Xavier Rene-Corail's Avatar

Xavier Rene-Corail

@xcorail

Open source security at GitHub. I don’t believe in perfection, but in continuous improvement. Opinions here are mine.

213
Followers
357
Following
58
Posts
21.10.2024
Joined
Posts Following

Latest posts by Xavier Rene-Corail @xcorail

Video thumbnail

“AI is destroying my humanity.” @mitchellh.com (HashiCorp; Ghostty, Vouch). From a conversation @helen.blog and I had with him.

Not an anti-AI take. A maintainer capacity take. Creation got cheaper. Review didn’t.

Maintainers: what’s helped you keep mentoring sustainable?

02.03.2026 16:00 👍 17 🔁 4 💬 1 📌 0

Come say hi 👋 at DeveloperWeek.

19.02.2026 17:10 👍 0 🔁 0 💬 0 📌 0

Who knows how to secure open source better than the maintainers themselves? 🛡️

17.02.2026 22:26 👍 27 🔁 7 💬 4 📌 2
Preview
Godfather Tom Hagen GIF Alt: Gif from the godfather where Mike tells Tom Hagen (played by Robert Duvall) that he is out. Tom answers “why am I out”

RIP Robert Duvall 😢

16.02.2026 18:58 👍 0 🔁 0 💬 0 📌 0

Apparently it decided that the drive-in line was the best place to stop for picking up the rider 😂

29.01.2026 06:43 👍 1 🔁 0 💬 0 📌 0
Cars are lined up in a fast food drive in and a self-driving Waymo car is trying to cut the line and insert into it.

Cars are lined up in a fast food drive in and a self-driving Waymo car is trying to cut the line and insert into it.

Not a Waymo forcing the passage and cutting the line in a In-n-Out drive in 🤦‍♂️

29.01.2026 06:42 👍 0 🔁 0 💬 1 📌 0

Thanks for what you’re doing for all of us Ian.

25.01.2026 02:33 👍 0 🔁 0 💬 0 📌 0

This is amazing. Use a SAST to detect security issues, and then triage those alerts with LLMs, to remove false positives and focus on real and exploitable issues.
And of course, the framework is open source.

21.01.2026 05:11 👍 3 🔁 1 💬 0 📌 0

Ooooh, subscribing to this thread! My son is 16 and is also about to get his DL!

14.12.2025 06:42 👍 0 🔁 0 💬 0 📌 0

But same: I rewatch a lot of movies … I use my kids, and their artistic education, as an excuse.

08.12.2025 02:06 👍 1 🔁 0 💬 0 📌 0
Preview
a man in a tuxedo is talking to another man in a room with the words some day and that day may never come Alt: The godfather (Marlon Brando) in a tuxedo is talking to another man in a room with the words some day and that day may never come, I’ll ask a service of you
08.12.2025 01:22 👍 1 🔁 0 💬 1 📌 0

Oh hell no! … I saw it once, and I am never watching it again! lol 😂
Too realistic, too scarily probable. I haven’t ever looked at mushrooms the same way.

08.12.2025 01:19 👍 1 🔁 0 💬 1 📌 0
Towards a secure by default GitHub Actions · community · Discussion #179107 Why are you starting this discussion? Product Feedback What GitHub Actions topic or product is this about? Workflow Configuration Discussion Details Today, GitHub announced upcoming changes to the ...

🚀 GitHub is making Actions more secure by default

We recently announced upcoming changes to the pull_request_target event and environment protection rules to make GitHub Actions more secure by default.

We’ve opened a discussion to gather feedback 👇

🔗 github.com/orgs/communi...

11.11.2025 18:38 👍 6 🔁 4 💬 0 📌 0
Video thumbnail

The internet was on fire. 🔥
One small library affecting billions of systems.
Log4Shell was the biggest security vulnerability of all time.

Now, Log4J maintainer, Christian Grobmeier tells us what it felt like inside the flames 👉 github.blog/open-source/...

20.10.2025 18:37 👍 114 🔁 18 💬 5 📌 3
Video thumbnail

“Ignorance will break all software.”

Log4Shell’s one line of code broke the internet, and taught us all a lesson we can’t ignore. As Christian Grobmeier, maintainer of Log4J puts it: "Learning is the only cure for ignorance. So just keep learning."

20.10.2025 19:05 👍 0 🔁 1 💬 0 📌 0

Oh, congrats Kara!

19.10.2025 02:58 👍 1 🔁 0 💬 0 📌 0
Preview
a woman in a striped coat is standing in front of a man ALT: a woman in a striped coat is standing in front of a man

😭

12.10.2025 00:03 👍 0 🔁 0 💬 0 📌 0
Preview
Our plan for a more secure npm supply chain GitHub is strengthening npm's security with stricter authentication, granular tokens, and enhanced trusted publishing.

We're taking action to make the npm supply chain stronger and harder to attack. 🛡️

Check out our plan to create a more secure future for the JavaScript community.👇
https://github.blog/security/supply-chain-security/our-plan-for-a-more-secure-npm-supply-chain/

30.09.2025 15:55 👍 29 🔁 10 💬 1 📌 3
Preview
Our plan for a more secure npm supply chain GitHub is strengthening npm's security with stricter authentication, granular tokens, and enhanced trusted publishing.

Recent account takeovers and attacks on package registries are a wake-up call: it's time to raise the bar on authentication and secure publishing practices. Find out what npm is doing—and what steps you can take—to help secure the open source supply chain: github.blog/security/sup...

23.09.2025 16:11 👍 3 🔁 3 💬 1 📌 0

Yay!

03.09.2025 03:18 👍 1 🔁 0 💬 0 📌 0
Preview
a close up of a man with the words we come far Alt: a close up of a dialogue between Greene and Costner in “Dance with wolves”: Greene: we come far you and me - Costner: I will not forget you

RIP Graham Greene.

02.09.2025 03:25 👍 1 🔁 0 💬 0 📌 0

When we see your smile for 2001 vs. Twilight, we know what the final result will be 😂

12.08.2025 04:40 👍 7 🔁 0 💬 0 📌 0

Hey security people, if you’re in Las Vegas, say hi!
If you want to talk open source security, or GitHub security products, I’d be happy to chat!

05.08.2025 16:37 👍 0 🔁 0 💬 0 📌 0
LinkedIn This link will take you to a page that’s not on LinkedIn

Are you at Security BSides Las Vegas?

Our very own Madison Oliver is joining a panel on the evolving role of the CVE Program — from funding challenges to global coordination and new governance models.

ℹ️ pretalx.com/security-bsi...
🗓️ August 5 | ⏰ 13:00–13:45 PT

05.08.2025 07:38 👍 1 🔁 1 💬 0 📌 0

Anyone else going to #ossna and flight to Denver is delayed, without visibility?

23.06.2025 00:57 👍 0 🔁 0 💬 0 📌 0

Throw them a volleyball and see what happens. We need to know.

23.06.2025 00:54 👍 1 🔁 0 💬 0 📌 0

If you, a business, are reliant on an open source project to function it is YOUR responsibility to assess and ensure the health of that project by either contributing to it yourself or by using an alternative if project health cannot be guaranteed.

22.06.2025 22:11 👍 370 🔁 73 💬 7 📌 7

I am curious now … which one?

16.06.2025 01:30 👍 1 🔁 0 💬 0 📌 0

It’s free. It’s fun. It’s easy.
Learn about secure coding with the GitHub secure code game.

04.06.2025 05:44 👍 1 🔁 0 💬 0 📌 0

Depends. It would take me too long to arrive … I would make long pauses on the grass!

29.05.2025 05:55 👍 1 🔁 0 💬 0 📌 0