Material (SBOMs), containers, and filesystems. Created and maintained by @Anchore.
falcosecurity @falco_org
4K Followers 50 Following Cloud Native Runtime Security https://t.co/steV0fVLOi
Evan Gilman @evan2645
842 Followers 102 Following Co-founder @spirl_inc, and @SPIFFEio + SPIRE maintainer. Co-author of Zero Trust Networks. ex-@pagerduty ex-@scytale_io ex-@VMware
Syft @SyftProject
1K Followers 312 Following Syft is an open source tool to generate a Software Bill of Materials (SBOM) from a container image or filesystem. Created and maintained by @Anchore.
Brandon @governetes
391 Followers 1K Following safety third. co-founder & head yaml engineer @RancherFederal @rancher_govt
Aditya Sirish @adityasaky
294 Followers 1K Following Software Supply Chain Security @bloomberg | https://t.co/lUFR0LkHMp Maintainer | https://t.co/s7w0x5eQ0h | Prev. Ph.D. @nyu_cse
REI Systems @REI_Systems
462 Followers 363 Following REI Systems is a leading provider of web-based solutions to meet the complex business challenges of the public and private sectors.
Jason @ImJasonH
1K Followers 313 Following World's Okayest Dad, pizza enthusiast, single-hyphenate, onomatopoet, building Origin at @spacexai
Dan Luhring @danluhring
489 Followers 389 Following Heading up Vulnerability Management @chainguard_dev
Dan Lorenc @lorenc_dan
12K Followers 2K Following OSS Supply Chain Security. Founder/CEO/Primary Ariba Admin at https://t.co/sGmuUU9JbG Sigstore: https://t.co/dWKlyYu6kv
sigstore @projectsigstore
4K Followers 1 Following sigstore is a non-profit , public good software signing service funded under the OpenSSF. https://t.co/HYGAJ06Z11 [email protected]
🦄 Frederick Kautz ... @ffkiv
975 Followers 888 Following KubeCon Co-Chair, Co-Author of SPIFFE Book & Cloud-Native Security White Paper, SPIFFE Steering Committee, GitBom and NSM Co-Founder, Zero Trust, CISSP
Brad Downey @TechBradD
75 Followers 133 Following Technology Evangelist for the Digital Era. Helping customers move to a software and data driven economy.
Chainguard ⛓️ @chainguard_dev
6K Followers 116 Following The trusted source for open source (& memes).
OpenSSF @openssf
6K Followers 29 Following Open Source Security Foundation (OpenSSF) Together, we're securing the #opensource ecosystem #OSSSecurity https://t.co/uUpbn44G4Q https://t.co/adjLU8dbk0
Cole Kennedy @colek42c
547 Followers 456 Following Founder - TestifySec - Secure Systems from Source to Production
developer-guy @developerguyba
5K Followers 3K Following 🚀CNCF Ambassador 23• 🐳 Docker Captain 23•🎖Best Sigstore Evangelist 22 • ㏅CDF Ambassador 23 • 🇹🇷@kcdturkey Organizer •🕴Organizer @cloudnativetr @devopstr
Jonas Pettersson @petterssonsoftw
218 Followers 2K Following Rust, Go, Embedded, Webassembly and containers
Kim Lewandowski @kimsterv
3K Followers 736 Following 🥷 🐙 ⛓ Founder/Product at Chainguard. Previously at Google, and a smattering of other startups. Co-creator of SLSA, Security Scorecards and Tekton.
Andy Clemenko @clemenko
446 Followers 473 Following Geek, Dad, cyclist. - Docker / Kubernetes / Rancher - Tech Teacher https://t.co/vjsxYe5lfs
Trishank Karthik Kupp... @trishankkarthik
12K Followers 415 Following Amateur computational philosopher, #RWRI alumnus & instructor, physical culturist. Malaysian-American Tamil.











