More Open Source Security episodes

Open Source Pledge with Vlad-Stefan Harbuz thumbnail

Open Source Pledge with Vlad-Stefan Harbuz

Published 27 Apr 2026

Duration: 34:56

Challenges in open source sustainability include undervaluing maintainers, dependency tracking issues, fragmented tooling, burnout, governance flaws, and paradoxical tool sustainability, necessitating financial support, sustainable governance, and collective action for long-term project viability.

Episode Description

Josh has a discussion with Vlad-Stefan Harbuz about the Open Source Pledge as well as his recent FOSDEM talk. The Open Source Pledge is all about tryi...

Overview

The podcast explores challenges in open source software maintenance, emphasizing the need for financial and systemic support for contributors. It highlights the Open Source Pledge, an initiative encouraging companies to pay $2,000 annually per full-time equivalent developer they rely on, to sustain open source maintainers. However, implementation faces hurdles, including difficulties in identifying maintainers, ineffectiveness of platforms like GitHub Sponsors, and debates over equitable funding models. The discussion also addresses broader issues like the undervaluation of open source labor, the ethical and social dimensions of collaboration, and the sustainability of projects reliant on single maintainers or unmanaged dependencies.

Technical and governance challenges are central, with problems in tracking binary dependencies (e.g., in Python packages) and the risks of unattributed security vulnerabilities. Tools like Thanks.dev and custom solutions offer partial remedies but lack scalability. The podcast underscores the vulnerability of open source projects due to burnout, limited governance structures, and the "bus factor" riskprojects dependent on a single contributor. Maintainers often struggle with balancing community expectations, personal well-being, and unpaid labor, while employers and users are urged to recognize their critical role. Systemic solutions, such as shared governance models, research funding for sustainability tools, and institutional support, are proposed to address these issues.

The conversation also critiques the tension between open source ideals and corporate practices, including the "market mentality" of expecting free fixes and the need for companies to prioritize long-term investment in open source. It stresses the importance of collective action, transparency in contributor dynamics, and fostering sustainable ecosystems to ensure the longevity of critical technologies. The discussion reflects a call for rethinking how open source is valued, maintained, and supported, both financially and structurally, to prevent burnout, neglect, and security risks.

Recent Episodes of Open Source Security

20 Jul 2026 Abandoned open source with Josh Marpet

"Outdated vendor risk management processes, plagued by misrepresented questionnaires and slow vulnerability disclosures, demand faster, proactive security measures and greater transparency in open-source software."

13 Jul 2026 Red Hat's Project Lightwell with Mo Duffy

"Project Lightwell uses AI and open-source collaboration to detect and fix vulnerabilities missed by traditional tools, emphasizing upstream transparency, AI's role in security, and Red Hat's efforts to sustain long-term open-source security through collaboration and patch adoption."

29 Jun 2026 AIBOM, CBOM, and HBOM with Allan Friedman

The evolution of Software Bill of Materials (SBOM) beyond manufacturing into cryptographic, hardware, and AI domains faces challenges in unified integration, compliance, tooling, and dependency tracking, requiring open-source collaboration, standardized frameworks, and adaptive policies to meet industry demands in procurement and risk management.

22 Jun 2026 Packagist and Composer security with Jordi Boggiano

Strategies for securing open-source ecosystems include malware detection via third-party feeds, transparency logs, rapid incident response, blocking malicious downloads, private registry controls, immutable package releases, standardized workflows, MFA enforcement, and technical proposals like artifact validation and build attestation, while addressing challenges like maintainer hacking, AI risks, usability trade-offs, and the need for ecosystem-wide alignment and human verification.

15 Jun 2026 Sustaining Open VSX with Mike and Thabang

Eclipse Foundation's OpenVSX, a VS Code extension repository, surged to 600M monthly downloads, evolved to a commercial model with enterprise SLAs and security teams, while addressing scalability, open-source balance, and funding challenges for AI expansion.

More Open Source Security episodes