More Open Source Security episodes

Open source is critical infrastructure with Kat Cosgrove thumbnail

Open source is critical infrastructure with Kat Cosgrove

Published 11 May 2026

Duration: 38:01

Maintaining open source infrastructure is critical to prevent security risks from neglected projects, highlighting the need for sustainable funding, corporate collaboration beyond financial support, and systemic reforms to address coordination challenges, dependency fragility, and vulnerabilities.

Episode Description

Josh talks to Kat Cosgrove about a how companies should be treating open source more like their critical infrastructure than free stuff. Kat has a ton...

Overview

The podcast emphasizes the critical need for sustained maintenance of open source infrastructure, highlighting security risks that emerge when projects like Ingress NGINXsupporting 50% of cloud-native environmentsare neglected due to a lack of active maintainers or corporate support. Such oversights can leave systems vulnerable to exploits, as seen in the accumulation of unresolved vulnerabilities (CVEs) and the eventual shutdown of Ingress NGINX. The discussion underscores that many open source projects rely on voluntary contributions from individuals working in their spare time, an unsustainable model for critical infrastructure. While organizations like the CNCF provide foundational support (e.g., infrastructure, legal guidance), they do not directly fund engineering resources for individual projects, leaving sustainability challenges unaddressed. The contrast between Kubernetes successthrough widespread coordination and community engagementand other projects struggles highlights the uneven distribution of attention and resources in the open source ecosystem, with non-flashy tools often facing greater neglect.

Key themes also include the risks of single-maintainer projects, which can create fragile dependencies and potential time bombs if abandoned, as well as the psychological and cultural barriers that hinder contributions to unglamorous but vital components. The podcast critiques systemic communication failures in the security industry, where vague warnings and condescension alienate non-expert audiences, and stresses the need for audience-centric messaging that avoids overestimating or underestimating technical knowledge. Maintainer burnout and the moral burden of sustaining projects indefinitely are also flagged as significant issues, with calls for policies that prioritize contributor well-being, such as delaying project releases to prevent overwork. The discussion advocates for improved collaboration between engineers and executives to translate technical risks into business terms, while urging individual contributors to engage with open source projects without relying on employer approval.

Finally, the conversation addresses the growing challenges of trust in open source ecosystems, including heightened skepticism among maintainers due to past security incidents and the difficulty of distinguishing malicious intent from legitimate contributions. While organizations like OpenSSF and the Linux Foundation are working to address these issues, the podcast stresses that systemic changes are needed to ensure the long-term sustainability and security of open source infrastructure. It concludes by framing current challenges as growing pains in a trend toward open source becoming the norm, though legacy systems persist, and emphasizes the importance of fostering inclusive, sustainable practices to prevent future crises.

Recent Episodes of Open Source Security

22 Jun 2026 Packagist and Composer security with Jordi Boggiano

Strategies for securing open-source ecosystems include malware detection via third-party feeds, transparency logs, rapid incident response, blocking malicious downloads, private registry controls, immutable package releases, standardized workflows, MFA enforcement, and technical proposals like artifact validation and build attestation, while addressing challenges like maintainer hacking, AI risks, usability trade-offs, and the need for ecosystem-wide alignment and human verification.

15 Jun 2026 Sustaining Open VSX with Mike and Thabang

Eclipse Foundation's OpenVSX, a VS Code extension repository, surged to 600M monthly downloads, evolved to a commercial model with enterprise SLAs and security teams, while addressing scalability, open-source balance, and funding challenges for AI expansion.

8 Jun 2026 Hacking your CI/CD with Francois Proulx

Critical vulnerabilities in open source CI/CD pipelines, including hijacking and supply chain attacks via social engineering or compromised builds, are highlighted through incidents like TJ Actions and Ultralytics, with mitigation strategies emphasizing secure credentials, externalized workflows, threat modeling, and tools like *Smoked Meat* and *Bagel* to enhance incident response and supply chain security.

1 Jun 2026 Open source verification with Sal Kimmich

Cybersecurity challenges include complex application ecosystems, overlooked kernel vulnerabilities, supply chain risks, and systemic risks from under-resourced organizations prioritizing surface-level controls, alongside calls for regulatory reforms, proactive threat modeling, secure development practices, and addressing tribal nations' unique legal and sovereignty concerns.

25 May 2026 Vulnerability disclosure with Casey Ellis

The evolution of vulnerability disclosure highlights challenges in prioritizing critical issues, outdated legal frameworks, and the role of initiatives like Disclosed.io in standardizing policies, alongside AI's impact on detection, open-source risks, triage complexities, and the need for collaboration and transparency to address systemic security barriers.

More Open Source Security episodes