Jonatan Männchen
@maennchen.dev
📤 103
📥 66
📝 24
CISO & Member Security WG
@theerlef.bsky.social
| he/him
reposted by
Jonatan Männchen
Erlang Ecosystem Foundation
about 9 hours ago
What if the BEAM got hit by a worm? 🪱 We’ve been lucky so far — but luck runs out. The Ægis Initiative is how we defend our ecosystem. 👉 Read more & support:
erlef.org/blog/eef/bea...
#Erlang
#Elixirlag
#Gleam
0
3
4
One package. One update. A worm crawling through the BEAM ecosystem. A dark “what if” — and how we can stop it before it’s real.
erlef.org/blog/securit...
#erlang
#elixirlang
1 day ago
0
7
2
reposted by
Jonatan Männchen
LostKobrakai
11 days ago
There‘s still a bit to go to making this happen. Rebar is an important piece to using erlang not just for erlang, but just as much for elixir, gleam, … Consider backing this effort.
add a skeleton here at some point
1
13
9
reposted by
Jonatan Männchen
Zach Daniel
12 days ago
@maennchen.dev
has just released the first version of Clarity:
hexdocs.pm/clarity/Clar...
Clarity is an interactive introspection and visualization tool for Elixir projects.
2
36
10
reposted by
Jonatan Männchen
Maggie Tate
13 days ago
Cool!!!
@maennchen.dev
introduces Clarity!
@ash-hq.org
#elixirlang
1
8
2
reposted by
Jonatan Männchen
Petter Boström
13 days ago
The first part of the last afternoon gave us insights on how to handle a security disaster, converting from old code to new and our host
@lawik.bsky.social
showed us thousands of VMs running on the same machine.
#goatmire
#elixir
0
6
3
reposted by
Jonatan Männchen
Erlang Ecosystem Foundation
17 days ago
Proud to back the Rebar4 Kickstarter — moving the BEAM ecosystem forward with the community. 🙌
add a skeleton here at some point
0
6
4
reposted by
Jonatan Männchen
Zach Daniel
19 days ago
Hey folks, we have a CVE for
#AshFramework
. `before_transaction` hooks will execute in certain scenarios (bulk action calls) even if the action is forbidden by policies. Please update Ash core to 3.5.39. For more see:
github.com/ash-project/...
#AshFramework
#ElixirLang
loading . . .
Before action hooks may execute in certain scenarios despite a request being forbidden
### Summary Certain bulk action calls with a `before_transaction` hook and no `after_transaction` hook, will call the `before_transaction` hook before authorization is checked and a Forbidden erro...
https://github.com/ash-project/ash/security/advisories/GHSA-jj4j-x5ww-cwh9
0
18
4
reposted by
Jonatan Männchen
Louis Pilfold
22 days ago
Stretch goal 2 (inclusion in Erlang/OTP itself) would solve the #1 thing people get stuck on when trying to get started with Gleam or Erlang!
www.kickstarter.com/projects/pee...
loading . . .
From Rebar3 to Rebar4: Integrating with Erlang/OTP
Building on top of Rebar3 to Fully Integrate with Erlang/OTP for All BEAM Languages, creating Rebar4 the next generation build tool.
https://www.kickstarter.com/projects/peerstritzinger/rebar3-integrating-with-erlang-otp
0
22
7
I just backed From Rebar3 to Rebar4: Integrating with Erlang/OTP on
@kickstarter.com
www.kickstarter.com/projects/pee...
#elixir
loading . . .
From Rebar3 to Rebar4: Integrating with Erlang/OTP
Building on top of Rebar3 to Fully Integrate with Erlang/OTP for All BEAM Languages, creating Rebar4 the next generation build tool.
https://www.kickstarter.com/projects/peerstritzinger/rebar3-integrating-with-erlang-otp?ref=thanks-tweet
22 days ago
0
3
0
reposted by
Jonatan Männchen
ElixirConf
27 days ago
Community growth needs collective action Roadmap for outreach and engagement @danj3.bsky.social on taking responsibility for Elixir's future through community championship.
#ElixirConfUS
0
2
1
reposted by
Jonatan Männchen
ElixirConf
27 days ago
Security incident response: from panic to patch CVEs, Hex retirement, vulnerability scanners @maennchen.devshows how to handle security disasters with transparency and leadership.
