GithubHelp home page GithubHelp logo

About me 👨‍💻

  • 😄 Pronouns: He/Him
  • 🇧🇷 I am Brazilian! Currently Living in São Paulo
  • 🎓 Graduated in Computer Engineering in University of Campinas (UNICAMP), with an exchange program to Russia 🎒
  • 💻 My favorite language is Kotlin, and I love to code using VIM
  • 🕶️ Fun facts:
    • 🐈 I'm a very proud cat dad! His name is Ravi 🥰
    • 🎮 I'm a fan of Dark Souls series and I'm enjoying my recently bought Playstation 5 😋
    • 🍷 I love wine and I'm starting to learn about them hehe
  • 🏢 I work at Google on Google Open Source Security Team (GOSST)
  • 📖 My next learning objectives are French and improving general communication/leading skills
  • 💬 I'd be more than happy to receive any contact through [email protected], Twitter or LinkedIn 😃

About GOSST 👻

Logo of GOSST team

GOSST was created as a response to the current scenario of increasing attacks on supply chain projects. The team counts with experienced open-source contributors and works alongside the Open Source Security Foundation (OpenSSF) to develop and spread solutions to make open software safer at scale. You can read more about Google initiatives on open source on this blogpost.

More specifically, I'm part of a sub-team responsible for our direct engagement with the Open Source community. We work with critical open source projects to help them increase their security, in any way we can. As a team, our goal is to:

  • Build individual analyses and approaches for each project.
  • Evaluate and suggest solutions or enhancements that would better fit the repository and not burden the maintainers.
  • Welcome and conduct discussions about our suggestion or any security solutions the maintainers prefer, as we can surely provide specific help according to their demands.
  • If possible and wanted, implement the changes ourselves via PRs to contribute with the discussed improvements.
  • Collect all kinds of feedback, as we work closely with OpenSSF and any complaints would be kindly heard.

Please read more about our acchievements on our 1-year blogpost.

Security Solutions

See below some of the tools developed by GOSST and the OpenSSF:

  • Scorecard: automated checks to evaluate a project's security practices and suggest improvements as needed
  • SLSA (pronounced "salsa"): a standard and protocol to ensure an artifact's provenance, guaranteeing it comes from the expected location and process. It prevents tampering and improves the integrity of infrastructure and consumed packages
  • Sigstore: keyless signing and verification of artifacts
  • OSS-FUZZ: automated fuzzing at scale, now fuzzing 800+ projects in 6 languages
  • OSV: a precise human - and machine - readable database of vulnerabilities that maps affected software versions across open source ecosystems
  • OSV-Scanner: A frontend for the OSV Database that connects a project’s list of dependencies with the vulnerabilities that affect them
  • GUAC: graph database of security metadata (in development)

Diogo Teles Sant'Anna's Projects

rhino icon rhino

Rhino is an open-source implementation of JavaScript written entirely in Java

scorecard icon scorecard

OpenSSF Scorecard - Security health metrics for Open Source

selenium icon selenium

A browser automation framework and ecosystem.

serve icon serve

Serve, optimize and scale PyTorch models in production

slsa icon slsa

Supply-chain Levels for Software Artifacts

spin-rs icon spin-rs

Spin-based synchronization primitives

swift-sdk icon swift-sdk

Swift SDK for Optimizely Feature Experimentation and Optimizely Full Stack (legacy)

tablesorter icon tablesorter

Github fork of Christian Bach's tablesorter plugin + awesomeness ~

testing-dependabot icon testing-dependabot

Repository created to test if dependabot or renovabot can update hash-pinned dependencies on specific scenarios

transformers icon transformers

🤗 Transformers: State-of-the-art Machine Learning for Pytorch, TensorFlow, and JAX.

tslib icon tslib

Runtime library for TypeScript helpers.

utils icon utils

Utility crates used in RustCrypto

whisper icon whisper

Robust Speech Recognition via Large-Scale Weak Supervision

xarray icon xarray

N-D labeled arrays and datasets in Python

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.