
Sign up to save your podcasts
Or


Josh chats with James Matchett from Cloudsmith about a new report they put out. It has some scary looking statistics in it about how organizations are using dependencies. There are some surprising numbers in there, but the story is really one of defense in depth. There's no single thing we can do here, it's all about knowing what you have every step of the way. It's easy to say, but certainly a challenge to do right. James is a ton of fun to chat with and filled with energy and knowledge.
The show notes and blog post for this episode can be found at https://opensourcesecurity.io/2026/2026-10-james-cloudsmith
Josh welcomes Amanda Brock from OpenUK to chat about sovereignty, policy, open source, and a whole host of other topics. Amanda has front row seat into how sovereignty decisions can affect a county and its open source. It seems sometimes like open source is a global phenomenon, but there are always country wide considerations. This is what the OpenUK is doing in the UK. The discussion is great and the things the OpenUK is dealing with will affect many of us moving forward, even if we would prefer to ignore our digital borders.
The show notes and blog post for this episode can be found at https://opensourcesecurity.io/2026/2026-09-OpenUK-amanda-brock
Josh chats with Daniel and Stefan from curl about their summer of bliss. Curl stopped taking vulnerability reports for a month and nothing much happened really. Daniel and Stefan have a really pragmatic view of all the new LLM powered vulnerability detection tools. The cost of finding a vulnerability has dropped dramatically, but the cost of fixing those bugs hasn't changed. Taking some time off is important for anyone in the middle of these reports. Daniel and Stefan have some great experience and ideas on how to make this all happen. It's great advice for anyone working on software, not just open source.
The show notes and blog post for this episode can be found at https://opensourcesecurity.io/2026/2026-09-curl-bliss-stefan-daniel
Josh welcomes back Daniel Thompson to explain what just happened regarding vulnerability reporting and the CRA on September 11. The very first CRA requirements kicked in, but what does it really mean? Daniel explains it's not too bad. There are plenty more requirements coming, but this one feels very approachable.
The show notes and blog post for this episode can be found at https://opensourcesecurity.io/2026/2026-09-daniel-cra
Josh chats with Jaya Baloo from AISLE about their vulnerability scanner. If you follow open source vulnerabilities AISLE is a name you've seen popping up recently. They have a vulnerability scanner that is outperforming most of the existing scanners like Mythos. Jaya gives us some insight into how this all works and why they're different. We also learn about some scary new attacks that can be conducted on LLM models. Jaya was a ton of fun and filled with insights.
The show notes and blog post for this episode can be found at https://opensourcesecurity.io/2026/2026-09-jaya-aisle
Josh chats with Erik Möller from the Sovereign Tech Agency about what they're doing. The Sovereign Tech Agency is doing some amazing work around funding open source maintainers and projects. Eric breaks down what they're doing, how it works, and how you can apply for funding. We even learn about some similar projects happening in the EU. Hopefully in the near future we will see the work Sovereign Tech Agency is doing happening in every country.
The show notes and blog post for this episode can be found at https://opensourcesecurity.io/2026/2026-08-erik-sta
Josh chats with Paul Asadoorian about a tool he wrote called fettle and a recent report Paul published on CVEs. Fettle is a tool to help update and manage Linux systems. The big sell on this one is checking if your firmware is out of date. We then talk about a report Paul created that doesn't obsess over CVEs, but rather the vendor updates. It makes more sense to worry about advisories as those are actionable, where CVEs often are not. It's a great chat and Paul is a legend in the industry.
The show notes and blog post for this episode can be found at https://opensourcesecurity.io/2026/2026-08-paul-fettle-cve
Josh chats with Erin Schnabel and Rob Nalen about a new effort from Commonhaus and HeroDevs for maintaining end of life open source. This project, the Open Source Sustainability Initiative is a clever way to bring corporations and projects together for maintenance of new and old versions of open source projects. This is pretty new territory for everyone, this project is worth keeping an eye on because it has a very small scope initially. Other similar ideas have gigantic scopes that are almost certainly too large.
The show notes and blog post for this episode can be found at https://opensourcesecurity.io/2026/2026-08-commonhaus-herodevs
Josh chats with James from e18e. This is a project that is working on improving Javascript packages by cleaning up, speeding up, and leveling up the dependencies. The way the e18e project handles this work is very human open source. It's all about building up connections and trust with the package communities, which is no small effort. James fills us in on what they're doing as well as how we can get involved. It's a truly amazing effort
The show notes and blog post for this episode can be found at https://opensourcesecurity.io/2026/2026-08-e18e-james
Josh chats with Patrick Garrity about the VulnCheck State of Exploitation 1H-2026 report. Patrick explains the current trends we are seeing around vulnerabilities right now. While the number of CVEs is way up, the number of actually exploited vulnerabilities isn't growing year over year. This tells us there is a lot of FUD and hype. We also ask where are all the vulnerabilities that project Glasswing found. They should be going public by now, but we're not seeing that play out in the data.
The show notes and blog post for this episode can be found at https://opensourcesecurity.io/2026/2026-08-vulncheck-state-of-exploitation
From the publisher's feed

192 Listeners

286 Listeners

2,012 Listeners

373 Listeners

272 Listeners

375 Listeners

653 Listeners

1,029 Listeners

169 Listeners

318 Listeners

8,059 Listeners

314 Listeners

73 Listeners

98 Listeners

47 Listeners