Memory Safety and the Future of Vulnerabilities
How wider adoption of memory-safe languages may reshape the vulnerability landscape and make other classes of weaknesses more important.

I’m a Principal Engineer at MITRE working on software security, vulnerability management, and open source. I lead Hipcheck, which helps maintainers and users assess dependency supply-chain risk via plugin-based analyses.
I also work on the CVE system, improving authz / authn, introducing support for Package URLs in CVE Records, and enhancing the processes of the Quality Working Group.
I previously served on the OmniBOR Core Team, including leading creation of the Rust library and omnibor CLI.
I want the people who build and maintain software to be able to make informed decisions about what they depend on. That is why I founded Hipcheck and led its redesign as an extensible supply-chain analysis tool.
I am drawn to work at the intersection of technical standards, public policy, and open source communities. I have advised federal software policy on SBOMs and open source security, and through OmniBOR, I worked on better ways to handle software identity.
Memory safety matters to me because it makes software safer by default. In “Memory Safety for Skeptics”, published in ACM Queue and Communications of the ACM, I make the case for pursuing it amid competing priorities. I have taught Rust at MITRE and programming language theory at CSUSB, spoken at RustConf and Rust Belt Rust, contributed to the official Rust documentation and Rustonomicon, and edited a book on Rust procedural macros.
How wider adoption of memory-safe languages may reshape the vulnerability landscape and make other classes of weaknesses more important.
A panel on software identity in vulnerability management, covering CPE, pURL, OmniBOR, and the role of software identifiers in CVE Records.
Lessons from teaching Rust to 26 undergraduates, including how newcomers understood its key concepts and what their experience suggests about teaching Rust well.
An examination of documentation quality in the Rust ecosystem, with practical ways maintainers and contributors can make crate documentation more discoverable, complete, and welcoming.
@alilleybrinker.com
Follow Andrew’s writing and conversations on Bluesky.
Loading Bluesky profile.
@alilleybrinker
Explore Andrew’s open-source software and projects on GitHub.
Loading GitHub profile.
Message me on Bluesky for my Signal username to chat.
You can also find me on Mastodon, LinkedIn, Hacker News, Lobste.rs, and Reddit.
The words on this site were written by Andrew with care. Its design was implemented with the aid of AI. If AI-generated content is ever posted, it will be clearly identified.