Elektrine
Log in Register
Paige Chat Timeline Gallery Friends Email Drive DNS Private DNS Domains VPN Kairo Nerve
Remote

nscur0

@nscur0@infosec.exchange
mastodon 4.8.0-alpha.3+glitch
  • Open on infosec.exchange

Co-Lead of @DependencyTrack@infosec.exchange.
Maintainer of a bunch of @CycloneDX@infosec.exchange tooling.
AppSec, supply chain security, bill of materials opinion-haver.
Plant muncher 🌱.

0 Followers
0 Following
6 Posts
Joined November 11, 2022
GitHub:
https://github.com/nscuro
Location:
Kiel, Germany
Open post
nscur0 @nscur0@infosec.exchange
· 2w ago
Replying to
@fribbledom@mastodon.social Just hoping this hypothetical spec language doesn't involve XML or YAML in any shape or form.
1
0
0
0
Open post
nscur0 @nscur0@infosec.exchange
· 3mo ago
Getting really fucking tired of obscenely verbose Claude output being dumped verbatim into GitHub issues. If you can't be arsed to even write a comment yourself, why should I spend time interacting with it?
0
0
0
0
Open post
nscur0 @nscur0@infosec.exchange
· 4w ago
implementing workload identity federation. how hard can it be? i'm sure the token exchange will be super straightforward because IdPs all provide a small set of uniform claims, and it won't be necessary to use an expression language to deal with them, right?
0
0
0
1
Open post
nscur0 @nscur0@infosec.exchange
· 2w ago
RE: https://infosec.exchange/@nscur0/117254750212873843 Anyway, the upcoming version of @DependencyTrack@infosec.exchange will support workload identity federation, making long-lived API keys entirely obsolete for deployments where OIDC (e.g. through GitHub Actions) or SPIFFE is available. Long live short-lived credentials! Ergh, I mean...
Open quoted post
Quoting
nscur0
@nscur0@infosec.exchange
implementing workload identity federation. how hard can it be? i'm sure the token exchange will be super straightforward because IdPs all provide a small set of uniform claims, and it won't be necessary to use an expression language to deal with them, right?
Open quoted post
0
0
1
0
Open post
nscur0 @nscur0@infosec.exchange
· 1w ago
With Error Prone, NullAway, and Spotless, you can get a JVM project quite far to what you'd have in Go with its fantastic linter and formatter ecosystem. Obviously it'd be better if all that would ship with the JDK, but the tooling is mature and works well, and that's all that counts in the end. Error Prone being a compiler plugin means you pay the linting price on every build though. Most other ecosystems separate compilation from linting, which ofc makes builds faster but also linting entirely optional and easy to forget. Torn on what approach I like better.
0
1
0
0
Open post
nscur0 @nscur0@infosec.exchange
· 1w ago
Replying to
@elmuerte@idlethumbs.social Yep, although to my understanding it's necessary for some checks that would otherwise not be possible. It's more of a failure of the JDK for not offering a public API that alternative compilers can implement. Go has a fairly clean API for this (notably separate from the compiler entirely), but tbf Go is also a much simpler language. https://pkg.go.dev/golang.org/x/tools/go/analysis
pkg.go.dev

analysis package - golang.org/x/tools/go/analysis - Go Packages

Package analysis defines the interface between a modular static analysis and an analysis driver program.

0
0
0
0
Back
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

I2P eepsite

j6b6cyk6gjmepjih7jjadxgxvvf3lzzujljuu2v4biemzpg3naya.b32.i2p

Platform

  • Email
  • Chat
  • Timeline
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ
  • Lite (no JS)

Legal

  • Terms of Service
  • Privacy Policy
  • Transparency Report
  • Report Abuse
  • Warrant Canary
  • VPN Policy

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 22:40:17 UTC