What's in the SOSS? An OpenSSF Podcast

Bridging DevOps and Security: Tracy Reagan on the Future of Open Source


Listen Later

In this episode of What's in the SOSS, we sit down with longtime open source leader and DevOps champion Tracy Ragan. From her early days with the Eclipse Foundation to her current work with Ortelius, the Continuous Delivery Foundation, and the OpenSSF, Tracy shares her journey through the ever-evolving world of open source security.

We dig into the importance of configuration management, what DevSecOps really means, and how projects like the OpenSSF Scorecard and Ortelius help make our software supply chains more transparent and secure. Plus, we tackle the education gap between security pros and DevOps engineers—and how we can bridge it.

If you're curious about building more secure pipelines or just want to geek out about SBOMs and Scorecard, this episode is for you.

Chapters:
00:25 – Welcome + Tracy's Open Source Origin Story
02:00 – Early Days at the Eclipse Foundation
03:10 – DevOps + DevSecOps: Why It Matters
04:20 – Explaining the DevOps “Factory Floor”
06:00 – DevOps Pipelines as Security Data Engines
07:50 – What Is the OpenSSF Scorecard?
09:30 – Ortelius: Aggregating DevOps + Security Insights
11:20 – The DevOps Budget Problem + Exposing Insecure Packages
13:00 – Why DevRel Is Critical for DevOps Security Education
15:40 – Crossing the Divide Between DevOps and Security Teams
16:10 – 🎉 Rapid Fire: Editors, Mascots & Spicy Food
17:30 – Final Call to Action + How to Get Involved

Episode links:

  • Tracy Ragan’s LinkedIn page
  • Ortelius Project
  • Scorecard Project
  • Eclipse Foundation
  • CD Foundation
  • Get involved with the OpenSSF
  • Subscribe to the OpenSSF newsletter
  • Follow the OpenSSF on LinkedIn
...more
View all episodesView all episodes
Download on the App Store

What's in the SOSS? An OpenSSF PodcastBy OpenSSF