Arkadii Yakovets · CCSP · CISSP · CSSLP
arkid15r.com
Arkadii Yakovets · CCSP · CISSP · CSSLP
@arkid15r.com
Cybersecurity lead (@nest.owasp.org, @nettacker.owasp.org), #opensource contributor, home #automation and #hydroponic gardening enthusiast.

https://arkid15r.com
https://arkid15r.dev
Formal open source programs run on their own calendar, and promising contributors are often ready before the next cycle opens.

Maintainer, mentor, manager: why I fund contributors before programs do arkid15r.dev/open-source-...
Maintainer, mentor, manager: why I fund contributors before programs do
Maintainer, mentor, then manager -- and when personal sponsorship bridges the gap so strong contributors keep shipping before a formal program says yes.
arkid15r.dev
September 16, 2026 at 12:38 AM
security.txt is a tiny file with an outsized job: tell researchers where to report vulnerabilities. But it is still not as well-known as it should be. I wrote up what good-enough looks like, a shipping checklist, and patterns from live files -- arkid15r.dev/security-txt...
Not as well-known as it should be: shipping security.txt
security.txt lives at a well-known URI and costs almost nothing -- yet adoption is uneven. What good-enough looks like, live examples, and the file this site ships.
arkid15r.dev
September 7, 2026 at 5:17 PM
GSoC 2026's 12-week timeline wrapped final evaluations last month. This post reads the official projects page and Google's program announcements for scale, what is marked complete versus still active, the top organizations, and my personal top 50 completed projects.

arkid15r.dev/gsoc-2026-pr...
I know what you did last summer: GSoC 2026 top 50 projects to check out
GSoC 2026 work is mostly marked complete. A personal 50 from orgs like Apache, Debian, Django, Git, Linux Foundation, OWASP, and PSF, org volume, and a hope that 2027 still happens.
arkid15r.dev
September 6, 2026 at 1:46 AM
Reposted by Arkadii Yakovets · CCSP · CISSP · CSSLP
🎉 OWASP Nest Achieves OpenSSF Best Practices Passing Badge!

We're thrilled to announce that OWASP Nest has officially earned the OpenSSF Best Practices Passing Badge!

www.bestpractices.dev/en/projects/...
January 20, 2026 at 6:04 PM
Reposted by Arkadii Yakovets · CCSP · CISSP · CSSLP
🎉 Big news from the OWASP Nest Team! 🎉

We're thrilled to share that OWASP Nest has officially been promoted from the Incubator level to the Lab level!

www.linkedin.com/feed/update/...
October 11, 2025 at 4:57 PM
Reposted by Arkadii Yakovets · CCSP · CISSP · CSSLP
🎉We're proud to announce that 3 proposals from OWASP Nest have been accepted for GSoC 2025 🎉

- OWASP Contribution Hub Development by Raj Gupta
- OWASP Nest API and Schema Development by Abhay Mishra
- OWASP NestBot as an AI Agent/Assistant by Dishant Miyani

#GSoC #OpenSource #OWASP #OWASPNest
May 8, 2025 at 6:02 PM
Reposted by Arkadii Yakovets · CCSP · CISSP · CSSLP
🚀 GSoC 2025 is just around the corner! 🚀

GSoC 2025 contributor application period opens March 24 and we’re looking for passionate developers to help shape the future of OWASP Nest! Check out our project ideas and consider applying: owasp.org/www-communit...

#GSoC #OWASP #OpenSource
March 18, 2025 at 6:43 PM
Reposted by Arkadii Yakovets · CCSP · CISSP · CSSLP
We are proudly announcing that @[email protected] is as of today officially co-leading the @owasp.org Juice Shop project together with @bkimminich.bsky.social! 🧃🥳

👉 Read more about this in our blog post https://owasp.org/blog/2025/01/29/juice-shop-leadership.html
OWASP Juice Shop leadership changes & contributor recognition | OWASP Foundation
OWASP Juice Shop leadership changes & contributor recognition on the main website for The OWASP Foundation. OWASP is a nonprofit foundation that works to improve the security of software.
owasp.org
January 29, 2025 at 3:50 PM
Reposted by Arkadii Yakovets · CCSP · CISSP · CSSLP
Last week the Python package "Ultralytics" suffered a supply-chain attack on its build and release process. This is a review of the attack from @pypi.org's perspective.

