Open Source Security
4.7(40)

Open Source Security

by Josh Bressers

546 episodesLatest 4 days agoEN
Open Source Security is a media project to help showcase and educate on open source security. Our goal is to give the community a platform educate both developers and users on how open source security works. There's a lot of good work happening that doesn't get attention because there's no marketing department behind it, they don't have a developer relations team posting on LinkedIn every two hours. Let's focus on those people and teams then learn what they do and how they do it. The goal is to hear from the people doing the work, they know what's up, they have a lot to teach us. We just have to listen.

This work is licensed under the Creative Commons Attribution 4.0 International License. To view a copy of this license, visit http://creativecommons.org/licenses/by/4.0/ or send a letter to Creative Commons, PO Box 1866, Mountain View, CA 94042, USA.

Recent reviews on Apple Podcasts (5)
  • josh is insufferable

    I really enjoy Kurt’s perspective on stuff. Josh is insufferable. Not sure what complex he suffers from, but he can never be wrong and is always steamrolling Kurt.

    letitsnowman ·

  • Great Podcast

    I don't work in this field; I'm strictly a security hobbyist. Found this podcast through archive.org, incidentally. Listened to 5 minutes of one episode and that was enough for me to subscribe. Thanks for a great podcast!

    CornOnTheMacabre ·

  • Most frustrating show I continue listening to

    Like a meeting with no agenda it can be informative and entertaining and you’re never quite sure if you should attend again but usually you do.

    cspeckrun ·

  • The banter is spot on

    as of September 2023 be negative reviews may be from non-techs or squishy persons in general. I understand the humor, and every episode that I have listened to so far which is only half a dozen the hosts understand and get what they are talking about. having over 20 years both professionally and not in the information technology field I find myself quite amused at their observations, and more often than not not in agreement more than once an episode. If the hosts, however, ever come across this comment, if you guys would enable Apple podcasts, so that I could toss a few dollars your way I would be more than happy to do so.

    unbleachedbit ·

  • Excellent

    I listen every week - it’s great to hear from others in my field.

    ktkaffee ·

View all reviews on Apple Podcasts

Episodes (546)

  1. CRA vulnerability reporting with Daniel Thompson

    Sep 14, 202640m

    Josh welcomes back Daniel Thompson to explain what just happened regarding vulnerability reporting and the CRA on September 11. The very first CRA requirements kicked in, but what does it really mean? Daniel explains it'

  2. Finding difficult vulnerabilities with Jaya Baloo from AISLE

    Sep 7, 202629m

    Josh chats with Jaya Baloo from AISLE about their vulnerability scanner. If you follow open source vulnerabilities AISLE is a name you've seen popping up recently. They have a vulnerability scanner that is outperforming

  3. Sovereign Tech Agency with Erik Möller

    Aug 31, 202636m

    Josh chats with Erik Möller from the Sovereign Tech Agency about what they're doing. The Sovereign Tech Agency is doing some amazing work around funding open source maintainers and projects. Eric breaks down what they're

  4. CVEs vs Advisories with Paul Asadoorian

    Aug 24, 202638m

    Josh chats with Paul Asadoorian about a tool he wrote called fettle and a recent report Paul published on CVEs. Fettle is a tool to help update and manage Linux systems. The big sell on this one is checking if your firmw

  5. Maintaining EOL Open Source with Commonhaus and HeroDevs

    Aug 17, 202634m

    Josh chats with Erin Schnabel and Rob Nalen about a new effort from Commonhaus and HeroDevs for maintaining end of life open source. This project, the Open Source Sustainability Initiative is a clever way to bring corpor

  6. Cleanup, Speedup, Levelup open source at e18e

    Aug 10, 202635m

    Josh chats with James from e18e. This is a project that is working on improving Javascript packages by cleaning up, speeding up, and leveling up the dependencies. The way the e18e project handles this work is very human

  7. VulnCheck's State of Exploitation Report with Patrick Garrity

    Aug 3, 202636m

    Josh chats with Patrick Garrity about the VulnCheck State of Exploitation 1H-2026 report. Patrick explains the current trends we are seeing around vulnerabilities right now. While the number of CVEs is way up, the number

  8. Securing critical infrastructure with Josh Corman

    Jul 27, 202635m

    Open Source Security welcomes Josh Corman to talk about the challenges around securing our critical infrastructure. Specifically the discussion centers around our water supplies. There are a lot of really wild things hap

