Open Source Security

Open Source Security

By Josh BressersTechnology
Download on the App Store

Open Source Security episodes

  • Securing critical infrastructure with Josh Corman

    Open Source Security welcomes Josh Corman to talk about the challenges around securing our critical infrastructure. Specifically the discussion centers around our water supplies. There are a lot of really wild things happening right now with attacks like Volt Typhoon and Salt Typhoon. Josh has an amazing ability to make these sort of discussions easy to understand without spreading FUD. Josh also has suggestions for actions that need to be taken to help deal with these problems. It's not all technical solutions, there are non technical things we can do to help reduce the risk posed by our technical systems failing.

    The show notes and blog post for this episode can be found at https://opensourcesecurity.io/2026/2026-07-critical-infrastructure-josh-corman

    36 min
  • Abandoned open source with Josh Marpet

    Josh welcomes Josh Marpet for a discussion about abandoned open source packages. Josh Marpet has a foundation called Value Chain Risk Institute that has a report discussion how to start measuring if an open source package might be abandoned. There's a lot of data, but not a lot of groups using that data to help make informed decisions about using open source. VCRI is one of those places that's starting to do this.

    The show notes and blog post for this episode can be found at https://opensourcesecurity.io/2026/2026-07-VCRI-josh-marpet

    35 min
  • Red Hat's Project Lightwell with Mo Duffy

    Josh welcomes Mo Duffy from Red Hat to chat about project Lightwell. The idea is to leverage the resources and understanding Red Hat has built up over the years to help deal with the deluge of vulnerability reports that are overwhelming open source projects. Mo does a really good job of explaining why this is fundamentally a people problem, not a technology problem. But it's a people problem we can probably use technology to help. It will be interesting to see where Lightwell goes in the next few years.

    The show notes and blog post for this episode can be found at https://opensourcesecurity.io/2026/2026-07-lightwell-mo-duffy

    33 min
  • Rust Foundation Maintainers Fund with Lori and Niko

    Josh chats with Lori Lorusso and Niko Matsakis about the Rust Foundation Maintainers Fund. This is a new project the Rust Foundation has create to help fund Rust maintainers. It's a great discussion where Lori and Niko cover all the ways they expect to fund the maintainers which is never as easy as one initially expects. Funding open source is a huge topic right now, it sounds like the Rust Foundation has some great ideas.

    The show notes and blog post for this episode can be found at https://opensourcesecurity.io/2026/2026-07-rfmf-lori-niko

    33 min
  • AIBOM, CBOM, and HBOM with Allan Friedman

    Josh chats with Allan Friedman about all things Bill of Materials. Allan did a ton of work to help turn SBOM into what it is today. He has many thoughts and ideas around the new types of BOMs, a concept he's calling the OmniBOM. Allan is always fun to chat with and he brings a ton of knowledge and advice.

    The show notes and blog post for this episode can be found at https://opensourcesecurity.io/2026/2026-06-allan-omnibom

    35 min
  • Packagist and Composer security with Jordi Boggiano

    Josh welcomes Jordi Boggiano the lead maintainer of Composer and Packagist to explain the truckload of security features they've recently added. Packagist is the PHP package registry, Composer is the dependency manager for PHP. Recently the people behind these projects have added a number of security features that will improve the security of the entire ecosystem. Jordi explains it all to us and gives a glimpse of what's coming next.

    The show notes and blog post for this episode can be found at https://opensourcesecurity.io/2026/2026-06-packagist-security-jordi

    35 min
  • Sustaining Open VSX with Mike and Thabang

    Josh welcomes Mike Milinkovich and Thabang Mashologu from the Eclipse Foundation to talk about their new managed Open VSX registry. This is the first open source package registry to create a commercial operation for large company users to help fund the registry. We discuss how we got here, what's actually going on, and why this commercial approach is working. Everyone knew this day would come, and it looks like the Eclipse Foundation got this one right.

    The show notes and blog post for this episode can be found at https://opensourcesecurity.io/2026/2026-06-openvsx-mike-thabang/

    37 min
  • Hacking your CI/CD with François Proulx

    Josh welcomes back François Proulx to talk about the absolute madness in the CI/CD universe right now. We also learn about François' new project SmokedMeat which is a tool to help you hack your own CI/CD. When Josh spoke to François a year ago, the world was a very different place than it is today. François has a ton of knowledge about how we got here and what we can do moving forward. Boost Security has a bunch of amazing open source tools François built that can help keep CI/CD systems understood and locked down.

    The show notes and blog post for this episode can be found at https://opensourcesecurity.io/2026/2026-06-françois-smoked-meat/

    36 min
  • Open source verification with Sal Kimmich

    Josh chats with Sal Kimmich about the current state of everything, and what we can expect next. Sal has some incredible insight into what we can expect to see due to the current wave of security bugs and incidents. There are some new features we will need in both our hardware and software to ward off the state of things. Since those features are years away, what we need in the short term is shoring up our SDLC programs. Sal has some really good medical examples and analogies for this one. It's a huge problem but not insurmountable.

    The show notes and blog post for this episode can be found at https://opensourcesecurity.io/2026/2026-06-verification-sal-kimmich/

    32 min
  • Vulnerability disclosure with Casey Ellis

    Josh talks to Casey Ellis about why vulnerability disclosure is so hard, and also so important. Casey is one of the best in this space having been a Bugcrowd founder. There are few people with more experience and insight into how a security vulnerability should be handled, and why the explosion of AI is making all this much harder than it's ever been before. While finding vulnerabilities is easy, reporting them is still a lot of work. Casey is working on helping everyone better understand all this with his disclose.io project.

    The show notes and blog post for this episode can be found at https://opensourcesecurity.io/2026/2026-05-vulnerability-disclosure-casey-ellis/

    38 min

About Open Source Security

From the publisher's feed

Open Source Security is a media project to help showcase and educate on open source security. Our goal is to give the community a platform educate both developers and users on how open source security works.

More shows like Open Source Security

Hacked by Hacked

Hacked

192 Listeners

The Changelog: Software Development, Open Source by Changelog Media

The Changelog: Software Development, Open Source

286 Listeners

Security Now (Audio) by TWiT

Security Now (Audio)

2,012 Listeners

Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec by Jerry Bell and Andrew Kalat

Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec

373 Listeners

LINUX Unplugged by Jupiter Broadcasting

LINUX Unplugged

272 Listeners

Risky Business by Risky Business Media

Risky Business

375 Listeners

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast) by Johannes B. Ullrich

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

653 Listeners

CyberWire Daily by N2K Networks

CyberWire Daily

1,029 Listeners

Late Night Linux by The Late Night Linux Family

Late Night Linux

169 Listeners

Smashing Security by Graham Cluley

Smashing Security

318 Listeners

Darknet Diaries by Jack Rhysider

Darknet Diaries

8,059 Listeners

Hacking Humans by N2K Networks

Hacking Humans

314 Listeners

Defense in Depth by CISO Series

Defense in Depth

73 Listeners

2.5 Admins by The Late Night Linux Family

2.5 Admins

98 Listeners

Risky Bulletin by Risky Business Media

Risky Bulletin

47 Listeners