mastodon.me.uk is one of the many independent Mastodon servers you can use to participate in the fediverse.
Open, user-supported, corporation-free social media for the UK.

Administered by:

Server stats:

545
active users

re: xz

In a dream world, we'd be able to pay an open source tithe somewhere that gets automatically split up between all the open source dependencies we're reliant on, all the way down. And if a project isn't set up to receive the money, it gets held in trust until it is.

I know this is an incredibly hard problem, but I really really hope someone is working on it. It's all open source; we can KNOW what we're running, surely.

@Floppy sboms finally have a purpose.

@Floppy @bob @www.jvt.me I've been banging on for months we need SBOM for everything we ship, and even now I'm working on improving our CI/CD pipelines to actually ship binaries in highly controlled images instead of source + packages so we minimise what we ship - keep everything potentially insecure at the build level. Looks like I'll keep working on it...