Open Source Security
Josh Bressers
0
Open Source Security is a media project that aims to showcase and educate on open source security. The podcast gives the community a platform to educate both developers and users on how open source security works. It focuses on the people and teams doing the work, highlighting their contributions and teaching listeners about their methods.
Bölümler
-
CRA vulnerability reporting with Daniel Thompson 14.09.2026 40dkJosh welcomes back Daniel Thompson to explain what just happened regarding vulnerability reporting and the CRA on September 11. The very first CRA requirements kicked in, but what does it really mean? Daniel explains it's not too bad. There are plenty more requirements coming, but this one feels very approachable. The show notes and blog post for this episode can be found at https://opensourcesecurity.io/2026/2026-09-daniel-cra -
Finding difficult vulnerabilities with Jaya Baloo from AISLE 07.09.2026 29dkJosh chats with Jaya Baloo from AISLE about their vulnerability scanner. If you follow open source vulnerabilities AISLE is a name you've seen popping up recently. They have a vulnerability scanner that is outperforming most of the existing scanners like Mythos. Jaya gives us some insight into how this all works and why they're different. We also learn about some scary new attacks that can be conducted on LLM models. Jaya was a ton of fun and filled with insights. The show notes and blog post for this episode can be found at https://opensourcesecurity.io/2026/2026-09-jaya-aisle -
Sovereign Tech Agency with Erik Möller 31.08.2026 36dkJosh chats with Erik Möller from the Sovereign Tech Agency about what they're doing. The Sovereign Tech Agency is doing some amazing work around funding open source maintainers and projects. Eric breaks down what they're doing, how it works, and how you can apply for funding. We even learn about some similar projects happening in the EU. Hopefully in the near future we will see the work Sovereign Tech Agency is doing happening in every country. The show notes and blog post for this episode can be found at https://opensourcesecurity.io/2026/2026-08-erik-sta -
CVEs vs Advisories with Paul Asadoorian 24.08.2026 38dkJosh chats with Paul Asadoorian about a tool he wrote called fettle and a recent report Paul published on CVEs. Fettle is a tool to help update and manage Linux systems. The big sell on this one is checking if your firmware is out of date. We then talk about a report Paul created that doesn't obsess over CVEs, but rather the vendor updates. It makes more sense to worry about advisories as those are actionable, where CVEs often are not. It's a great chat and Paul is a legend in the industry. The show notes and blog post for this episode can be found at https://opensourcesecurity.io/2026/2026-08-paul-fettle-cve -
Maintaining EOL Open Source with Commonhaus and HeroDevs 17.08.2026 34dkJosh chats with Erin Schnabel and Rob Nalen about a new effort from Commonhaus and HeroDevs for maintaining end of life open source. This project, the Open Source Sustainability Initiative is a clever way to bring corporations and projects together for maintenance of new and old versions of open source projects. This is pretty new territory for everyone, this project is worth keeping an eye on because it has a very small scope initially. Other similar ideas have gigantic scopes that are almost certainly too large. The show notes and blog post for this episode can be found at https://opensourcesecurity.io/2026/2026-08-commonhaus-herodevs -
Cleanup, Speedup, Levelup open source at e18e 10.08.2026 35dkJosh chats with James from e18e. This is a project that is working on improving Javascript packages by cleaning up, speeding up, and leveling up the dependencies. The way the e18e project handles this work is very human open source. It's all about building up connections and trust with the package communities, which is no small effort. James fills us in on what they're doing as well as how we can get involved. It's a truly amazing effort The show notes and blog post for this episode can be found at https://opensourcesecurity.io/2026/2026-08-e18e-james -
VulnCheck's State of Exploitation Report with Patrick Garrity 03.08.2026 36dkJosh chats with Patrick Garrity about the VulnCheck State of Exploitation 1H-2026 report. Patrick explains the current trends we are seeing around vulnerabilities right now. While the number of CVEs is way up, the number of actually exploited vulnerabilities isn't growing year over year. This tells us there is a lot of FUD and hype. We also ask where are all the vulnerabilities that project Glasswing found. They should be going public by now, but we're not seeing that play out in the data. The show notes and blog post for this episode can be found at https://opensourcesecurity.io/2026/2026-08-vulncheck-state-of-exploitation -