0
2
1
reposted by
Jonatan Männchen
Maggie Tate
28 days ago
Had a great chat with
@zachdaniel.dev
and
@maennchen.dev
during a break at
@elixirconf.bsky.social
about the Erlang Ecosystem Foundation and its role in security.
#elixirlang
loading . . .
1
9
3
reposted by
Jonatan Männchen
Code BEAM
about 1 month ago
🚀 6 must-see talks at CodeBEAM Europe 2025: Gleam careers, workflow orchestration, VPP with Elixir, security disasters, BEAM+Rust combo, and taming 20M Oban jobs! Featuring
@ihh.dev
@maennchen.dev
codebeameurope.com#register
0
9
3
reposted by
Jonatan Männchen
Erlang Ecosystem Foundation
about 2 months ago
👉🏽 "From Freakout to Fix: Navigating a Security Disaster" Our Foundation's CISO -
@maennchen.dev
- will be speaking at
@elixirconf.bsky.social
on how to handle serious security holes — without melting down. 📢 Don’t miss it:
elixirconf.com/talks/from-f...
#ElixirLang
#Security
#BEAM
0
5
3
reposted by
Jonatan Männchen
Erlang Ecosystem Foundation
about 2 months ago
🎙️
@maennchen.dev
joins the latest
@openssf.org
podcast! In this SOSS episode, he shares how the Erlang community is proactively addressing security concerns, why manufacturers are investing in upstream projects — and what other ecosystems can learn from their approach. Listen!
shorturl.at/iKdG7
0
3
2
reposted by
Jonatan Männchen
OpenSSF
3 months ago
🎉 Today we celebrate
#OpenSSFCommunity
Day NA 2025, welcoming six new member organizations and honoring incredible contributors with the Golden Egg Awards 🥚. Read the full update: 🌐
openssf.org/blog/2025/06...
#OpenSSF
#OpenSource
#SoftwareSecurity
#OSS
0
7
3
reposted by
Jonatan Männchen
Erlang Ecosystem Foundation
3 months ago
🙌 Welcome to another
#GettingToKnowUs
edition! This time we got to meet
@maennchen.dev
a seasoned developer and lead engineer, with contributions to projects like the certified
#OpenID
Connect client for the
#BEAM
. He is currently the CISO of our Foundation. 🔗
erlef.org/blog/marketi...
1
5
3
reposted by
Jonatan Männchen
Louis Pilfold
3 months ago
Watch out folks, there's a CVE for the Erlang zip module. Update to the latest patch release when you can
cna.erlef.org/cves/cve-202...
loading . . .
Absolute path traversal in zip:unzip/1,2
This project handles the CVE Numbering Authority (CNA) for the Erlang Ecosystem Foundation (EEF).
https://cna.erlef.org/cves/cve-2025-4748.html
0
23
14
reposted by
Jonatan Männchen
Erlang Solutions
3 months ago
In part two of our talk with
@maennchen.dev
(CISO at
@theerlef.bsky.social
), we dive into the real security challenges BEAM developers face. From CVE tracking to practical tips for open source teams, this is about building safer systems from the start, not patching them too late. 🎥
bit.ly/45WjT3y
loading . . .
Security and the BEAM Ecosystem - Erlang Solutions
In the second and final part, Jonatan Männchen on how the BEAM community is making security smarter and more collaborative.
https://bit.ly/45WjT3y
0
3
2
reposted by
Jonatan Männchen
Erlang Solutions
4 months ago
Security is most effective when it is built in from day one. In part one of our latest webinars with
@maennchen.dev
, CISO
@theerlef.bsky.social
, he shares his experience using SAFE, our security audit service for Erlang and Elixir systems. 🔒
loading . . .
SAFE and OIDCC - Erlang Solutions
Even secure code benefits from a second opinion. In part one, Jonatan Männchen shares how SAFE helped strengthen his authentication library.
https://bit.ly/4l1D5Bp
1
4
2
reposted by
Jonatan Männchen
Zach Daniel
4 months ago
Elixir 1.19 is a banger! Honestly I'm so pleased with the direction that
#ElixirLang
is going. My programs just get faster and more correct every time. I just know that we're in good hands. Thank you to everyone on the team for your hard work!
github.com/elixir-lang/...
loading . . .
