Open Source Security

Open Source Security thumbnail

Open Source Security is a podcast to educate both developers and users on how open source security works.

Categories:

Links

Episodes

Showing 11-20 of 31

Vulnerability disclosure with Casey Ellis thumbnail

Vulnerability disclosure with Casey Ellis

25 May 2026

The evolution of vulnerability disclosure highlights challenges in prioritizing critical issues, outdated legal frameworks, and the role of initiatives like Disclosed.io in standardizing policies, alongside AI's impact on detection, open-source risks, triage complexities, and the need for collaboration and transparency to address systemic security barriers.

Open episode
F-Driod the open app store with Hans thumbnail

F-Driod the open app store with Hans

18 May 2026

F-Droid, an open-source Android app store modeled on Linux distributions, emphasizes security and transparency through source-code verification, contrasting with fragmented alternatives and corporate control, while addressing Android's ecosystem challenges and efforts to preserve open-source principles.

Open episode
Open source is critical infrastructure with Kat Cosgrove thumbnail

Open source is critical infrastructure with Kat Cosgrove

11 May 2026

Maintaining open source infrastructure is critical to prevent security risks from neglected projects, highlighting the need for sustainable funding, corporate collaboration beyond financial support, and systemic reforms to address coordination challenges, dependency fragility, and vulnerabilities.

Open episode
How to actually test a disaster plan with David Bernstein thumbnail

How to actually test a disaster plan with David Bernstein

4 May 2026

A three-part disaster recovery framework emphasizing simplicity, clear roles, and collaboration, utilizing structured testing via HSEEP, real-world validation, and continuous improvement through exercises, while addressing pitfalls and balancing realism with psychological safety.

Open episode
Open Source Pledge with Vlad-Stefan Harbuz thumbnail

Open Source Pledge with Vlad-Stefan Harbuz

27 Apr 2026

Challenges in open source sustainability include undervaluing maintainers, dependency tracking issues, fragmented tooling, burnout, governance flaws, and paradoxical tool sustainability, necessitating financial support, sustainable governance, and collective action for long-term project viability.

Open episode
Building a plan for disaster with David Bernstein thumbnail

Building a plan for disaster with David Bernstein

20 Apr 2026

Adaptive emergency management and disaster recovery demand dynamic strategies, structured frameworks like ISO 22301/NIST, cyclical preparedness, stress testing, stakeholder alignment, and resilience through collaboration and continuous learning to tackle evolving digital and physical risks.

Open episode
Open Source Malware with Paul McCarty thumbnail

Open Source Malware with Paul McCarty

13 Apr 2026

Open Source Malware (OSM) addresses the gap in detecting intentional malicious open-source components by cataloging threats, de-obfuscating code, extracting indicators of compromise, and providing post-incident data, while tackling challenges like persistent malicious packages, limitations of traditional tools against interpreted languages, fragmented collaboration, AI risks, and the need for improved CI/CD security, audit tools, and balanced AI-human oversight.

Open episode
Package management challenges with Andrew Nesbitt thumbnail

Package management challenges with Andrew Nesbitt

6 Apr 2026

Challenges in package management across ecosystems demand standardization to address fragmentation in naming, versioning, and dependencies, interoperability gaps between system-level and language-specific tools, SBOM scanner inconsistencies, and cross-ecosystem complexity, urging collaboration on shared specs and protocols despite cultural and practical barriers.

Open episode
Open Source Security at scale with Michael Wisner thumbnail

Open Source Security at scale with Michael Wisner

30 Mar 2026

The Alpha Omega Project addresses open-source security by targeting leverage points like Node.js and Python ecosystems, advocating for systemic solutions, dedicated security roles, sustainable funding, and registry infrastructure improvements to counter fragmented practices and downstream risks.

Open episode
2026 State of the Software Supply Chain with Brian Fox thumbnail

2026 State of the Software Supply Chain with Brian Fox

23 Mar 2026

The State of the Software Supply Chain Report underscores explosive open source growth (10T annual downloads) paired with critical challenges like malware proliferation (1.2M malicious packages), unresolved vulnerabilities (65% unaddressed), infrastructure strain, AI's dual role in risk (hallucinations) and potential (MCP systems), and urgent needs for improved tools, policies, and cost management amid regulatory and scalability pressures.

Open episode

Showing 11-20 of 31