<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: dlor</title><link>https://news.ycombinator.com/user?id=dlor</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Sun, 11 Oct 2026 09:09:37 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=dlor" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[New comment by dlor in "NIST gives up enriching most CVEs"]]></title><description><![CDATA[
<p>Enriching does a few things, but the main ones are adding CVSS information and CPE information.<p>CVSS (risk) is already well handled by other sources, but CPE (what software is affected) is kind of critical. I don't even know how they're going to focus enrichment on software the government uses without knowing what software the CVEs are in.</p>
]]></description><pubDate>Fri, 17 Apr 2026 18:34:36 +0000</pubDate><link>https://news.ycombinator.com/item?id=47809086</link><dc:creator>dlor</dc:creator><comments>https://news.ycombinator.com/item?id=47809086</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47809086</guid></item><item><title><![CDATA[New comment by dlor in "Supply chain nightmare: How Rust will be attacked and what we can do to mitigate"]]></title><description><![CDATA[
<p>We're going to be launching Chainguard Libraries for Rust in a few weeks, this article perfectly calls out the issues.<p>crates are somewhat better designed than NPM/PyPI (the dist artifacts are source based), but still much worse than Go where there's an intermediate packaging step disconnected from the source of truth.</p>
]]></description><pubDate>Fri, 10 Apr 2026 18:38:46 +0000</pubDate><link>https://news.ycombinator.com/item?id=47721989</link><dc:creator>dlor</dc:creator><comments>https://news.ycombinator.com/item?id=47721989</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47721989</guid></item><item><title><![CDATA[New comment by dlor in "Tell HN: Litellm 1.82.7 and 1.82.8 on PyPI are compromised"]]></title><description><![CDATA[
<p>It's both. They got compromised by another supply chain attack on Trivy initially.</p>
]]></description><pubDate>Tue, 24 Mar 2026 16:21:47 +0000</pubDate><link>https://news.ycombinator.com/item?id=47505067</link><dc:creator>dlor</dc:creator><comments>https://news.ycombinator.com/item?id=47505067</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47505067</guid></item><item><title><![CDATA[New comment by dlor in "A Safer Container Ecosystem with Docker: Free Docker Hardened Images"]]></title><description><![CDATA[
<p>Hey!<p>I work at Chainguard. We don't guarantee zero active exploits, but we do have a contractual SLA we offer around CVE scan results (those aren't quite the same thing unfortunately).<p>We do issue an advisory feed in a few versions that scanners integrate with. The traditional format we used (which is what most scanners supported at the time) didn't have a way to include pending information so we couldn't include it there.<p>The basic flow was: scanner finds CVE and alerts, we issue statement showing when and where we fixed it, the scanner understands that and doesn't show it in versions after that.<p>so there wasn't really a spot to put "this is present", that was the scanner's job. Not all scanners work that way though, and some just rely on our feed and don't do their own homework so it's hit or miss.<p>We do have another feed now that uses the newer OSV format, in that feed we have all the info around when we detect it, when we patch it, etc.<p>All this info is available publicly and shown in our console, many of them you can see here: <a href="https://github.com/wolfi-dev/advisories" rel="nofollow">https://github.com/wolfi-dev/advisories</a><p>You can take this example: <a href="https://github.com/wolfi-dev/advisories/blob/main/amass.advisories.yaml" rel="nofollow">https://github.com/wolfi-dev/advisories/blob/main/amass.advi...</a> and see the timestamps for when we detected CVEs, in what version, and how long it took us to patch.</p>
]]></description><pubDate>Wed, 17 Dec 2025 19:04:58 +0000</pubDate><link>https://news.ycombinator.com/item?id=46303993</link><dc:creator>dlor</dc:creator><comments>https://news.ycombinator.com/item?id=46303993</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46303993</guid></item><item><title><![CDATA[New comment by dlor in "Analysis of supply-chain attack on Ultralytics"]]></title><description><![CDATA[
<p>Really cool to see all the hard work on Trusted Publishing and Sigstore pay off here. As a reminder, these tools were never meant to prevent attacks like this, only to make them easier to detect, harder to hide, and easier to recover from.</p>
]]></description><pubDate>Sat, 14 Dec 2024 16:02:51 +0000</pubDate><link>https://news.ycombinator.com/item?id=42417858</link><dc:creator>dlor</dc:creator><comments>https://news.ycombinator.com/item?id=42417858</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=42417858</guid></item><item><title><![CDATA[New comment by dlor in "PyPI now supports digital attestations"]]></title><description><![CDATA[
