Content by Gregg Cochran (3)
Gregg Cochran shares lessons from Session 4 of the GitHub Secure Open Source Fund, where 50 projects used GitHub security tooling, expert guidance, and AI-assisted workflows to make measurable security improvements—covering incident response, supply chain risks, and how maintainers can use tools like GitHub Copilot for triage and remediation.
Gregg Cochran explores how the GitHub Secure Open Source Fund empowered maintainers of 67 crucial AI stack projects to boost software supply chain security—a pivotal effort for global open source safety.
Gregg Cochran shares the inside story of the Log4Shell vulnerability, focusing on the personal and technical challenges faced by Log4j maintainers and highlighting the critical need for open source security reforms.
End of content