14 Sept 2026 CRA vulnerability reporting with Daniel Thompson
"Cyber Resilience Act imposes strict vulnerability reporting rules on manufacturers, raising concerns over inefficiency, ethical disclosures, and industry compliance challenges."
More Open Source Security episodes

Published 21 Sept 2026
Duration: 33:26
"Explored open-source security challenges, highlighting curl's 'Summer of Bliss' initiative to reduce maintainer burnout, the impact of AI-generated vulnerability reports, and the need for human expertise in security management, while advocating for sustainable practices in open-source development."
Josh chats with Daniel and Stefan from curl about their summer of bliss. Curl stopped taking vulnerability reports for a month and nothing much happen...
The podcast discusses the challenges faced by open-source maintainers, particularly in managing the overwhelming volume of security vulnerability reports. The curl project team introduced an initiative called the "Summer of Bliss," a temporary pause on processing security reports during the summer months, which significantly reduced mental stress and recharged the developers. This break highlighted the importance of mental health in open-source work, demonstrating that even short respites can restore motivation and productivity. The team found that upon returning, the expected flood of reports was delayed, suggesting a potential shift in reporting patterns and offering insight into more sustainable vulnerability management practices.
A major theme is the growing role of AI in identifying vulnerabilities, with tools now capable of discovering complex issues at a scale beyond human researchers. However, while AI excels at detection, it often falls short in generating effective fixes, which still require deep human expertise to address root causes and prevent recurrence. The discussion emphasizes that long-term security improvement depends on architectural changes and thoughtful code refactoring - tasks that demand experienced judgment. Additionally, concerns were raised about the imbalance between resources dedicated to finding versus fixing vulnerabilities, ethical dilemmas in prioritization, and the need for structural solutions like vulnerability windows. The conversation also touched on the maturity and stability of the curl project, its independence, and the value of long-term contributor expertise in sustaining robust open-source software.
What if you scheduled a "Month of Bliss" to reclaim focus and reduce burnout as a solo developer?
What if you integrated AI-generated vulnerability reports but enforced human-first triage workflows?
What if you implemented a "Vulnerability Window" aligned with your release cycle?
14 Sept 2026 CRA vulnerability reporting with Daniel Thompson
"Cyber Resilience Act imposes strict vulnerability reporting rules on manufacturers, raising concerns over inefficiency, ethical disclosures, and industry compliance challenges."
31 Aug 2026 Sovereign Tech Agency with Erik Moller
"Explores the Sovereign Tech Agency's efforts to sustain open-source software as critical infrastructure, emphasizing public investment, digital sovereignty, and strategic funding for projects like *curl* and AI security."
17 Aug 2026 Maintaining EOL Open Source with Commonhaus and HeroDevs
"Explores open-source maintenance challenges, solutions for solo maintainers, and the role of organizations like Common House and HeroDevs in sustaining projects through financial, legal, and administrative support, emphasizing governance, dependency management, and enterprise-community collaboration to ensure long-term sustainability."
10 Aug 2026 Cleanup, Speedup, Levelup open source at e18e
"E18e enhances JavaScript by reducing dependencies, optimizing tools, and improving security, as seen in its work with Storybook, while promoting cleaner code and community collaboration."
3 Aug 2026 VulnCheck's State of Exploitation Report with Patrick Garrity
"Cybersecurity vulnerabilities are being exploited faster (80-day average), AI is both a tool and target, disclosure practices are inconsistent, and better coordination, transparency, and proactive patching are critical to mitigating risks."