Release v1.19.0-rc.0 · elixir-lang/elixir
Type system improvements Type checking of protocol dispatch and implementations This release also adds type checking when dispatching and implementing protocols. For example, string interpolation i...
https://github.com/elixir-lang/elixir/releases/tag/v1.19.0-rc.0
2
113
24
reposted by
Jonatan Männchen
Erlang Ecosystem Foundation
4 months ago
🔐Security and the BEAM Ecosystem In this insightful session organized by
@erlangsolutions.bsky.social
,
@maennchen.dev
— CISO at our Foundation —shares how the BEAM community is stepping up its open source security efforts, including becoming an official CNA
www.erlang-solutions.com/webinars/sec...
loading . . .
Security and the BEAM Ecosystem - Erlang Solutions
Jonatan Männchen shares how the BEAM community is improving security through better tracking, smarter tooling and shared responsibility.
https://www.erlang-solutions.com/webinars/security-and-the-beam-ecosystem/
0
4
3
reposted by
Jonatan Männchen
Zach Daniel
4 months ago
Did the required work this morning to get
#AshFramework
passing the OpenSSF Best Practices certification, and to get our OpenSSF Scorecard. Thanks again to
@maennchen.dev
from
@theerlef.bsky.social
for his expert council and advice. See the scorecard here:
scorecard.dev/viewer/?uri=...
#ElixirLang
0
18
2
reposted by
Jonatan Männchen
Erlang Ecosystem Foundation
4 months ago
🎥 What’s new at the EEF? Alistair Woodman,
@maennchen.dev
& Dan Janowski share big updates: 🔐 We’ve joined the CVE® Program as an official CNA 🛡️ Launched the Ægis Initiative to boost security Must-watch for the BEAM community! ▶
youtu.be/5WqMpSt_rRE
loading . . .
LT: EEF Update - Alistair Woodman, Jonatan Männchen, Dan Janowski | ElixirConf EU 2025
YouTube video by Code Sync
https://youtu.be/5WqMpSt_rRE
0
4
2
reposted by
Jonatan Männchen
Lars Wikman
4 months ago
Not an Ash talk. Not an Igniter talk. Is easy to couple Zach Daniel to his massive efforts in the Ash framework but ever since I met him the phrase "Elixir ride or die" live rent-free in my head. I must not say much about the talk itself. You need to see it.
goatmire.com/speaker/zach...
#elixirlang
loading . . .
A Letter From Ourselves by Zach Daniel - Goatmire Elixir
Elixir has a storied past—but what does its future hold? In this session, we won’t be unveiling new features or delivering a roadmap. And yet, somehow, the future makes an appearance. Expect familiar…
https://goatmire.com/speaker/zach-daniel
0
12
3
reposted by
Jonatan Männchen
Lars Wikman
4 months ago
Serious monday for a serious topic. Navigating security problems doesn't have to be all dread and cold sweat. Jonatan Männchen is the CISO of the Erlang Ecosystem Foundation. He will take you on the journey in his talk to get you ready.
goatmire.com/speaker/jona...
#elixirlang
loading . . .
From Freakout to Fix: Navigating a Security Disaster by Jonatan Männchen - Goatmire Elixir
Picture this: you’re chugging coffee late at night when you realize your beloved library has a massive security hole. Worse yet, someone’s already posted a proof-of-concept exploit for the world to…
https://goatmire.com/speaker/jonatan-mannchen
0
4
2
reposted by
Jonatan Männchen
Erlang Ecosystem Foundation
4 months ago
✨Thanks to everyone who joined our talk at
@elixirconf.bsky.social
! We loved sharing everything we’ve been working on — from the Foundation to the community. Big shoutout to all the amazing speakers for the inspiring lightning talks, and to everyone who made this event so special!
#Elixirlang
0
8
3
reposted by
Jonatan Männchen
Zach Daniel
4 months ago
#ElixirLang
❤️
@theerlef.bsky.social
I firmly believe the EEF will play an ever increasing role in the success of the Elixir ecosystem, and I intend to do my part to support them in this effort. Our community is growing and the need for coordination on things that impact us all grows alongside it. 👇
add a skeleton here at some point
4
37
6
reposted by
Jonatan Männchen
Erlang Ecosystem Foundation
4 months ago
The EEF board 2025 Election Vote is over! 🗳 Cohort C contains the following new three members:
@lawik.bsky.social
, Lee Barney,
@zachdaniel.dev
👏 We’re thankful for everyone who decided to get involved by running, and those who made their voices heard by voting.
erlef.org/blog/eef/ele...