  9. Abandoned open source with Josh Marpet

    Jul 20, 202634m

    Josh welcomes Josh Marpet for a discussion about abandoned open source packages. Josh Marpet has a foundation called Value Chain Risk Institute that has a report discussion how to start measuring if an open source packag

  10. Red Hat's Project Lightwell with Mo Duffy

    Jul 13, 202632m

    Josh welcomes Mo Duffy from Red Hat to chat about project Lightwell. The idea is to leverage the resources and understanding Red Hat has built up over the years to help deal with the deluge of vulnerability reports that

  11. Rust Foundation Maintainers Fund with Lori and Niko

    Jul 6, 202632m

    Josh chats with Lori Lorusso and Niko Matsakis about the Rust Foundation Maintainers Fund. This is a new project the Rust Foundation has create to help fund Rust maintainers. It's a great discussion where Lori and Niko c

  12. AIBOM, CBOM, and HBOM with Allan Friedman

    Jun 29, 202634m

    Josh chats with Allan Friedman about all things Bill of Materials. Allan did a ton of work to help turn SBOM into what it is today. He has many thoughts and ideas around the new types of BOMs, a concept he's calling the

  13. Packagist and Composer security with Jordi Boggiano

    Jun 22, 202634m

    Josh welcomes Jordi Boggiano the lead maintainer of Composer and Packagist to explain the truckload of security features they've recently added. Packagist is the PHP package registry, Composer is the dependency manager f

  14. Sustaining Open VSX with Mike and Thabang

    Jun 15, 202636m

    Josh welcomes Mike Milinkovich and Thabang Mashologu from the Eclipse Foundation to talk about their new managed Open VSX registry. This is the first open source package registry to create a commercial operation for larg

  15. Hacking your CI/CD with François Proulx

    Jun 8, 202635m

    Josh welcomes back François Proulx to talk about the absolute madness in the CI/CD universe right now. We also learn about François' new project SmokedMeat which is a tool to help you hack your own CI/CD. When Josh spoke

  16. Open source verification with Sal Kimmich

    Jun 1, 202631m

    Josh chats with Sal Kimmich about the current state of everything, and what we can expect next. Sal has some incredible insight into what we can expect to see due to the current wave of security bugs and incidents. There

  17. Vulnerability disclosure with Casey Ellis

    May 25, 202637m

    Josh talks to Casey Ellis about why vulnerability disclosure is so hard, and also so important. Casey is one of the best in this space having been a Bugcrowd founder. There are few people with more experience and insight

  18. F-Droid the open app store with Hans

    May 18, 202636m

    Josh talks to Hans-Christoph Steiner about F-Droid, the Free and Open Source Android App Repository. The way F-Droid works looks a lot like a Linux distribution which has some interesting security challenges, but also so

  19. Open source is critical infrastructure with Kat Cosgrove

    May 11, 202638m

    Josh talks to Kat Cosgrove about a how companies should be treating open source more like their critical infrastructure than free stuff. Kat has a ton of knowledge about how the interactions between companies and open so

  20. How to actually test a disaster plan with David Bernstein

    May 4, 202634m

    Josh and David finish up the disaster recovery and emergency planning trilogy. In this one David tells us how to test the plan he told us how to build in the last episode. There are some great ideas in this one about how

  21. Open Source Pledge with Vlad-Stefan Harbuz

    Apr 27, 202634m

    Josh has a discussion with Vlad-Stefan Harbuz about the Open Source Pledge as well as his recent FOSDEM talk. The Open Source Pledge is all about trying to build a sustainable universe for open source maintainers. This t

  22. Building a plan for disaster with David Bernstein

    Apr 20, 202639m

    Josh welcomes back David Bernstein to talk about creating a disaster recover plan. It's a very timely topic given all the current events. There are more supply chain attacks and compromises than ever before. There are so

  23. Open Source Malware with Paul McCarty

    Apr 13, 202638m

    Josh talks to Paul McCarty of Open Source Malware about ... open source malware. Paul explains why there aren't many good open source malware datasets. We discuss why the existing data is lacking for many use cases. We o

  24. Package management challenges with Andrew Nesbitt

    Apr 6, 202636m

    Josh welcomes back Andrew Nesbitt to discuss some recent blog posts he wrote about the challenges of new ecosystems as well as challenges of no ecosystems like C. There aren't very many people who look at multiple ecosys

  25. Open Source Security at scale with Michael Winser

    Mar 30, 202642m

    Josh talks to Michael Winser about a talk he gave at FOSDEM as well as his work on Alpha Omega at the Linux Foundation. Michael is approaching open source security in a way that nobody has ever tried before. What if we c