How mature is this repository? My long quest for open-source software metrics For years, I have been looking for a reasonable answer to a deceptively simple question: When I discover an open-source software project for the first time, how can I estimate whether it is mature, healthy and usable? Usually the first encounter is a repository on GitHub, GitLab, Codeberg or another forge. And usually we…
Sovereignty Is Engineered, Not Procured Europe often asks whether it can build a company like Palantir: a software champion capable of serving intelligence, defence, law enforcement, crisis response, cyber defence, and public-sector decision-making at scale. The usual answer is that Europe lacks data, capital, talent, or legal room. I do not think this is the full story. The capacity is there. The…
Don’t Do Team Meetings Regular team meetings are often treated as a default part of work. They are seen as a sign of coordination, alignment, and healthy communication. In practice, they often reveal the opposite. A recurring team meeting where everyone goes around the room to explain what they did last week is usually not a good use of time. It turns communication into a performance instead of a…
Bring Back RSS for Operational Security This post expands on ideas I previously presented at Pass the SALT 2024 in my talk Bring Back RSS For Operational Security . 1 2 The short version is simple: operational security teams still need a reliable way to track change, automate collection, and reduce dependency on closed platforms. RSS already solves much of that problem. Operational security teams…
Open Contributions Descriptor — or how to map your contribution in open source, open data, and open standards Open ecosystems thrive on collaboration. Open source software, open data initiatives, and open standards communities all depend on a complex web of contributors, maintainers, organizations, and users working together across domains and borders. Yet, despite this openness, one surprisingly…
Full Disclosure Still Exists and That’s Exactly the Point Disclaimer: This post is grounded in personal experience and roughly 25 years of interaction with vulnerability management , across vendors, researchers, operators, CERTs, and open communities. It does not claim neutrality or theoretical purity. It reflects what repeatedly emerges when disclosure leaves policy documents and meets reality.…
This open source book explores how intelligence and cyber-security analysts can uncover hidden links between threat actor infrastructure and ongoing investigations by pivoting on both classic and unconventional indicators — many of which are often overlooked. The material is grounded in empirical, field-tested strategies used in cyber-security, digital forensics, cyber threat intelligence, and…
How to Choose an Open Source Project for the Long Term version 1.0 - 25th May 2025 Many of us face the challenge of selecting open source projects for long-term use. This could involve choosing dependencies for your own open source project, or simply selecting software you plan to run and rely on over time. After experiencing multiple failures, disappointments with projects that turned…
J’ai toujours des idées à la con… Il y avait une issue sur GitHub pour créer un petit livret en PDF et EPUB de notre brol sillonesque . L’optimisme est toujours l’apanage des fous . Comme le chat n’était pas en super forme, je me suis dit que travailler sur l’ordinateur serait facile tout en lui tenant compagnie. Je commence en me disant qu’une conversion de pages HTML vers un livre PDF serait…
If you are writing, one of your primary objectives is to be seen and read—two distinct but interconnected goals. Visibility helps your work reach a wider audience, which can lead to more readers engaging with your content. However, in today’s Internet landscape, visibility is shaped by algorithms on social networks, search engines, and advertising networks. These systems often prioritize content…