@taleodori
iAccount based inCanada
About this account
- Account based in
- Canada
- Connected via
- Web
Account-level information from X, not a live location or the device used for a specific post.
Pinned Tweet
Working (never expires) join link for our community DevOps and DataOps Discord Server: discord.gg/UTxjBf9juQ
Missed my live ReARM CE Demo at Black Hat USA 2026? Here is a pre-recorded version, where AI agent tried to cheat but ReARM caught it with the help of an #SBOM produced by cdxgen.
youtube.com/watch?v=qjSyETch…
I believe hashes are the weakest link in 2026 CISA's Minimum Elements #SBOM requirements and here is why and what we can potentially do about it - worklifenotes.com/2026/09/14…
I'm hosting Matt Rutkowski from IBM with his talk "Beyond the Model Card: Engineering Trust into AI Systems using AI/ML-BOM and #CycloneDX" on the next ML&AI Ottawa online meetup. September 23rd at 1pm - meetup.com/machine-learning-… #AIBOM #AI
ReARM 26.08.95 makes Team a first-class entity so you can trace relationships from products and components to respective teams that own them with their own notification channels.
Full notes: rearmhq.com/news/2026-08-27-…
#SBOM #SupplyChainSecurity #ProductSecurity #DevSecOps
Who's really in the loop when a coding agent ships your code?
At the ML & AI #Ottawa #Meetup sponsored by #ReARM, Petar Djukic demonstrated the workflow he uses daily to generate production code with #AI agents.
youtube.com/watch?v=KU_AsbMm…
ReARM 26.07.158 is out.
🔔 A reworked notifications platform
🔍 Dependency-Track 5 support
📦 We've open-sourced our Dependency-Track 5 Helm chart
Plus: installing ReARM CE got much easier!
rearmhq.com/news/2026-07-29-…
#SBOM #SupplyChainSecurity #DevSecOps #OpenSource
ReARM is proud to sponsor the online meetup on #Agentic Feedback Loops, featuring the talk "The Human is the Loop" by Petar Djukic on August 11 at noon ET (9:00AM PT, 4:00PM GMT).
RSVP on the meetup page - meetup.com/machine-learning-…
Followed up on my blog post from 6 years ago to include CI/CD principles for 2026 based on the state of supply chain #security: worklifenotes.com/2026/06/18…
CycloneDX just released updated AI/ML-BOM Guide with EU AI Act compliance part - linkedin.com/feed/update/urn… #AIBOM #MLBOM #CycloneDX #SBOM
Running an AI agent 🤖 fully autonomously — and not worrying about it. I recorded a demo of how ReARM makes that possible. youtube.com/watch?v=kzMzQK51…
#DevSecOps #SoftwareSupplyChain #AIagents #SBOM #SupplyChainSecurity
🤖 AI agents are writing your code — can you tell which commits are theirs & govern what they ship?
🛡️ ReARM 26.06.5: agentic coding guardrails. Human-vs-agent commit signing + policies that block at session/PR/release.
👉 rearmhq.com/news/2026-06-01-…
#AIAgents #DevSecOps #DevOps
🚀 ReARM 26.05.108 is out! A focused follow-up to last week's major 26.05.90 release.
What's in it:
🔹 Programmatic VEX import
🔹 Memory optimizations
🔹 ReARM CE docker-compose fixes
rearmhq.com/news/2026-05-19-…
#SupplyChainSecurity #VEX #SBOM #DevSecOps #ReARM
🚀 ReARM 26.05.90 is out. One of our biggest releases yet!
🔀 Pull Requests as a first-class entity
🔁 VEX export & import
👉 Release news: rearmhq.com/news/2026-05-13-…
#ReARM #SBOM #VEX #SupplyChainSecurity #DevSecOps #ReleaseGovernance
The #Agentic Era is here! 🤖 🤖 🤖
Pavel Shukhman pitching ReARM at #Cybersecurity & Identity Summit Ottawa 2026 youtube.com/watch?v=e1kZY9qs…
New ReARM release: 26.04.90 🎉
Visual CEL policy builder · TEA 0.4.0 with per-release CLE · Download Audit Logs · Branch Suffix Mode · Reverse Feature Set Lookup · Most Recent Releases widget.
Read news release 👇
rearmhq.com/news/2026-04-20-…
Shared my thoughts on #QA and #CyberSecurity in the #AI era at OnPod podcast youtube.com/watch?v=4K2p7eXA…
Pavel Shukhman retweeted
Today, we're launching CycloneDX Assessors Studio (alpha). Built for maturity tracking, compliance audits, and supply chain vendor trust. Turn compliance checklists into verifiable attestations.
#CycloneDX #OWASP #Compliance #GRC #OpenSource
assessors.studio/
It is no longer possible to apply a human-scale control model to an agent-scale development world. I put together my thoughts on the principles of release management in the #agentic era - medium.com/@taleodor/release…
Time to Start Treating Dev Machines as Untrusted #CyberSecurity #SupplyChainSecurity #YubiKey
worklifenotes.com/2026/03/31…
🚨 🚨 🚨 Following the recent Trivy and LiteLLM compromises, it has become clear that we still lack a good way to protect our CI/CD layer 🧨
rearmhq.com/blog/2026-03-29-…
#SupplyChainSecurity #CICD #CyberSecurity