#OpenJS

Frontend Dogmafrontenddogma@mas.to
2026-01-30

OpenJS Foundation Security Program: Annual Report 2025, by @openjsf:

openjsf.org/blog/openjs-securi

#openjs

Frontend Dogmafrontenddogma@mas.to
2025-11-02

Lit Is Joining the OpenJS Foundation, by @lit.dev:

lit.dev/blog/2025-10-14-openjs/

#lit #openjs

2025-10-27

๐Ÿš€ Recent #Lodash updates focus on stronger #CI & #security posture!

โœ… CI support expanded (Node 4 โ†’ 25)

๐ŸŒ New browser tests via #Playwright

๐Ÿ“ Docs now have dedicated CI

๐Ÿ”’ Added #OpenJS #CNA escalation policy

๐Ÿ“Š Reporting #OSSF #Scorecard

๐Ÿงฏ New Incident Response Plan (#IRP)

๐Ÿง  Threat Model inspired by #Express & #Webpack

More details: blog.ulisesgascon.com/the-futu

TonySpegeltonyspegel
2025-10-14

is now an OpenJS Foundation Impact Project, transitioning to an open governance model.
It's my go-to for web components and has been trusted by many large projects for years, check it out ๐Ÿค 

lit.dev/blog/2025-10-14-openjs/

2025-09-22

Welcome Rafael Gonzaga to the #OpenJS #CNA team! ๐Ÿ‘ ๐Ÿ‘ ๐Ÿ‘

github.com/openjs-foundation/s

2025-09-05

๐Ÿฟ Exciting news! The #OpenJS Foundation #AI Collaboration Space holds its first meeting next week.

A community hub where developers, maintainers and policy thinkers explore how #JavaScript connects billions of people to #AI.

github.com/openjs-foundation/a

2025-09-02

๐Ÿ—ž๏ธ Exciting news: #webpack now has a Security Working Group!

Weโ€™ll:
๐Ÿ‘‰ Define triage & policies
๐Ÿ‘‰ Guide secure plugin development
๐Ÿ‘‰ Improve report processes
๐Ÿ‘‰ Promote best practices
๐Ÿ‘‰ Support #OpenJS & #OpenSSF initiatives

github.com/webpack/security-wg

Benjamin Sternthalbooboobenny@indieweb.social
2025-03-18

Member summit week. #openjs #opensource

Lanyard and laptop
Bart Louwersbart@floss.social
2024-09-08

Iโ€™ll be in #London tomorrow with some time to kill. Feels like a waste to just work in my hotel. If you want to meet up or have tips, let me know!

Attending the #OpenJS Vizualization Summit at the Microsoft offices Tuesday and Wednesday. Mostly as an excuse to meet my #MapLibre colleagues. ๐Ÿ™‚

Gea-Suan Lingslin@abpe.org
2024-05-12

XZ ็š„ๅพŒ้–€ไบ‹ไปถ๏ผŒไปฅๅŠ OpenJS Foundations ไนŸ้‡ๅˆฐ้กžไผผ็š„ๅ•้กŒ

XZ ็š„ๅพŒ้–€ไบ‹ไปถๅพžๆšด็™ผๅ‡บไพ†ไนŸๅทฒ็ถ“ไธ€ๅ€‹ๅคšๆœˆไบ†๏ผŒๅคงๅคšๆ•ธ็š„่ญ‰ๆ“šไนŸ้ƒฝๅˆ†ๆž็š„ๅทฎไธๅคšไบ†๏ผŒๆ˜ฏๅทฎไธๅคšๅฏไปฅๅ›ž้กงไธ€ไธ‹...

blog.gslin.org/archives/2024/0

#Computer #Murmuring #Security #Software #backdoor #community #engineering #foundations #maintainer #open #openjs #security #social #source #xz

Benjamin Carr, Ph.D. ๐Ÿ‘จ๐Ÿปโ€๐Ÿ’ป๐ŸงฌBenjaminHCCarr@hachyderm.io
2024-05-04

Open sourcerers say suspected #xz-style attacks continue to target #maintainers
#SocialEngineering patterns spotted across range of popular projects
Higher-ups at the #OpenJS Foundation and #OpenSource Security Foundation (#OpenSSF) believe the attempt to plant a #backdoor into #Linux's xz data compression library "may not be an isolated incident" given their recent observations.
theregister.com/2024/04/16/xz_

2024-04-18
Benjamin Carr, Ph.D. ๐Ÿ‘จ๐Ÿปโ€๐Ÿ’ป๐ŸงฌBenjaminHCCarr@hachyderm.io
2024-04-18

Open Source Security (#OpenSSF) and #OpenJS Warn of Fake #Maintainers Targeting #JavaScript Projects
Alarming #socialengineering attacks target critical #opensource projects! Learn how to protect your project and the open-source community from takeovers. hackread.com/openssf-fake-main #itsec #cybersecurity #supplychain

2024-04-16

Excellent summary by Solar Designer on oss-security of what's happened in the last two weeks in response to the #xz #backdoor:

openwall.com/lists/oss-securit

Noteworthy:
- #OpenSSH implemented systemd notification
- #systemd moves to dlopen(3) for some dependencies
- another detailed timeline at research.swtch.com/xz-timeline
- similar social engineering takeover attempts suspected in #OpenJS and #OpenSSF

Sam Stepanyan :verified: ๐Ÿ˜securestep9@infosec.exchange
2024-04-16
Matt "msw" Wilsonmsw@mstdn.social
2024-04-15

This exemplifies the unique network of human beings in and around Open Source that makes it so _resilient_.

With OSS, people are curious. They are empowered to take a peek under the hood. To share what they find with others. To ignore organizational and architectural boundaries.

#OpenSource #FreeSoftware #FOSS #OSS #InfoSec #XZ #OpenJS #OpenSSF #Linux #SOSSCommunity

twitter.com/postgresperf/statu

Matt "msw" Wilsonmsw@mstdn.social
2024-04-15

Free and Open Source software communities are anything *but* โ€œfragileโ€ in light of recent failed attacks.

They are smart. They are vigilant. They are resilient.

But they also need support from institutions given the resources attackers may have.

#OpenSource #FreeSoftware #FOSS #OSS #InfoSec #XZ #OpenJS #OpenSSF #Linux #SOSSCommunity

Matt "msw" Wilsonmsw@mstdn.social
2024-04-15

Open Source Security (OpenSSF) and OpenJS Foundations Issue Alert for Social Engineering Takeovers of Open Source Projects

XZ Utils cyberattack likely not an isolated incident

#OpenSource #FreeSoftware #FOSS #OSS #InfoSec #XZ #OpenJS #OpenSSF #Linux

openjsf.org/blog/openssf-openj

2023-10-20

How does Wikimedia approach security and performance?

We're quite selective in our dependencies and often audit the sources ourselves. Progressive enhancement makes for a blazing fast and accessible site, and, I argue, it's also the cheaper choice in the long run!

timotijhof.net/posts/2023/wiki

#mediawiki #Wikipedia #OpenJS #infosec #webperf #foss #floss

Client Info

Server: https://mastodon.social
Version: 2025.07
Repository: https://github.com/cyevgeniy/lmst