Ga naar de inhoud
PodcastsTechnologieOpen Source Security

Open Source Security

Josh Bressers
Open Source Security
Nieuwste aflevering

550 afleveringen

  • Open Source Security

    Dependency attacks in 2026 with James Matchett

    05-10-2026 | 32 Min.
    Josh chats with Jeff Matchett from Cloudsmith about a new report they put out. It has some scary looking statistics in it about how organizations are using dependencies. There are some surprising numbers in there, but the story is really one of defense in depth. There's no single thing we can do here, it's all about knowing what you have every step of the way. It's easy to say, but certainly a challenge to do right. James is a ton of fun to chat with and filled with energy and knowledge.
    The show notes and blog post for this episode can be found at
    https://opensourcesecurity.io/2026/2026-10-james-cloudsmith
  • Open Source Security

    Sovereignty, policy, and OpenUK with Amanda Brock

    28-09-2026 | 34 Min.
    Josh welcomes Amanda Brock from OpenUK to chat about sovereignty, policy, open source, and a whole host of other topics. Amanda has front row seat into how sovereignty decisions can affect a county and its open source. It seems sometimes like open source is a global phenomenon, but there are always country wide considerations. This is what the OpenUK is doing in the UK. The discussion is great and the things the OpenUK is dealing with will affect many of us moving forward, even if we would prefer to ignore our digital borders.
    The show notes and blog post for this episode can be found at
    https://opensourcesecurity.io/2026/2026-09-OpenUK-amanda-brock
  • Open Source Security

    The curl summer of Bliss with Daniel and Stefan

    21-09-2026 | 33 Min.
    Josh chats with Daniel and Stefan from curl about their summer of bliss. Curl stopped taking vulnerability reports for a month and nothing much happened really. Daniel and Stefan have a really pragmatic view of all the new LLM powered vulnerability detection tools. The cost of finding a vulnerability has dropped dramatically, but the cost of fixing those bugs hasn't changed. Taking some time off is important for anyone in the middle of these reports. Daniel and Stefan have some great experience and ideas on how to make this all happen. It's great advice for anyone working on software, not just open source.
    The show notes and blog post for this episode can be found at
    https://opensourcesecurity.io/2026/2026-09-curl-bliss-stefan-daniel
  • Open Source Security

    CRA vulnerability reporting with Daniel Thompson

    14-09-2026 | 40 Min.
    Josh welcomes back Daniel Thompson to explain what just happened regarding vulnerability reporting and the CRA on September 11. The very first CRA requirements kicked in, but what does it really mean? Daniel explains it's not too bad. There are plenty more requirements coming, but this one feels very approachable.
    The show notes and blog post for this episode can be found at
    https://opensourcesecurity.io/2026/2026-09-daniel-cra
  • Open Source Security

    Finding difficult vulnerabilities with Jaya Baloo from AISLE

    07-09-2026 | 29 Min.
    Josh chats with Jaya Baloo from AISLE about their vulnerability scanner. If you follow open source vulnerabilities AISLE is a name you've seen popping up recently. They have a vulnerability scanner that is outperforming most of the existing scanners like Mythos. Jaya gives us some insight into how this all works and why they're different. We also learn about some scary new attacks that can be conducted on LLM models. Jaya was a ton of fun and filled with insights.
    The show notes and blog post for this episode can be found at
    https://opensourcesecurity.io/2026/2026-09-jaya-aisle
Meer Technologie podcasts
Over Open Source Security
Open Source Security is a media project to help showcase and educate on open source security. Our goal is to give the community a platform educate both developers and users on how open source security works. There's a lot of good work happening that doesn't get attention because there's no marketing department behind it, they don't have a developer relations team posting on LinkedIn every two hours. Let's focus on those people and teams then learn what they do and how they do it. The goal is to hear from the people doing the work, they know what's up, they have a lot to teach us. We just have to listen.
Podcast website

Luister naar Open Source Security, Bright Podcast en vele andere podcasts van over de hele wereld met de radio.net-app

Ontvang de gratis radio.net app

  • Zenders en podcasts om te bookmarken
  • Streamen via Wi-Fi of Bluetooth
  • Ondersteunt Carplay & Android Auto
  • Veel andere app-functies
Open Source Security: Podcasts in familie