<p>This is awesome to see, and the result of many years of hard work from awesome people.</p>
]]></description><pubDate>Thu, 14 Nov 2024 15:00:57 +0000</pubDate><link>https://news.ycombinator.com/item?id=42136754</link><dc:creator>dlor</dc:creator><comments>https://news.ycombinator.com/item?id=42136754</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=42136754</guid></item><item><title><![CDATA[New comment by dlor in "Chainguard Images now available on Docker Hub"]]></title><description><![CDATA[
<p>There's no defeating of scanners or even static linking. It's all automation, dynamic linking and patching to make the scanners happy. We go to great lengths to make sure that the scanners actually find everything so the results are accurate.</p>
]]></description><pubDate>Thu, 14 Mar 2024 15:24:02 +0000</pubDate><link>https://news.ycombinator.com/item?id=39705202</link><dc:creator>dlor</dc:creator><comments>https://news.ycombinator.com/item?id=39705202</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=39705202</guid></item><item><title><![CDATA[New comment by dlor in "Chainguard Images now available on Docker Hub"]]></title><description><![CDATA[
<p>I can confirm our business is roughly 0 percent consulting and that it's 100% selling these hardened images.</p>
]]></description><pubDate>Thu, 14 Mar 2024 15:21:44 +0000</pubDate><link>https://news.ycombinator.com/item?id=39705169</link><dc:creator>dlor</dc:creator><comments>https://news.ycombinator.com/item?id=39705169</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=39705169</guid></item><item><title><![CDATA[New comment by dlor in "Chainguard Images now available on Docker Hub"]]></title><description><![CDATA[
<p>The big ones that help are SBOMs, STIGs, FIPS, and CVE reduction. The images and the paperwork we provide make it so they can be dropped in to even the most regulated environments without toil.<p>Most of our customers use them for FedRAMP or IL 5/6 stuff out of the box.</p>
]]></description><pubDate>Thu, 14 Mar 2024 15:18:56 +0000</pubDate><link>https://news.ycombinator.com/item?id=39705138</link><dc:creator>dlor</dc:creator><comments>https://news.ycombinator.com/item?id=39705138</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=39705138</guid></item><item><title><![CDATA[New comment by dlor in "Chainguard Images now available on Docker Hub"]]></title><description><![CDATA[
<p>The program details are here: <a href="https://docs.docker.com/trusted-content/dvp-program/" rel="nofollow">https://docs.docker.com/trusted-content/dvp-program/</a></p>
]]></description><pubDate>Thu, 14 Mar 2024 14:54:24 +0000</pubDate><link>https://news.ycombinator.com/item?id=39704839</link><dc:creator>dlor</dc:creator><comments>https://news.ycombinator.com/item?id=39704839</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=39704839</guid></item><item><title><![CDATA[New comment by dlor in "Chainguard Images now available on Docker Hub"]]></title><description><![CDATA[
<p>Yep, that's it - the product is hardened container images!</p>
]]></description><pubDate>Thu, 14 Mar 2024 14:51:53 +0000</pubDate><link>https://news.ycombinator.com/item?id=39704794</link><dc:creator>dlor</dc:creator><comments>https://news.ycombinator.com/item?id=39704794</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=39704794</guid></item><item><title><![CDATA[New comment by dlor in "Chainguard Images now available on Docker Hub"]]></title><description><![CDATA[
<p>Great question! We take hardening of our build infrastructure very seriously, and helped build many of the OSS technologies in this space like the SLSA framework and the Sigstore project.<p>We produce SBOMs during the build process, and cryptographically sign SLSA-formatted provenance artifacts depicting the entire build process so you can trace a built container all the way back to the sources it was built from.<p>We also try to make as much of our build system reproducible as possible (but we're not all the way there yet), so you can audit or rebuild the process yourself.</p>
]]></description><pubDate>Thu, 14 Mar 2024 14:43:39 +0000</pubDate><link>https://news.ycombinator.com/item?id=39704678</link><dc:creator>dlor</dc:creator><comments>https://news.ycombinator.com/item?id=39704678</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=39704678</guid></item><item><title><![CDATA[New comment by dlor in "Chainguard Images now available on Docker Hub"]]></title><description><![CDATA[
<p>Good callout, if you know how to use docker and and dockerhub then it's just as easy as `docker pull chainguard/node`</p>
]]></description><pubDate>Thu, 14 Mar 2024 14:33:37 +0000</pubDate><link>https://news.ycombinator.com/item?id=39704543</link><dc:creator>dlor</dc:creator><comments>https://news.ycombinator.com/item?id=39704543</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=39704543</guid></item><item><title><![CDATA[New comment by dlor in "Chainguard Images now available on Docker Hub"]]></title><description><![CDATA[
<p>I work at Chainguard, happy to answer any questions!</p>