Securing critical infrastructure with Josh Corman 27.07.2026 35dkOpen Source Security welcomes Josh Corman to talk about the challenges around securing our critical infrastructure. Specifically the discussion centers around our water supplies. There are a lot of really wild things happening right now with attacks like Volt Typhoon and Salt Typhoon. Josh has an amazing ability to make these sort of discussions easy to understand without spreading FUD. Josh also has suggestions for actions that need to be taken to help deal with these problems. It's not all technical solutions, there are non technical things we can do to help reduce the risk posed by our technical systems failing. The show notes and blog post for this episode can be found at https://opensourcesecurity.io/2026/2026-07-critical-infrastructure-josh-corman -
Abandoned open source with Josh Marpet 20.07.2026 34dkJosh welcomes Josh Marpet for a discussion about abandoned open source packages. Josh Marpet has a foundation called Value Chain Risk Institute that has a report discussion how to start measuring if an open source package might be abandoned. There's a lot of data, but not a lot of groups using that data to help make informed decisions about using open source. VCRI is one of those places that's starting to do this. The show notes and blog post for this episode can be found at https://opensourcesecurity.io/2026/2026-07-VCRI-josh-marpet -
Red Hat's Project Lightwell with Mo Duffy 13.07.2026 32dkJosh welcomes Mo Duffy from Red Hat to chat about project Lightwell. The idea is to leverage the resources and understanding Red Hat has built up over the years to help deal with the deluge of vulnerability reports that are overwhelming open source projects. Mo does a really good job of explaining why this is fundamentally a people problem, not a technology problem. But it's a people problem we can probably use technology to help. It will be interesting to see where Lightwell goes in the next few years. The show notes and blog post for this episode can be found at https://opensourcesecurity.io/2026/2026-07-lightwell-mo-duffy -
Rust Foundation Maintainers Fund with Lori and Niko 06.07.2026 32dkJosh chats with Lori Lorusso and Niko Matsakis about the Rust Foundation Maintainers Fund. This is a new project the Rust Foundation has create to help fund Rust maintainers. It's a great discussion where Lori and Niko cover all the ways they expect to fund the maintainers which is never as easy as one initially expects. Funding open source is a huge topic right now, it sounds like the Rust Foundation has some great ideas. The show notes and blog post for this episode can be found at https://opensourcesecurity.io/2026/2026-07-rfmf-lori-niko -
AIBOM, CBOM, and HBOM with Allan Friedman 29.06.2026 34dkJosh chats with Allan Friedman about all things Bill of Materials. Allan did a ton of work to help turn SBOM into what it is today. He has many thoughts and ideas around the new types of BOMs, a concept he's calling the OmniBOM. Allan is always fun to chat with and he brings a ton of knowledge and advice. The show notes and blog post for this episode can be found at https://opensourcesecurity.io/2026/2026-06-allan-omnibom -
Packagist and Composer security with Jordi Boggiano 22.06.2026 34dkJosh welcomes Jordi Boggiano the lead maintainer of Composer and Packagist to explain the truckload of security features they've recently added. Packagist is the PHP package registry, Composer is the dependency manager for PHP. Recently the people behind these projects have added a number of security features that will improve the security of the entire ecosystem. Jordi explains it all to us and gives a glimpse of what's coming next. The show notes and blog post for this episode can be found at https://opensourcesecurity.io/2026/2026-06-packagist-security-jordi -
Sustaining Open VSX with Mike and Thabang 15.06.2026 36dkJosh welcomes Mike Milinkovich and Thabang Mashologu from the Eclipse Foundation to talk about their new managed Open VSX registry. This is the first open source package registry to create a commercial operation for large company users to help fund the registry. We discuss how we got here, what's actually going on, and why this commercial approach is working. Everyone knew this day would come, and it looks like the Eclipse Foundation got this one right. The show notes and blog post for this episode can be found at https://opensourcesecurity.io/2026/2026-06-openvsx-mike-thabang/ -