5
41
17
reposted by
Jonatan Männchen
Common Vulnerabilities and Exposures (CVE™) Program
5 months ago
Erlang Ecosystem Foundation is now a CVE Numbering Authority (CNA) assigning CVE IDs for vulnerabilities in active packages on
Hex.pm
+ projects on GitHub under elixir-lang, erlang, erlef-cna, erlef, gleam-lang, & hexpm, unless covered by the scope of another CNA
cve.org/Media/News/i...
0
13
8
reposted by
Jonatan Männchen
Erlang Ecosystem Foundation
4 months ago
🚨We’ve officially joined the CVE® Program as an authorized CVE Numbering Authority! 🔐 This means we can now assign CVE IDs to publicly disclosed cybersecurity vulnerabilities in our defined scope, helping improve security and transparency in the broader open-source community
shorturl.at/0bOxC
1
21
9
reposted by
Jonatan Männchen
Zach Daniel
5 months ago
📢 New API Key strategy for
@ash-hq.org
merged 🎉.
github.com/team-alembic...
Massive shoutout (once again) to
@maennchen.dev
at
@theerlef.bsky.social
for his invaluable guidance on implementing this securely.
#AshFramework
#ElixirLang
0
33
7
reposted by
Jonatan Männchen
Erlang Ecosystem Foundation
5 months ago
💫Just released: a GitHub Action to submit Elixir/Mix dependencies via GitHub's Dependency Submission API. ✅ Perfect for unlocking security alerts, dependency graphs, and Dependabot Security updates! Check it out:
github.com/erlef/mix-de...
#Elixirlang
loading . . .
GitHub - erlef/mix-dependency-submission: Calculates dependencies for Mix and submits the list to the GitHub Dependency Submission API
Calculates dependencies for Mix and submits the list to the GitHub Dependency Submission API - erlef/mix-dependency-submission
https://github.com/erlef/mix-dependency-submission
0
10
3
reposted by
Jonatan Männchen
Erlang Ecosystem Foundation
5 months ago
📢Why did we launch the Ægis Initiative? Because we believe a safer BEAM ecosystem benefits us all 🔒Elevate ecosystem-wide security ✅Streamline compliance readiness 🤝Foster trust and transparency 🌍Democratize access to advanced security 🚀Enable secure publishing workflows
security.erlef.org/aegis/
0
5
1
reposted by
Jonatan Männchen
Tib3rius
5 months ago
BREAKING. From a reliable source. MITRE support for the CVE program is due to expire tomorrow. The attached letter was sent out to CVE Board Members.
37
688
623
reposted by
Jonatan Männchen
Zach Daniel
5 months ago
Hey folks, we have a minor CVE issued for AshAuthentication. Please read the CVE and update accordingly. Relatively low severity, can't compromise a users data, but there is an opportunity for a user to be "confirmed" for an email they do not have access to.
github.com/team-alembic...
loading . . .
Email link auto-click account confirmation vulnerability
### Impact The confirmation flow for account creation currently uses a GET request triggered by clicking a link sent via email. Some email clients and security tools (e.g., Outlook, virus scanne...
https://github.com/team-alembic/ash_authentication/security/advisories/GHSA-3988-q8q7-p787
2
17
5
reposted by
Jonatan Männchen
Erlang Ecosystem Foundation
5 months ago
🔐 Big news from the
#Gleam
community! The EEF Security Working Group helped
@gleam.run
include Build SBoMs and SLSA build provenance for all release artifacts and Docker images. This means greater visibility into dependencies and stronger software supply chain security💪
github.com/gleam-lang/g...
1
25
5
reposted by
Jonatan Männchen
Erlang Ecosystem Foundation
6 months ago
💜Join the Erlang Ecosystem Foundation! 🙌 Be part of a global community! Whether you're looking to connect, contribute, or stay informed, there’s a membership level for you! 👉Learn more:
members.erlef.org/join-us
#Erlang
#Elixirlang
#Gleam
0
8
2
reposted by
Jonatan Männchen
Erlang Ecosystem Foundation
6 months ago
👉Why join the
@erlangworkshop.bsky.social
? A while ago, we talked with Kiko Fernández Reyes from the program committee. If you work in industry, are an academic, or want to participate, listen to why this event matters! 💥
youtu.be/lSm8-jA-gsM?...
#Erlang
#MyElixirStatus
#Gleam
loading . . .
