Christopher Guindon
Director, Software Development · Eclipse Foundation
Open source ecosystems, developer platforms, and the systems that enable global software collaboration.
Posts tagged “Open Source Security”
9 posts
6 min readGetting started with AI-assisted development in the Eclipse Foundation Software Development team
How the Eclipse Foundation Software Development team is introducing AI-assisted development with careful guardrails and controlled experimentation.
5 min readStrengthening supply-chain security in Open VSX
Open VSX Registry adds pre-publish security checks to protect the extension supply chain and strengthen developer trust.
2 min readImproving ECA Renewals with Automated Notifications
Starting June 11, 2025, the Eclipse Foundation will send automated email reminders before a standalone Eclipse Contributor Agreement (ECA) expires.
2 min readSecurity Incident Review: API Endpoint Exposure on accounts.eclipse.org
An API endpoint on accounts.eclipse.org exposed some user fields in late March 2025. The endpoint has been disabled and field permissions hardened.
3 min readPolicy Update: Eclipse Foundation Hosted Services Privacy and Acceptable Usage Policy
Updated Eclipse Foundation privacy and usage policy with clearer Service Operator guidelines, enhanced security, and analytics support.
3 min readMigrating to Google Analytics 4: Recommendations for Eclipse Project Websites
With Universal Analytics ending July 1, 2023, Eclipse projects should remove Google Analytics if no longer needed or migrate manually to GA4.
1 min readECA Validation Update for Gerrit
A new Gerrit ECA validation plugin moves validation logic to the REST-based ECA Validation API, reducing contributor validation errors.
2 min readEclipse Foundation Contributor Validation Service
A new Eclipse ECA Validation GitHub App ensures every contributor is covered by required legal agreements, with better feedback and a revalidation button.
2 min readEclipse Foundation Hosted Services Privacy and Acceptable Usage Policy
The Eclipse Foundation published a Hosted Services Privacy and Acceptable Usage Policy to ensure GDPR compliance for projects and hosted services.