
Sign up to save your podcasts
Or


đ¨ What happens when the backbone of vulnerability reporting wobbles? In April 2025, funding shocks to CVE/CWEâand the downstream NVDâsparked panic before a short-term lifeline appeared. The uncertainty hasnât gone away.In this clip:Christopher âCRobâ Robinson, CTO & Chief Security Architect, OpenSSF (The Linux Foundation)CRob previews his OSFF NY session on why reliable, authoritative vulnerability metadata is critical for banks, regulated enterprises, and open source maintainersâand what upstream is doing about it. He walks through the recent CVE/NVD turbulence, why downstream teams (risk, OSPOs, product owners) struggle to meet regulatory obligations without stable data, and how the open source community is collaborating to deliver consistent, high-quality vulnerability information going forward. Expect clear context, practical takeaways, and a path from fragmented signals to trustworthy feeds.đď¸ See CRobâs full talk at OSFF New York (Oct 21â22, 2025).đ More about FINOS: https://www.finos.org/đ§ Join our newsletter: https://www.finos.org/newsletter#FINOS #OSFFNY #OpenSourceSecurity #OpenSSF #CVE #CWE #NVD #VulnerabilityManagement #Risk #Compliance #SupplyChainSecurity
 By FINOS
By FINOS5
55 ratings
đ¨ What happens when the backbone of vulnerability reporting wobbles? In April 2025, funding shocks to CVE/CWEâand the downstream NVDâsparked panic before a short-term lifeline appeared. The uncertainty hasnât gone away.In this clip:Christopher âCRobâ Robinson, CTO & Chief Security Architect, OpenSSF (The Linux Foundation)CRob previews his OSFF NY session on why reliable, authoritative vulnerability metadata is critical for banks, regulated enterprises, and open source maintainersâand what upstream is doing about it. He walks through the recent CVE/NVD turbulence, why downstream teams (risk, OSPOs, product owners) struggle to meet regulatory obligations without stable data, and how the open source community is collaborating to deliver consistent, high-quality vulnerability information going forward. Expect clear context, practical takeaways, and a path from fragmented signals to trustworthy feeds.đď¸ See CRobâs full talk at OSFF New York (Oct 21â22, 2025).đ More about FINOS: https://www.finos.org/đ§ Join our newsletter: https://www.finos.org/newsletter#FINOS #OSFFNY #OpenSourceSecurity #OpenSSF #CVE #CWE #NVD #VulnerabilityManagement #Risk #Compliance #SupplyChainSecurity