KIKO FERNÁNDEZ REYES 🎙️ | 🌐 Getting to Know Us
YouTube video by Erlang Ecosystem Foundation
https://youtu.be/lSm8-jA-gsM?t=590
0
5
2
reposted by
Jonatan Männchen
Erlang Ecosystem Foundation
6 months ago
🔒Big news! The EEF Security WG has launched the Supply Chain Security & Compliance Initiative! This initiative is focused on enhancing security and compliance across the BEAM ecosystem. All work is guided and reviewed by the WG and the EEF CISO
security.erlef.org/aegis/
#Erlang
#Elixirlang
#Gleam
loading . . .
Ægis Initiative
Supply Chain Security & Compliance Initiative
https://security.erlef.org/aegis/
0
4
3
reposted by
Jonatan Männchen
Erlang Ecosystem Foundation
6 months ago
🎧Alistair and
@maennchen.dev
joined the
@thinkingelixir.com
Podcast to dive into supply-chain security, SBoMs, and Jonatan’s role as the Foundation’s Chief Information Security Officer. What does this mean for the community?
youtu.be/jYkV9n4WW-Y?...
#WeBeamTogether
#Elixirlang
loading . . .
Thinking Elixir Podcast 245: Supply Chain Security and SBoMs
YouTube video by Mark Ericksen
https://youtu.be/jYkV9n4WW-Y?t=1907
0
6
2
reposted by
Jonatan Männchen
ThinkingElixir
6 months ago
News includes phoenix_sync for real-time Postgres sync, a new Text Parser library, plus our interview with the EEF's CISO about supply-chain security, SBoMs, and what this means for the Elixir community, and much more!
#ElixirLang
www.youtube.com/watch?v=jYkV...
loading . . .
Thinking Elixir Podcast 245: Supply Chain Security and SBoMs
YouTube video by Mark Ericksen
https://www.youtube.com/watch?v=jYkV9n4WW-Y
0
15
9
reposted by
Jonatan Männchen
Josh Price
7 months ago
@zachdaniel.dev
showing us Igniter — composable code generators that are additive and not based on opting out of the kitchen sink
#elixirlang
0
19
5
reposted by
Jonatan Männchen
Erlang Ecosystem Foundation
7 months ago
🔒 The Elixir project is now OpenChain (ISO/IEC 5230) certified, meeting global standards for open source license compliance! This was done in collaboration with the EEF, reinforcing our commitment to secure and compliant open source development. More details 👉
shorturl.at/UlYgZ
#Elixirlang
loading . . .
Announcing Elixir OpenChain Certification
The Elixir project now meets OpenChain (ISO/IEC 5230). Each release ships with Source SBoMs in CycloneDX 1.6 and SPDX 2.3, plus attestation.
https://shorturl.at/UlYgZ
1
13
3
Elixir now meets OpenChain (ISO/IEC 5230) standards! This milestone strengthens our commitment to open source license compliance and secure development. Get the full story and see what it means for contributors and users alike:
elixir-lang.org/blog/2025/02...
loading . . .
Announcing Elixir OpenChain Certification
The Elixir project now meets OpenChain (ISO/IEC 5230). Each release ships with Source SBoMs in CycloneDX 1.6 and SPDX 2.3, plus attestation.
https://elixir-lang.org/blog/2025/02/26/elixir-openchain-certification/
7 months ago
0
32
6
reposted by
Jonatan Männchen
AntoineDufo
9 months ago
De retour du
#38c3
Un moment toujours aussi unique et incroyable
0
1
1
reposted by
Jonatan Männchen
Philipp Garbe
9 months ago
We know where your
#Volkswagen
car is... Scary but also fascinating talk how they got and analyzed TBs of location data.
media.ccc.de/v/38c3-wir-w...
loading . . .
Wir wissen wo dein Auto steht
Bewegungsdaten von 800.000 E-Autos sowie Kontaktinformationen zu den Besitzern standen ungeschützt im Netz. Sichtbar war, wer wann zu Hau...
https://media.ccc.de/v/38c3-wir-wissen-wo-dein-auto-steht-volksdaten-von-volkswagen
0
4
1
reposted by
Jonatan Männchen
Erlang Ecosystem Foundation
9 months ago
Are you unknowingly publicly exposing Erlang distribution or RabbitMQ? Don’t worry—checking is quick and easy! 🔍 Run a port scan and verify if EPMD and Erlang Distribution are accessible. 🔒 Secure it behind a firewall or disable Erlang Distribution if it’s unnecessary.
erlef.org/blog/eef/epm...
0
4
3
Load more
feeds!
log in