10 Aug 2026 Cleanup, Speedup, Levelup open source at e18e
"E18e enhances JavaScript by reducing dependencies, optimizing tools, and improving security, as seen in its work with Storybook, while promoting cleaner code and community collaboration."
More Open Source Security episodes

Published 29 Jun 2026
Duration: 34:38
The evolution of Software Bill of Materials (SBOM) beyond manufacturing into cryptographic, hardware, and AI domains faces challenges in unified integration, compliance, tooling, and dependency tracking, requiring open-source collaboration, standardized frameworks, and adaptive policies to meet industry demands in procurement and risk management.
Josh chats with Allan Friedman about all things Bill of Materials. Allan did a ton of work to help turn SBOM into what it is today. He has many though...
The podcast explores the evolution and challenges of Software Bill of Materials (SBOM) frameworks, emphasizing their role in enhancing transparency and security across software, hardware, and cryptographic domains. It introduces the "Omnibomb" concepta unified system engineering approach to integrating multiple "bombs" (SBOM, hardware BOM, cryptographic BOM, etc.)while acknowledging debates over whether these domains should remain separate or merged. Key use cases include cryptographic standards like FIPS 140-2, IoT devices requiring coordinated BOM tracking, and cross-architecture software development. Challenges highlighted include balancing integration complexity with practicality, defining minimum compliance requirements, and addressing gaps in structured data formats for risk analysis, such as the inadequacy of unstructured metadata. The discussion also critiques the underdevelopment of SBOM adoption in security tools and procurement practices, despite growing industry demand.
The podcast further addresses the impact of rapid technological advancements, such as AI-driven code generation, which complicates traditional SBOM tracking by blurring lines of origin and dependency. It critiques current open-source licensing practices, emphasizing the need for clearer standards and tooling (e.g., SPDX, CycloneDX) to manage compliance risks. Regulatory and policy challenges are examined, including the difficulty of aligning evolving technical standards with static legal frameworks and the need for phased, incremental approaches to AI transparency. The role of community-driven open-source projects in shaping SBOM and AI transparency frameworks is stressed, along with calls to embed SBOM requirements into contracts and procurement to enforce accountability. Finally, it underscores the importance of structured, modular systems for AI and infrastructure transparency, akin to SBOM, while advocating for targeted compliance efforts over broad, simultaneous reforms.
What if you created an AI transparency tool that automatically maps AI-generated code dependencies to SBOM standards?
What if you contributed a modular SBOM parser to an open-source project like SPDX or Cyclone DX to streamline integration with AI transparency tools?
What if you designed a phased Omnibomb framework for hardware-software-cryptographic synergy in SaaS products?
10 Aug 2026 Cleanup, Speedup, Levelup open source at e18e
"E18e enhances JavaScript by reducing dependencies, optimizing tools, and improving security, as seen in its work with Storybook, while promoting cleaner code and community collaboration."
3 Aug 2026 VulnCheck's State of Exploitation Report with Patrick Garrity
"Cybersecurity vulnerabilities are being exploited faster (80-day average), AI is both a tool and target, disclosure practices are inconsistent, and better coordination, transparency, and proactive patching are critical to mitigating risks."
27 Jul 2026 Securing critical infrastructure with Josh Corman
"Cybersecurity faces escalating threats to critical infrastructure, requiring stronger OT security, IT-OT collaboration, proactive threat modeling, and resilience engineering to prevent real-world disasters."
20 Jul 2026 Abandoned open source with Josh Marpet
"Outdated vendor risk management processes, plagued by misrepresented questionnaires and slow vulnerability disclosures, demand faster, proactive security measures and greater transparency in open-source software."
13 Jul 2026 Red Hat's Project Lightwell with Mo Duffy
"Project Lightwell uses AI and open-source collaboration to detect and fix vulnerabilities missed by traditional tools, emphasizing upstream transparency, AI's role in security, and Red Hat's efforts to sustain long-term open-source security through collaboration and patch adoption."