]]></description><pubDate>Thu, 14 Mar 2024 14:02:40 +0000</pubDate><link>https://news.ycombinator.com/item?id=39704137</link><dc:creator>dlor</dc:creator><comments>https://news.ycombinator.com/item?id=39704137</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=39704137</guid></item><item><title><![CDATA[OpenPubKey and Sigstore]]></title><description><![CDATA[
<p>Article URL: <a href="https://blog.sigstore.dev/openpubkey-and-sigstore/">https://blog.sigstore.dev/openpubkey-and-sigstore/</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=37786781">https://news.ycombinator.com/item?id=37786781</a></p>
<p>Points: 93</p>
<p># Comments: 28</p>
]]></description><pubDate>Fri, 06 Oct 2023 03:12:45 +0000</pubDate><link>https://blog.sigstore.dev/openpubkey-and-sigstore/</link><dc:creator>dlor</dc:creator><comments>https://news.ycombinator.com/item?id=37786781</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=37786781</guid></item><item><title><![CDATA[The Tyranny of Nits]]></title><description><![CDATA[
<p>Article URL: <a href="https://www.leafwing-studios.com/blog/tyranny-of-nits/">https://www.leafwing-studios.com/blog/tyranny-of-nits/</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=37715590">https://news.ycombinator.com/item?id=37715590</a></p>
<p>Points: 1</p>
<p># Comments: 0</p>
]]></description><pubDate>Sat, 30 Sep 2023 14:09:31 +0000</pubDate><link>https://www.leafwing-studios.com/blog/tyranny-of-nits/</link><dc:creator>dlor</dc:creator><comments>https://news.ycombinator.com/item?id=37715590</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=37715590</guid></item><item><title><![CDATA[New comment by dlor in "Mystery 'golden egg' found on ocean floor"]]></title><description><![CDATA[
<p>Have you ever been on a boat? It's not safe to assume the existence of anything, including a toilet, on them.</p>
]]></description><pubDate>Sun, 10 Sep 2023 21:26:21 +0000</pubDate><link>https://news.ycombinator.com/item?id=37460242</link><dc:creator>dlor</dc:creator><comments>https://news.ycombinator.com/item?id=37460242</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=37460242</guid></item><item><title><![CDATA[CVSS 4.0 Is Here, but Prioritizing Patches Still a Hard Problem]]></title><description><![CDATA[
<p>Article URL: <a href="https://www.darkreading.com/vulnerabilities-threats/cvss-4-prioritizing-patches-hard-problem">https://www.darkreading.com/vulnerabilities-threats/cvss-4-prioritizing-patches-hard-problem</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=36850036">https://news.ycombinator.com/item?id=36850036</a></p>
<p>Points: 3</p>
<p># Comments: 0</p>
]]></description><pubDate>Mon, 24 Jul 2023 15:58:13 +0000</pubDate><link>https://www.darkreading.com/vulnerabilities-threats/cvss-4-prioritizing-patches-hard-problem</link><dc:creator>dlor</dc:creator><comments>https://news.ycombinator.com/item?id=36850036</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=36850036</guid></item><item><title><![CDATA[New comment by dlor in "Open Container Initiative announces upcoming changes for registries"]]></title><description><![CDATA[
<p>Yep - a new version of image spec and distribution spec (not runtime spec).<p>This version allows for formalized ways to store other types of content in registries (think Helm Charts, OPA policies, etc.), as well as a way to "attach" arbitrary content to registries and then retrieve it later.<p>Both of these are powerful and will have lots of use cases, but the primary ones at this point are focused on supply chain security - storing content like SBOMs, digital signatures and attestations.</p>
]]></description><pubDate>Thu, 13 Jul 2023 18:26:56 +0000</pubDate><link>https://news.ycombinator.com/item?id=36713863</link><dc:creator>dlor</dc:creator><comments>https://news.ycombinator.com/item?id=36713863</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=36713863</guid></item><item><title><![CDATA[New comment by dlor in "CWE Top Most Dangerous Software Weaknesses"]]></title><description><![CDATA[
<p>Personally? I've done quite a bit here although there's always more. I worked at Google to fund Rust development internally and externally, helped sponsor the work that eventually led to getting Rust adopted in the Linux kernel, and now run a company that's building a new Linux distribution that prioritizes shipping code written in memory safe languages.<p><a href="https://security.googleblog.com/2021/02/mitigating-memory-safety-issues-in-open.html" rel="nofollow noreferrer">https://security.googleblog.com/2021/02/mitigating-memory-sa...</a><p><a href="https://www.chainguard.dev/unchained/building-the-first-memory-safe-distro-wolfi" rel="nofollow noreferrer">https://www.chainguard.dev/unchained/building-the-first-memo...</a></p>
]]></description><pubDate>Thu, 13 Jul 2023 12:56:03 +0000</pubDate><link>https://news.ycombinator.com/item?id=36708397</link><dc:creator>dlor</dc:creator><comments>https://news.ycombinator.com/item?id=36708397</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=36708397</guid></item></channel></rss>