<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: julietsecurity</title><link>https://news.ycombinator.com/user?id=julietsecurity</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Thu, 30 Apr 2026 17:52:40 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=julietsecurity" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[New comment by julietsecurity in "Show HN: Abom – Actions Bill of Materials for GitHub Actions Supply Chains"]]></title><description><![CDATA[
<p>We built this after CVE-2026-33634 (Trivy compromise). Every remediation guide says "grep your workflows for trivy-action" — but if you use a composite action that internally calls trivy-action, grep finds nothing.<p>abom recursively resolves every GitHub Action dependency in your workflows, including composite actions, reusable workflows, and actions that silently embed tools like Trivy as wrappers. It flags known-compromised actions against an advisory database and outputs standard formats (CycloneDX 1.5, SPDX 2.3) so you can treat your CI/CD supply chain like your application dependencies.<p>We're calling the output an ABOM — an Actions Bill of Materials. SBOMs exist for your app dependencies, ABOMs should exist for your pipelines.</p>
]]></description><pubDate>Thu, 26 Mar 2026 15:54:59 +0000</pubDate><link>https://news.ycombinator.com/item?id=47532061</link><dc:creator>julietsecurity</dc:creator><comments>https://news.ycombinator.com/item?id=47532061</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47532061</guid></item><item><title><![CDATA[Show HN: Abom – Actions Bill of Materials for GitHub Actions Supply Chains]]></title><description><![CDATA[
<p>Article URL: <a href="https://github.com/JulietSecurity/abom">https://github.com/JulietSecurity/abom</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=47532024">https://news.ycombinator.com/item?id=47532024</a></p>
<p>Points: 2</p>
<p># Comments: 1</p>
]]></description><pubDate>Thu, 26 Mar 2026 15:52:28 +0000</pubDate><link>https://github.com/JulietSecurity/abom</link><dc:creator>julietsecurity</dc:creator><comments>https://news.ycombinator.com/item?id=47532024</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47532024</guid></item><item><title><![CDATA[New comment by julietsecurity in "Algorithm Visualizer"]]></title><description><![CDATA[
<p>This is pretty neat. you should add sound effects like this - <a href="https://www.youtube.com/watch?v=kPRA0W1kECg" rel="nofollow">https://www.youtube.com/watch?v=kPRA0W1kECg</a></p>
]]></description><pubDate>Wed, 25 Mar 2026 12:18:51 +0000</pubDate><link>https://news.ycombinator.com/item?id=47516350</link><dc:creator>julietsecurity</dc:creator><comments>https://news.ycombinator.com/item?id=47516350</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47516350</guid></item></channel></rss>