Tap a claim on the ring to put it at the centre.
← Dependency cooldowns are currently the best defense against supply…
10 connected korrents · 9 moments on record from 22 Aug 2018 to 17 Sept 2026.
Everything filed under cybersecurity
cybersecurity
Everything filed under open source
open source
Same subject Same subject Same subject Same subject Same subject Same subject Same subject Same subject Same subject Same subject
Read this korrent: Dependency cooldowns are currently the best defense against supply chain attacks via compromised package publishers.
Dependency cooldowns are currently the best defense against supply chain attacks via compromised package publishers.
Last stated yesterday
17 Sept 2026
SW
Simon Willison — holds since 2026-09-17 — tap for who they are
Same subject: Any software that depends on open source has a network of humans with package publishing rights who are potential attack vectors. — tap to centre the map on it
Any software that depends on open source has a network of humans with package publishing rights who are potential attack vectors.
Last stated yesterday
17 Sept 2026
SW
Simon Willison — holds since 2026-09-17 — tap for who they are
Same subject: Most security reports an open-source project receives are agent-generated and untested, and the defence is publishing what you guarantee and what lies outside your security boundary. — tap to centre the map on it
Most security reports an open-source project receives are agent-generated and untested, and the defence is publishing what you guarantee and what lies outside your security boundary.
Last stated a month ago
10 Aug 2026
PS
Peter Steinberger — holds since 2026-08-10 — tap for who they are
Same subject: A million experiments are needed in security against autonomous attacks and entities. — tap to centre the map on it
A million experiments are needed in security against autonomous attacks and entities.
Last stated a week ago
9 Sept 2026
SP
Sunil Pai — holds since 2026-09-09 — tap for who they are
Same subject: A security header being present is not the same as it being deployed well, and most HSTS deployments are weaker than they look. — tap to centre the map on it
A security header being present is not the same as it being deployed well, and most HSTS deployments are weaker than they look.
Last stated 3 months ago
29 Jun 2026
SH
Scott Helme — holds since 2026-06-29 — tap for who they are
Same subject: A business making hundreds of millions from an open source project owes it money or contribution, and can be refused its trademarks if it gives neither. — tap to centre the map on it
A business making hundreds of millions from an open source project owes it money or contribution, and can be refused its trademarks if it gives neither.
Last stated 2 years ago
26 Sept 2024
MM
Matt Mullenweg — holds since 2024-09-26 — tap for who they are
Same subject: A company that will not accept a project’s terms is free to go and use a more permissive project instead. — tap to centre the map on it
A company that will not accept a project’s terms is free to go and use a more permissive project instead.
Last stated 2 years ago
26 Sept 2024
MM
Matt Mullenweg — holds since 2024-09-26 — tap for who they are
Same subject: A few hundred dollars a month is nothing to a company and transformative to a project, so engineers should be the ones asking their employers to pay it. — tap to centre the map on it
A few hundred dollars a month is nothing to a company and transformative to a project, so engineers should be the ones asking their employers to pay it.
Last stated 8 years ago
22 Aug 2018
DD
Drew DeVault — holds since 2018-08-22 — tap for who they are
Same subject: At any given moment the frontier systems are the ones worth worrying about, because by the time open models can do what these agents did, frontier models will be doing something far worse. — tap to centre the map on it
At any given moment the frontier systems are the ones worth worrying about, because by the time open models can do what these agents did, frontier models will be doing something far worse.
Last stated 2 weeks ago
1 Sept 2026
AC
Ajeya Cotra — holds since 2026-09-01 — tap for who they are
Same subject: Frontier AI labs such as Anthropic likely have had internal security incidents similar to OpenAI's HuggingFace attack that were never publicly disclosed. — tap to centre the map on it
Frontier AI labs such as Anthropic likely have had internal security incidents similar to OpenAI's HuggingFace attack that were never publicly disclosed.
Last stated 3 weeks ago
31 Aug 2026
ZM
Zvi Mowshowitz — holds since 2026-08-31 — tap for who they are
Same subject: OpenAI either could not find their agents' RubyGems attack in their logs after other incidents or knew and chose not to tell RubyGems, and both are bad. — tap to centre the map on it
OpenAI either could not find their agents' RubyGems attack in their logs after other incidents or knew and chose not to tell RubyGems, and both are bad.
Last stated 6 days ago
12 Sept 2026
SW
Simon Willison — holds since 2026-09-12 — tap for who they are
same subject or similar wording a cloud: claims about one subject, named for it bar: when it was last stated, on a scale from 2015 to today — full is today a face: someone on record holding the claim — tap it for who they are