Bob Callaway (@rdcallaw) 's Twitter Profile
Bob Callaway

@rdcallaw

OSS Supply Chain Security @google. @projectsigstore @theopenssf Technical Advisory Council - Ex-Red Hat, NetApp, IBM. PhD ECE NCSU.

ID: 144962898

calendar_today17-05-2010 19:40:36

499 Tweet

680 Followers

129 Following

sigstore (@projectsigstore) 's Twitter Profile Photo

ā° Reminder folks, the CFP deadline is Sept 13, please submit your talks before then! events.linuxfoundation.org/sigstorecon-su…

sigstore (@projectsigstore) 's Twitter Profile Photo

Announcing the schedule for SigstoreCon: Supply Chain Day! We're looking forward to talks on Sigstore development, package registry security, SBOMs, TUF, and more! Register now for Nov 12, co-located with Kubecon NA in Salt Lake City events.linuxfoundation.org/sigstorecon-su…

OpenSSF (@openssf) 's Twitter Profile Photo

🚨 The SigstoreCon agenda is live! Join us at KubeCon NA 2024 in Salt Lake City for deep dives into digital artifact signing, Sigstore, SLSA, TUF & more. Don't miss insights on the latest in supply chain security. events.linuxfoundation.org/sigstorecon-su… #SigstoreCon #OSSSecurity

OpenSSF (@openssf) 's Twitter Profile Photo

šŸš€ Showcase your brand at #SigstoreCon: Supply Chain Day! Join us to support the future of digital artifact signing & supply chain security. šŸ”— Explore options: events.linuxfoundation.org/sigstorecon-su…

šŸš€ Showcase your brand at #SigstoreCon: Supply Chain Day! Join us to support the future of digital artifact signing & supply chain security.
šŸ”— Explore options: events.linuxfoundation.org/sigstorecon-su…
sigstore (@projectsigstore) 's Twitter Profile Photo

Join us at SigstoreCon: Supply Chain Day on Nov 12, co-located with KubeCon NA in SLC! Registration includes a day of engaging talks, lunch, and swag! events.linuxfoundation.org/sigstorecon-su…

Trail of Bits (@trailofbits) 's Twitter Profile Photo

ToB's Artur Cygan found code execution and DoS bugs after just a few hours of fuzzing ZBar, an open-source library for reading barcodes. tl;dr basic fuzz testing can reveal serious bugs - even in widely used software. blog.trailofbits.com/2024/10/31/fuz…

Oliver Chang (@halbecaf) 's Twitter Profile Photo

New blog post about OSS-Fuzz AI-powered fuzzing is live! We talk about what went into making LLMs work well enough for this use case to find 26 new vulnerabilities (including a CVE in OpenSSL), as well as what else we have planned to make this better. security.googleblog.com/2024/11/leveli…

Heather Adkins - Ꜻ - Spes consilium non est (@argvee) 's Twitter Profile Photo

On the heels of Google’s ā€˜Big Sleep’ AI discovery of a real-world vulnerability, our OSS-Fuzz team identified and reported 26 vulnerabilities to open-source project maintainers by using AI-generated and enhanced fuzz targets. Read more here: security.googleblog.com/2024/11/leveli…

Oliver Chang (@halbecaf) 's Twitter Profile Photo

Happy new year! OSV had a lot of great progress in 2024, from new ecosystem adoption, API improvements, and scanner feature development! We just published a blog about these and our 2025 plans here: osv.dev/blog/posts/202… !

Bob Callaway (@rdcallaw) 's Twitter Profile Photo

cloud.google.com/blog/products/… Awesome blog on how we’re using SLSA to make GKE more secure for our customers!

Oliver Chang (@halbecaf) 's Twitter Profile Photo

OSV-Scanner has just released the first beta for V2, a major update that includes significant new features, including layer-aware container scanning, remediation for pom.xml, new HTML output and more. osv.dev/blog/posts/osv… Please try it out and give us feedback!

OpenSSF (@openssf) 's Twitter Profile Photo

šŸš€ The Alpha-Omega project has published its 2024 annual report! With $6M in grants, Alpha-Omega helped staff security teams, fund audits, and strengthen critical #opensource projects—shaping a more secure and sustainable ecosystem. šŸ“– hubs.la/Q034J9HY0

šŸš€ The Alpha-Omega project has published its 2024 annual report!

With $6M in grants, Alpha-Omega helped staff security teams, fund audits, and strengthen critical #opensource projects—shaping a more secure and sustainable ecosystem.

šŸ“– hubs.la/Q034J9HY0
OpenSSF (@openssf) 's Twitter Profile Photo

šŸ“£ Announcing v1.0 of the model-signing project, developed by the #OpenSSF AI/ML WG! This project enables signing + verifying ML models of any size/format using #sigstore, self-signed certs, or key pairs. Read the blog to learn more & get involved: openssf.org/blog/2025/04/0…

šŸ“£ Announcing v1.0 of the model-signing project, developed by the #OpenSSF AI/ML WG! This project enables signing + verifying ML models of any size/format using #sigstore, self-signed certs, or key pairs. Read the blog to learn more & get involved: openssf.org/blog/2025/04/0…
Mihai Maruseac (@mihaimaruseac) 's Twitter Profile Photo

Yesterday we launch v1.0 of model signing library, taming the wild west of model formats and deserialization vulnerabilities. You can read more about why this is needed and why we picked Sigstore as main signing method at security.googleblog.com/2025/04/taming…

Ryan Hurst (@rmhrisk) 's Twitter Profile Photo

Excellent post on how confidential computing is being used with the transparency.dev witness ecosystem. blog.transparency.dev/hardening-witn…

Mihai Maruseac (@mihaimaruseac) 's Twitter Profile Photo

I was pleasantly surprised to see model signing presented in the first 5 slides of the conference. And then the A2A talk raised the stakes: we need to sign the agent cards. My thesis: we can do the same with the same model signing solution

OpenSSF (@openssf) 's Twitter Profile Photo

Tom Hennen from Google shares how the new #SLSA Source Track helps reduce the risk of source tampering—bringing stronger guarantees to code integrity and auditability. Learn how to protect your repo from attacks like PHP and xz. #OSSummit #OpenSSF #SupplyChainSecurity

Tom Hennen from <a href="/Google/">Google</a> shares how the new #SLSA Source Track helps reduce the risk of source tampering—bringing stronger guarantees to code integrity and auditability. Learn how to protect your repo from attacks like PHP and xz. #OSSummit #OpenSSF #SupplyChainSecurity