PLAY PODCASTS
LI_S02E47_Tied_up_and_shackled

LI_S02E47_Tied_up_and_shackled

Linux Inlaws · The Linux Inlaws

October 2, 2025

Audio is streamed directly from the publisher (archive.org) as published in their RSS feed. Play Podcasts does not host this file. Rights-holders can request removal through the copyright & takedown page.

Show Notes

Tied up, shackled and then some: In contrast what you may be thinking after this intro, in this episode Martin and Chris take a closer look at an obscure concept known not only in esoteric circles as the software supply chain (chain being the keyword here). Once only appreciated by the inner circle of a small group of level-eight magicians, this concepts has now entered mainstream and is considered instrumental not only in the area creating and maintaining large scale codebases possibly clocking up a few million lines of code. This especially becomes important when a codebase largely relies on FLOSS components commonly downloaded from the internet. Relying on these components may cause a security issue if not handled with caution as not only the recent xz-utils incident (where possibly a nation-state actor) managed to infiltrate a popular compression library virtually used everywhere. So if you're interested in the security of your builds and applications, this is another episode you don't want to miss. <p>Links</p> <ul><li>Left-pad incident: <a href="https://en.wikipedia.org/wiki/Npm_left-pad_incident" target=_blank>https://en.wikipedia.org/wiki/Npm_left-pad_incident</a></li> <li>Lucene library: <a href="https://lucene.apache.org/core" target=_blank>https://lucene.apache.org/core</a></li> <li>Open source licenses episode (S01E36): <a href="https://archive.org/details/hpr3399" target=_blank>https://archive.org/details/hpr3399</a></li> <li>SBOMs: <a href="https://about.gitlab.com/blog/the-ultimate-guide-to-sboms" target=_blank>https://about.gitlab.com/blog/the-ultimate-guide-to-sboms</a></li> <li>XZ Utils backdoor: <a href="https://en.wikipedia.org/wiki/XZ_Utils_backdoor" target=_blank>https://en.wikipedia.org/wiki/XZ_Utils_backdoor</a></li> <li>OpenSSF's tools (not just SBOMs): <a href="https://openssf.org/projects" target=_blank>https://openssf.org/projects</a></li> <li>Autotools: <a href="https://www.gnu.org/software/automake/manual/html_node/Autotools-Introduction.html" target=_blank>https://www.gnu.org/software/automake/manual/html_node/Autotools-Introduction.html</a></li> <li>SPDX: <a href="https://spdx.dev" target=_blank>https://spdx.dev</a></li> <li>CycloneDX: <a href="https://cyclonedx.org" target=_blank>https://cyclonedx.org</a></li> <li>valkey-search: <a href="https://github.com/valkey-io/valkey-" target=_blank>https://github.com/valkey-io/valkey-</a></li> <li>Thunderbolts: <a href="https://www.marvel.com/movies/thunderbolts" target=_blank>https://www.marvel.com/movies/thunderbolts</a></li> </ul>