What's in the SOSS? An OpenSSF Podcast
OpenSSF
0
What's in the SOSS? is a podcast from the Open Source Security Foundation (OpenSSF) that explores the challenges and opportunities involved in making software more secure. Hosted by Christopher Robinson (CRob), it features security experts discussing trends at the intersection of AI and security, vulnerability management, and threat assessments. Each episode offers insights into the ingredients that make up secure open source software and aims to foster collaboration and stronger security practices. The show is designed for the open source software community and those interested in improving software security.
Эпизоды
-
Building the Agentic Future with Angie Jones 29.09.2026 19минIn this episode of What’s in the SOSS?, host Sally Cooper interviews Angie Jones, VP of Developer Experience at the Agentic AI Foundation (AAIF). Angie shares her career journey from software engineering and holding 27 patents at IBM to leading open source protocol and developer relations initiatives. She details the mission of the Agentic AI Foundation as a neutral home for governing open source standards and technologies such as the Model Context Protocol (MCP), Goose, Agents.md, and Google... -
Securing the Source: Navigating AI Velocity, CRA Compliance, and Dependency Debt with Abby Kearns 22.09.2026 19минIn this episode of What’s in the SOSS, host Sally Cooper sits down with technology executive and ActiveState CEO Abby Kearns to break down the rapidly evolving open source security landscape. Together, they dissect why reactive post-build scanning fails to prevent dependency debt, how machine-speed AI ingestion is overwhelming human maintainers, and what the impending EU Cyber Resilience Act (CRA) mandates mean for enterprise software supply chains. Abby offers actionable insights into why bu... -
Balancing AI's Double-Edged Sword: Software Engineering, Unlearning, and Ecosystem Sustainability with Mark Russinovich 08.09.2026 56минIn this episode of What's in the SOSS?, host CRob sits down with Mark Russinovich – CTO and Deputy CISO of Azure, as well as Board Chair for the Open Source Security Foundation (OpenSSF) – for a wide-ranging conversation on the changing landscape of software security. Mark shares insights from his journey from Sysinternals to Azure leadership, exploring how generative AI is delivering dramatic productivity boosts while creating new talent pipeline challenges for early-in-career engineers. The... -
Navigating the New Era: The EU Cyber Resilience Act Explained with Madalin Neag 01.09.2026 36минIn this episode of What’s in the SOSS, host Sally Cooper is joined by Madalin Neag, EU Policy Advisor at the OpenSSF, to demystify the European Union’s Cyber Resilience Act (CRA). As the tech industry shifts from treating open source as a free buffet to navigating a new era of regulatory liability, Madalin explains how the CRA establishes a horizontal cybersecurity baseline for digital products. The conversation explores the innovative concept of "open source software stewards," the importanc... -
Private Forks, CRA Deadlines, and the True Cost of Open Source Compliance with Dave Russo 25.08.2026 18минIn this episode of What's in the SOSS, host Sally Cooper sits down with returning champion Dave Russo, Policy and Standards Lead at Red Hat’s Open Source and AI Program Office, to unpack the European Union’s Cyber Resilience Act (CRA). Together, they explore the stark realities of the 2026 CRA Awareness and Readiness Report, exposing why three-quarters of North American tech companies remain completely unaware of the strictest cybersecurity mandate in history. Dave breaks down the hidden $250... -
Watering the Community Garden: Navigating the EU CRA for Open Source with Roman Zhukov 18.08.2026 47минThe clock is ticking toward the European Union’s Cyber Resilience Act (CRA) deadlines, yet a staggering 66% of organizations remain completely unaware of what is coming. In this episode of What’s in the SOSS? host Sally sits down with Roman Zhukov, co-chair of the OpenSSF Global Cyber Policy Working Group and Security Communities Lead at Red Hat, to demystify this sweeping regulation. Using a brilliant "community garden" analogy, Roman breaks down the distinct roles of maintainers, stewards, ... -
