Log inSign up
Dan Lorenc
13.2K posts
user avatar
Dan Lorenc
@lorenc_dan
OSS Supply Chain Security. Founder/CEO/Primary Ariba Admin at chainguard.dev Sigstore: sigstore.dev
The Arena
dlorenc.medium.com
Joined May 2014
1,976
Following
11.2K
Followers
  • Pinned
    user avatar
    Dan Lorenc
    @lorenc_dan
    Nov 1, 2023
    Big week for @chainguard_dev!
    Image with text "Chainguard" and octopus logo on dark purple gradient background.
    Chainguard raises $61 million series B round as enterprises move to fortify open source software
    From chainguard.dev
    54K
  • user avatar
    Dan Lorenc
    @lorenc_dan
    Mar 23, 2023
    Too soon?
    361K
  • user avatar
    Dan Lorenc
    @lorenc_dan
    Nov 26, 2023
    Your CTO showing the team he can still "get his hands dirty" and debug a production issue.
    user avatar
    Historic Vids
    00:00
    user avatar
    Historic Vids
    385K
  • user avatar
    Dan Lorenc
    @lorenc_dan
    Jun 15, 2023
    I'm so mad about this.
    user avatar
    9to5Google
    9to5Mac
    @9to5Google
    Jun 15, 2023
    Google Domains shutting down, assets sold and being migrated to Squarespace 9to5google.com/2023/06/15/goo… by @technacity
    336K
  • user avatar
    Dan Lorenc
    @lorenc_dan
    Nov 5, 2025
    Google literally runs a program to pay people to fix bugs in critical OSS projects. Ffmpeg is explicitly in scope. Anyone can just send a fix and fill out a form and get paid. github.com/google/bughunt… This is all so dumb.
    250K
  • user avatar
    Dan Lorenc
    @lorenc_dan
    Apr 30, 2023
    if you’re not rolling your own compiler I don’t trust you compilers have to be one of the most easy things to implement and they're such a core component to any service. Own your compiler.
    226K
  • user avatar
    Dan Lorenc
    @lorenc_dan
    Dec 24, 2019
    Instead of SemVer, I propose RealVer It has three parts, referred to as X.Y.Z. X: Name/number marketing decided. Y: Number of releases since leadership decided we needed a refresh and new name. Z: Number of times we screwed up the last release.
  • user avatar
    Dan Lorenc
    @lorenc_dan
    Apr 21, 2021
    Is there a word for when you make a piece of software that probably isn't really ready for production use, then forget about it, then someone comes along and builds a critical production system on top of it without asking?
  • user avatar
    Dan Lorenc
    @lorenc_dan
    Nov 17, 2022
    Replying to @d_feldman
    Think bigger! There's gotta be someone that took two faang jobs simultaneously and now has two severance packages.
  • user avatar
    Dan Lorenc
    @lorenc_dan
    Oct 12, 2022
    The core problem is that k8s allows us to treat containers as cattle, but images are still treated as pets. "Mom, I want this new image!" "Who's gonna take care of it?" "Me!" "You're gonna feed it and walk it and scan it for CVEs?" "Uh huh!" "Even when it's raining?" "Sure..."
  • user avatar
    Dan Lorenc
    @lorenc_dan
    Nov 5, 2025
    Fun fact: at one point Google had an entire team building a new sandboxing technology just so they could run ffmpeg safely. Later it ended up being used in App Engine and other environments.
    43K
  • user avatar
    Dan Lorenc
    @lorenc_dan
    Jun 13, 2023
    Engineer's hierarchy of needs
    75K
  • user avatar
    Dan Lorenc
    @lorenc_dan
    Dec 12, 2021
    Funding OSS is a hot topic today! I got to spend a lot of time over the last two years working on paying OSS maintainers at @Google. We spent a few million dollars and funded some relatively high profile work, in addition to a lot of smaller projects. A 🧵on problems I saw!
  • user avatar
    Dan Lorenc
    @lorenc_dan
    Aug 20, 2022
    HAVE YOU HEARD OF NIX? ITS A PURELY FUNCTIONAL DECLARATIVE REPRODUCIBLE PACKAGE MANAGER. ALL UPDATES ARE ATOMIC AND YOU JUST HAVE TO LEARN HOW TO OPERATE THE CLI WHICH IS KIND OF LIKE GIT EXCEPT THE HARD PARTS. IT HAS A CUSTOM LISP DIALECT TOO I CANT BELIEVE YOU HAVENT TRIED IT!

New to X?

Sign up now to get your own personalized timeline!

Create account

By signing up, you agree to the Terms of Service and Privacy Policy, including Cookie Use.

Terms of Service|Privacy Policy|Cookie Policy|Accessibility|Ads info|© 2026 X Corp.
Don't miss what's happening
People on X are the first to know.
Log inSign up