Hacking your CI/CD with François Proulx 08.06.2026 35dkJosh welcomes back François Proulx to talk about the absolute madness in the CI/CD universe right now. We also learn about François' new project SmokedMeat which is a tool to help you hack your own CI/CD. When Josh spoke to François a year ago, the world was a very different place than it is today. François has a ton of knowledge about how we got here and what we can do moving forward. Boost Security has a bunch of amazing open source tools François built that can help keep CI/CD systems understood and locked down. The show notes and blog post for this episode can be found at https://opensourcesecurity.io/2026/2026-06-françois-smoked-meat/ -
Open source verification with Sal Kimmich 01.06.2026 31dkJosh chats with Sal Kimmich about the current state of everything, and what we can expect next. Sal has some incredible insight into what we can expect to see due to the current wave of security bugs and incidents. There are some new features we will need in both our hardware and software to ward off the state of things. Since those features are years away, what we need in the short term is shoring up our SDLC programs. Sal has some really good medical examples and analogies for this one. It's a huge problem but not insurmountable. The show notes and blog post for this episode can be found at https://opensourcesecurity.io/2026/2026-06-verification-sal-kimmich/ -
Vulnerability disclosure with Casey Ellis 25.05.2026 37dkJosh talks to Casey Ellis about why vulnerability disclosure is so hard, and also so important. Casey is one of the best in this space having been a Bugcrowd founder. There are few people with more experience and insight into how a security vulnerability should be handled, and why the explosion of AI is making all this much harder than it's ever been before. While finding vulnerabilities is easy, reporting them is still a lot of work. Casey is working on helping everyone better understand all this with his disclose.io project. The show notes and blog post for this episode can be found at https://opensourcesecurity.io/2026/2026-05-vulnerability-disclosure-casey-ellis/ -
F-Droid the open app store with Hans 18.05.2026 36dkJosh talks to Hans-Christoph Steiner about F-Droid, the Free and Open Source Android App Repository. The way F-Droid works looks a lot like a Linux distribution which has some interesting security challenges, but also some great security benefits. Hans walks us through the current state of open app repositories and also what the future currently looks like. There are more open phones than ever before, but there are also more challenges than ever before. Hans breaks it all down in an easy to understand way. The show notes and blog post for this episode can be found at https://opensourcesecurity.io/2026/2026-05-fdroid-hans-steiner/ -
Open source is critical infrastructure with Kat Cosgrove 11.05.2026 38dkJosh talks to Kat Cosgrove about a how companies should be treating open source more like their critical infrastructure than free stuff. Kat has a ton of knowledge about how the interactions between companies and open source communities can work well, or not work at all. Kat's time on the Kubernetes Release Team. We touch on how a project like Kubernetes is super successful, while another, Ingress NGINX, was not. It's a super insightful discussion with a ton of lessons and advice for everyone. The show notes and blog post for this episode can be found at https://opensourcesecurity.io/2026/2026-05-open-source-infrastructure-kat/ -
How to actually test a disaster plan with David Bernstein 04.05.2026 34dkJosh and David finish up the disaster recovery and emergency planning trilogy. In this one David tells us how to test the plan he told us how to build in the last episode. There are some great ideas in this one about how to test the process not the people. How to construct the plan, and even some tips to go from a plan to some actual real world testing. It's another episode filled with great and practical advice. The show notes and blog post for this episode can be found at https://opensourcesecurity.io/2026/2026-05-testing-the-plan-david-bernstein/
Şurada popüler
Bu podcast şu ülkelerin podcast listelerinde de yer alıyor.