CRA Readiness: Practical Strategies for Open Source Communities with Megan Knight 11.08.2026 16минIn this episode of What's in the SOSS, host Sally sits down with Megan Knight, Director of Software Communities at ARM, OpenSSF Board Member, and Chair of the Awareness SIG within the Global Cyber Policy Working Group. Together, they break down the upcoming European Union Cyber Resilience Act (CRA) and address the persistent gap in ecosystem awareness. Megan outlines concrete, practical strategies for maintainers and organizations, highlights the vital role of community collaboration across w... -
Funding the Future: Community Collaboration and the Spirit of Open Source with Mila Zhou 04.08.2026 38минJoin host Yesenia as she sits down with Mila Zhou, Open Source Program Manager at AWS, to explore the fascinating intersection of finance, strategy, and security in the open source ecosystem. Mila shares her unique journey from forensic auditing to spearheading AWS funding initiatives, breaking down how strategic financial backing transforms vulnerable "long tail" projects and empowers dedicated security champions. Discover how full-time security engineers at foundations are securing critical... -
Turning AI into the Ultimate Open Source Maintainer Power Tool with Michael Winser 28.07.2026 33минIn this episode of What’s in the SOSS?, host CRob welcomes back open source security champion Michael Winser to reflect on Alpha-Omega’s spectacular milestone of surpassing $20 million in security grants. Michael breaks down how their mission has evolved from simply chasing bugs to acting as a catalyst for sustainable, long-term security culture across critical projects. The two dive deep into the unsustainable economics of package repositories—the "app stores" of software development —and ad... -
Signing the Future: Securing AI and ML Artifacts with Mihai Maruseac 14.07.2026 21минIn this episode of What’s in the SOSS?, host Yesenia Yser sits down with Mihai Maruseac, the lead of the OpenSSF AI/ML Working Group and Security and Privacy expert at OpenAI, to dive deep into the unique security challenges facing artificial intelligence. Unlike traditional software packages, AI models cannot simply be inspected for malware by looking at their weights – malicious code only exposes itself upon execution. Mihai outlines how the community is answering this threat through the ev... -
The Heartbeat of the Kernel: Why Upstream is the Ultimate Security Strategy with Greg Kroah-Hartman 30.06.2026 34минWhat does it feel like to wake up and realize your weekend passion project is now the critical infrastructure powering the planet? In this episode of What’s in the SOSS?, CRob sits down with Linux kernel maintainer and open source icon Greg Kroah-Hartman. Greg takes us on a journey from his early days writing firmware for printer and hospital ATMs to managing the relentless, everyday engineering task of maintaining the Linux kernel over decades. He breaks down the realities of modern kernel s... -
Consuming with Intent: Driving Enterprise Security and Career Growth Through Open Source with Jamie Thomas (IBM) 16.06.2026 29минIn this episode of Big Thoughts, Open Sources, host CRob sits down with Jamie Thomas, IBM Enterprise Security Executive and OpenSSF Governing Board Member (former Chair!), to tackle the vital shifting dynamics of enterprise open source engagement. From IBM's historical "billion-dollar bet" on Linux to modern supply chain wake-up calls like SolarWinds and Log4j, Jamie pulls back the curtain on what it truly means to move from accidental consumption to intentional stewardship. Tune in to discov... -
The Ghost in the Dependency Tree: Navigating Open Source End-of-Life with HeroDevs 02.06.2026 26минIn this episode of What’s in the SOSS, host CRob sits down with Isaac Wuest, Product Line Leader at HeroDevs, to explore the critical and often overlooked "gray area" of the software supply chain: End-of-Life (EOL) software. While the industry heavily relies on CVEs to track vulnerabilities, Isaac explains how maintainer abandonment creates a vacuum where risks are present but remain undiscovered and unreported. From the origins of HeroDevs supporting AngularJS to the nuances of the EU Cyber ... -