There's plenty of advice for how Python projects can increase their #security posture:

blog.pypi.org/posts/2024-1...
Supply-chain attack analysis: Ultralytics - The Python Package Index Blog
Analysis of a package targeted by a supply-chain attack to the build and release process
blog.pypi.org
December 11, 2024 at 3:22 PM
Is it just me, or is the entire world waiting for the #npm scheduled infrastructure upgrade to be completed?
December 8, 2024 at 6:42 PM
Reposted by Arkadii Yakovets · CCSP · CISSP · CSSLP
When we discussed string interning earlier, we mentioned a concept #Go uses to implement its unique map feature: the “weak pointer”. Discover more about GoLang in the last Phuong Le post ➡️
victoriametrics.com/blog/go-weak...

#golang #go #programming #TechInsights
Weak Pointers in Go: Why They Matter Now
Through the weak package, you can create these special pointers that automatically become nil when their target memory gets collected. While they’re a bit trickier to use than regular pointers, they’r...
victoriametrics.com
December 3, 2024 at 9:29 PM
60% OFF #CKA + #CKAD + #CKS Bundle -- $438 with CYBER24BUNDLE code (expires Dec 11, 2024, 12-months to schedule & take the exam, 2 exam attempts).
training.linuxfoundation.org/training/cka... -- Certified Kubernetes Security Specialist (CKS) requires passed Certified Kubernetes Administrator (CKA).
December 2, 2024 at 4:53 PM
🌱 My ultimate goal is to bring my #hydroponics #garden back to a setup similar to this (it all started from #cilantro for tacos)!

I’m especially hopeful that the #onions and #celery will thrive this time around. And I’ve got big hopes for the 🥦 -- it’s my first time growing it! 🌱
November 24, 2024 at 9:47 PM
🌱 Speaking of my #hydroponics #garden, I dug up some photos from a couple of years ago of my very first indoor setup! I repurposed my laundry room, building the system right on top of the washer and dryer. It was a humble start, but such a rewarding journey to see it come to life! 🌱
November 24, 2024 at 9:38 PM

I just started planting #seeds for my #hydroponics garden! This time, I’m growing cilantro, parsley, #basil, dill, onions, salad bowl lettuce, broccoli, and celery. I decided to skip #sorrel for now. It’s my first time trying #broccoli, and I’m giving #lettuce, onions, and celery another shot.
November 24, 2024 at 9:26 PM
I think it’s time to revive 🌱 my #indoor #hydroponics #garden! Last month, I had to step back when the parsley and #basil fell ill, but the sorrel thrived, producing an incredible harvest of lush leaves. Sadly, #KubeCon'24 timing wasn’t kind to these green friends too 🌿 #gardening #plants
November 24, 2024 at 7:07 PM
I'm going to migrate Open World Holidays Framework (github.com/vacanza/holi...) documentation from #sphinx + #rst to #MkDocs + #Markdown. Any suggestions?

Here is my pro vs con list:
GitHub - vacanza/holidays: Open World Holidays Framework
Open World Holidays Framework. Contribute to vacanza/holidays development by creating an account on GitHub.
github.com
November 23, 2024 at 1:29 AM
How to set a website as your Bluesky username

bsky.social/about/blog/4...
How to verify your Bluesky account - Bluesky
Here's how to verify your Bluesky account by setting your website as your username.
bsky.social
November 22, 2024 at 4:02 PM
GitHub Open Source Fund accepts applications until Jan, 7th 2025: $10,000 per project, 3-week educational program, GitHub Security office hours and more. #github #security #open-source #funding
github.blog/news-insight...
Announcing GitHub Secure Open Source Fund: Help secure the open source ecosystem for everyone
Applications for the new GitHub Secure Open Source Fund are now open! Applications will be reviewed on a rolling basis until they close on January 7 at 11:59 pm PT. Programming and funding will begin ...
github.blog
November 22, 2024 at 1:04 AM
PyPI package maintainers can now publish signed digital attestations when publishing, in order to further increase trust in the supply-chain security of their projects. Additionally, a new API is available for consumers and installers to verify published attestations. blog.pypi.org/posts/2024-1...
PyPI now supports digital attestations - The Python Package Index Blog
Announcing support for PEP 740 on the Python Package Index
blog.pypi.org
November 20, 2024 at 9:57 PM
Reposted by Arkadii Yakovets · CCSP · CISSP · CSSLP
**OWASP Nettacker Update** 🚀
We're excited to share that Nettacker has applied for a project-level promotion (Incubator → Lab) within #OWASP! This step will help us:
- Boost adoption & credibility
- Attract contributors & sponsors
- Secure long-term sustainability through visibility & support
November 20, 2024 at 8:27 PM