<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Baruch Sadogursky on foojay.io - Friends of OpenJDK</title><link>https://foojayio.github.io/website/today/author/jbaruch/</link><description>Articles written by Baruch Sadogursky on foojay.io - Friends of OpenJDK</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Mon, 02 Jun 2025 13:55:37 +0000</lastBuildDate><atom:link href="https://foojayio.github.io/website/today/author/jbaruch/index.xml" rel="self" type="application/rss+xml"/><item><title>Foojay Podcast #72: JCon Report, Part 1 - Grow your career, public speaking, 30 years of Java, greener coding,...</title><link>https://foojayio.github.io/website/today/foojay-podcast-72/</link><pubDate>Mon, 02 Jun 2025 13:55:37 +0000</pubDate><guid>https://foojayio.github.io/website/today/foojay-podcast-72/</guid><description>&lt;p&gt;On May 13th and 14th, Foojay attended the JCON conference in Köln, Germany, where we did over 30 live-stream interviews. In this episode, we present to you the first set of these interviews, in which we focus on celebrating 30 years of Java, how you can grow your career, become a public speaker and writer, make your code more green, a bit of AI (of course&amp;hellip;), and how the connections between open-source contributors can be visualized.&lt;/p&gt;</description></item><item><title>Foojay Podcast #59: DevRel Explained!</title><link>https://foojayio.github.io/website/today/foojay-podcast-59/</link><pubDate>Mon, 21 Oct 2024 10:42:21 +0000</pubDate><guid>https://foojayio.github.io/website/today/foojay-podcast-59/</guid><description>&lt;p&gt;&lt;strong&gt;What do people who have Developer Relations as their job description do? And how do you become a conference speaker? You&amp;rsquo;ll learn in this Foojay podcast!&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;At Devoxx in Belgium, I got to talk to Josh Long, Baruch, Pratik Patel, and Roni Dover, who were on the stage because it was part of their job. They shared many tips about being a DevRel and the many tasks involved in such a job.&lt;/p&gt;</description></item><item><title>Namespace Shadowing (a.k.a. “Dependency Confusion”) Attack</title><link>https://foojayio.github.io/website/today/namespace-shadowing-a-k-a-dependency-confusion-attack/</link><pubDate>Thu, 22 Apr 2021 06:31:08 +0000</pubDate><guid>https://foojayio.github.io/website/today/namespace-shadowing-a-k-a-dependency-confusion-attack/</guid><description>&lt;h3 id="h3-0-tl-dr-yet-another-case-for-using-exclude-patterns-in-remote-repositories"&gt;TL;DR: Yet Another Case for Using Exclude Patterns in Remote Repositories&lt;/h3&gt;
&lt;p&gt;The npm Registry is vulnerable to supply chain namespace shadowing, also known as &amp;ldquo;Dependency Confusion&amp;rdquo; attacks. Make sure you create npm scoped packages and force exclude patterns.&lt;/p&gt;
&lt;h3 id="h3-1-long-time-obsession-with-exclude-patterns"&gt;Long-time Obsession with Exclude Patterns&lt;/h3&gt;
&lt;p&gt;I remember the first JFrog customer training I delivered in February 2012. This slide was the one where I explained the importance of setting exclude patterns on your repositories (you can see it is 2012 by the slide design, right? Also, Ant was a thing.):&lt;/p&gt;</description></item></channel></rss>