Beginner to Builder: Shaping the Conversation in Open Source Security 19.05.2026 25минIn this episode of What's in the SOSS, Yesenia Yser interviews cybersecurity analyst Ejiro Oghenekome about her journey from UI/UX design to becoming a key contributor to the OpenSSF. Ejiro shares the inspiration behind her public "100 Days of Cybersecurity" challenge, which has helped her maintain discipline and consistency while making the field less intimidating for beginners. She discusses how connecting with the OpenSSF community led her to the BEAR Working Group, where her authorship of... -
Packaging, Transferring, and Deploying Software in Air-Gapped Environments with Zarf 05.05.2026 19минHost Sally Cooper is joined by Brandt Keller, a staff software engineer at Defense Unicorns and maintainer of the OpenSSF sandbox project, Zarf. Brandt discusses Zarf's origins as a tool designed to reliably package, transfer, and deploy software components (like container images and Helm charts) specifically for critical, air-gapped environments that lack internet connectivity. The conversation explores Zarf's evolution, highlighting its current role in introducing security gates, improving ... -
Big Thoughts, Open Sources Inaugural Episode: Beyond the Hype: Brian Fox on Securing the Agentic Future of Open Source 07.04.2026 29минIn this inaugural episode of Big Thoughts and Open Sources, host Crob sits down with Brian Fox, Co-founder and CTO of Sonatype, to dissect the friction between rapid AI adoption and foundational software security. Brian shares insights from the 11th annual State of the Software Supply Chain Report, revealing the emergence of "slop squatting" and the high frequency of AI models recommending non-existent or vulnerable dependencies. The conversation explores how the Model Context Protocol (MCP) ... -
From Noise to Signal: Security Expertise and Kusari Inspector with Mike Lieberman 24.03.2026 25минIn this episode, CRob talks with Mike Lieberman from Kusari about the current state of open source security. They discuss the growing burden on maintainers from the "deluge" of noisy, low-quality vulnerability reports, often generated by AI tools, and the vital role of "a human in the loop." Mike introduces Kusari's tool, Inspector, explaining how it uses codified security expertise to process data from tools like OpenSSF Scorecard and SLSA, effectively filtering out false positives and givin... -
Empowering New Maintainers: Inside the OpenSSF Mentorship Program 17.03.2026 22минIn this episode of What’s in the SOSS? host Sally Cooper sits down with Yesenia Yser, co-lead of the OpenSSF Mentorship Program and the BEAR Working Group, and Kairo De Araujo, Open Source Software Engineer and mentor for rstuf. They dive into the success of the OpenSSF Mentorship Program, which focuses on bringing underrepresented voices into software security. Kairo shares an incredible outcome from the last cycle – where two out of three mentees became project maintainers – while Yesenia d... -
The Gemara Project: GRC Engineering Model for Automated Risk Assessment 10.03.2026 17минHannah Braswell and Jenn Power, security engineers from Red Hat and contributors to the OpenSSF, join host Sally Cooper to discuss the Gemara project. Gemara, an acronym for GRC Engineering Model for Automated Risk Assessment, is a seven-layer logical model that aims to solve the problem of incompatibility in the GRC (Governance, Risk, and Compliance) stack. By outlining a separation of concerns, the project seeks to enable engineers to build secure and compliant systems without needing to be... -
AIxCC Part 4 – Cyber Reasoning Systems: The Real-World Journey After AIxCC 10.02.2026 17минIn this final episode of our AI Cyber Challenge (AIxCC) series, CRob and Jeff Diecks wrap-up the journey from DARPA's groundbreaking two-year competition to the exciting collaborative phase happening now. Discover how winning teams are taking their AI-powered vulnerability detection systems into the real world, finding actual bugs in projects like the Linux kernel and CUPS. Learn about the innovative OSS-CRS project that aims to create a standard infrastructure for mixing and matching the bes...
Популярен в
Этот подкаст также попадал в подкаст-чарты этих стран.