user avatar
Grey Baker
@greybaker
Visiting Partner at @ycombinator. Previously co-founder of @pincitesai (acq. by @filevine) and @dependabot (acq. by @github). Employee #3 at @gocardless.
San Francisco
Joined March 2012
Posts
  • user avatar
    So excited to finally announce this! If you thought what we did at @dependabot was cool, just wait until you see what we can do at GitHub! 🚀
    We’re delighted to welcome Dependabot to GitHub! 🎉 Dependabot is joining to help keep your projects secure and up-to-date. #GitHubSatellite
  • user avatar
    Rust is the fastest growing language on GitHub - about time we added support for Dependabot alerts to it 🦀
  • user avatar
    Replying to @soumithchintala and @github
    Sorry, this is my fault, and we're rolling that change back. Thanks for reporting it. We made the change yesterday to make GitHub's squash and merge consistent with `git merge --squash`. However, it broke important workflows in ways I should have foreseen.
  • user avatar
    Replying to @QuinnyPig @awscloud and @github
    I work with the secret scanning team here at GitHub. We don't tell you about leaks ourselves - we send them to AWS, who then take action. If you let me know the repo I can hunt down exactly what happened here - [email protected]
  • user avatar
    Is this the greatest @newsycombinator comment ever?
  • user avatar
    2.5 hours left to apply for the winter batch. The upside is huge. The downside is tiny. What are you waiting for?
    Five minutes before the deadline, @itsCathyDi applied to YC with @dedaluslabs. Months later, she's now running a company that's just raised $11M. The deadline to apply for the winter batch is tonight at 8pm PT - there's still time to get your app in: ycombinator.com/apply
    00:00
  • user avatar
    Two important security ships from GitHub today: the GitHub Advisory Database now supports Rust, and npm access tokens now have an easy-to-identify format. Both are a sign of things to come 1/n
  • user avatar
    I’m at GitHub Universe - DM me if you’re here and want to talk about security
  • user avatar
    .@dependabot hit $2,000 a month today. Nice reminder to keep going through the tough times when you have a product you believe in.
    Results of our big launch today are in... 1 signup. 🤦‍♂️
  • user avatar
    Good news for people who love bad news: you can now augment the GitHub dependency graph with scans you run yourself (e.g., at build time) and get Dependabot alerts for dependencies we couldn't previously detect (1/n)
  • user avatar
    The GitHub Advisory Database is now available as an open source repository and accepts contributions, both via a UI and as pull requests. It's a big deal both because the GitHub Advisory Database is important and because it shows the direction we're going. 1/n
    GitHub's database of security advisories is now open-source and available for community contributions! I'm so grateful to the team, who have been working on this since before I came to @github. Another step forward in reimagining the security industry. github.blog/2022-02-22-git…
  • user avatar
    This was one of the projects I was proudest we were able to work on at GitHub. It's just a first step - real impact in the npm ecosystem requires making it easy for all packages to adopt - but it's a step in the right direction for supply chain security.
    starting today, developers building npm projects on @GitHub Actions can request a provenance statement to be published alongside their package, giving consumers a verifiable way to link a package back to its source repository and build instructions. github.blog/2023-04-19-int…
  • user avatar
    Backstage at #GitHubSatellite. Can’t wait to show you what we’ve been working on! githubsatellite.com
  • user avatar
    Best headline from yesterday’s GitHub Satellite press? I’m biased 🤖 theregister.co.uk/2019/05/23/git…