PLAY PODCASTS
Open Source Security

Open Source Security

Josh Bressers · Open Source Security

536 episodesEN

Show overview

Open Source Security has been publishing since 2016, and across the 10 years since has built a catalogue of 536 episodes. That works out to roughly 310 hours of audio in total. Releases follow a weekly cadence.

Episodes typically run twenty to thirty-five minutes — most land between 31 min and 37 min — and the run-time is fairly consistent across the catalogue. It is catalogued as a EN-language Technology show.

The show is actively publishing — the most recent episode landed 4 weeks ago, with 26 episodes already out so far this year. The busiest year was 2020, with 74 episodes published.

Episodes
536
Running
2016–2026 · 10y
Median length
33 min
Cadence
Weekly

From the publisher

Open Source Security is a media project to help showcase and educate on open source security. Our goal is to give the community a platform educate both developers and users on how open source security works. There's a lot of good work happening that doesn't get attention because there's no marketing department behind it, they don't have a developer relations team posting on LinkedIn every two hours. Let's focus on those people and teams then learn what they do and how they do it. The goal is to hear from the people doing the work, they know what's up, they have a lot to teach us. We just have to listen.

Latest Episodes

View all 536 episodes

AIBOM, CBOM, and HBOM with Allan Friedman

Jun 29, 202634 min

Packagist and Composer security with Jordi Boggiano

Jun 22, 202634 min

Sustaining Open VSX with Mike and Thabang

Jun 15, 202636 min

Hacking your CI/CD with François Proulx

Jun 8, 202635 min

Open source verification with Sal Kimmich

Jun 1, 202631 min

Vulnerability disclosure with Casey Ellis

May 25, 202637 min

F-Driod the open app store with Hans

May 18, 202636 min

Open source is critical infrastructure with Kat Cosgrove

May 11, 202638 min

How to actually test a disaster plan with David Bernstein

May 4, 202634 min

Open Source Pledge with Vlad-Stefan Harbuz

Apr 27, 202634 min

Building a plan for disaster with David Bernstein

Apr 20, 202639 min

Open Source Malware with Paul McCarty

Apr 13, 202638 min

Package management challenges with Andrew Nesbitt

Apr 6, 202636 min

Open Source Security at scale with Michael Winser

Josh talks to Michael Winser about a talk he gave at FOSDEM as well as his work on Alpha Omega at the Linux Foundation. Michael is approaching open source security in a way that nobody has ever tried before. What if we could fund some really big, really hard projects? It's not cheap or easy, but he's getting it done. We spend a lot of the time discussing package registries, which are a huge topic. Michael is doing some amazing work helping package registries which is the first step in a very long journey. The show notes and blog post for this episode can be found at https://opensourcesecurity.io/2026/2026-03-michael-winser/

Mar 30, 202642 min

2026 State of the Software Supply Chain with Brian Fox

Josh chats with Brian Fox from Sonatype about their 2026 State of the Software Supply Chain report. Most of the number continue to grow at alarming rates, but there's some new interesting findings in this one. We discuss end of life and open source which is tough to define. We touch on what using AI with open source dependencies looks like (and why it's broken), and we discuss the challenge of upgrading your open source dependencies in a way that doesn't break everything. It's a great report and great discussion. The show notes and blog post for this episode can be found at https://opensourcesecurity.io/2026/2026-03-SOTSSC-Brian-Fox/

Mar 23, 202635 min

MCP and Agent security with Luke Hinds

Josh talks to Luke Hinds, CEO of Always Further, about MCP and agent security. We start out talking about Luke's new tool, nono which is a sandboxing tool that has AI agents in mind as a use case. We explain what MCP and agents are doing as well as why it's so hard to secure them. It's not impossible, but it's not simple either. We end the show by discussing some of the more human aspects to security and how history may be repeating itself with security folks laughing at new users who don't know any better. The show notes and blog post for this episode can be found at https://opensourcesecurity.io/2026/2026-03-mcp-agent-luke/

Mar 16, 202635 min

The State of OpenSSL for pyca/cryptography with Alex Gaynor and Paul Kehrer

Josh talks to Paul Kehrer and Alex Gaynor, from the Python Cryptographic Authority. Alex and Paul recently published a statement discuss the challenges posed by modern OpenSSL. We discuss the statement and their relationship with OpenSSL. We chat about some of the current features in cryptography, as well as some of what's coming in the future. It's a fun conversation that hits on a lot of great points. The show notes and blog post for this episode can be found at https://opensourcesecurity.io/2026/2026-03-cryptography-alex-paul/

Mar 9, 202633 min

Rust coreutils with Sylvestre Ledru

Josh talks to Sylvestre Ledru about the Rust coreutils project. We've been using GNU coreutils for decades now, and the goal of Rust coreutils is to rewrite these utilities in Rust. The primary reason isn't security, it's to modernize the code and attract new contributors. Sylvestre discusses with quite pleasant relationship with the GNU coreutils developers, some of the challenges in the project. What Ubuntu using this by default meant, and also gives us some things to watch for in the future. It's a super fun discussion about why Rust is not only awesome, but also the future. The show notes and blog post for this episode can be found at https://opensourcesecurity.io/2026/2026-03-rust-coreutils-sylvestre-ledru/

Mar 2, 202631 min

Goose and the Agentic AI Foundation with Brad Axen

Josh chats with Brad Axen from Block about his creation Goose as well as the Agentic AI Foundation (AAIF). I am quite skeptical of many AI claims, but Brad has a very pragmatic view about where things are today and where we might see them head. Donating Goose to the AAIF is great news as well as seeing MCP and AGENTS.MD in the foundation. We discuss how to deal with the problem of raising up junior developers, challenges of AI PRs, and some thoughts on how to get started if you're interested in AI development. The show notes and blog post for this episode can be found at https://opensourcesecurity.io/2026/2026-02-goose-aaif-brad-axen/

Feb 23, 202629 min

The Global Vulnerability Intelligence Platform with Olle E. Johansson

Josh chats with Olle E. Johansson about the Global Vulnerability Intelligence Platform (GVIP). It's no secret the current vulnerability systems are reaching a breaking point. Olle is one of the few people with a long term vision instead of trying to just fix the short term problems. His GVIP ideas are very good, but it's a community effort and needs our help. Give it a listen and if it sounds interesting, come help us out! The show notes and blog post for this episode can be found at https://opensourcesecurity.io/2026/2026-02-GVIP-olle-johansson/

Feb 16, 202634 min
This work is licensed under the Creative Commons Attribution 4.0 International License. To view a copy of this license, visit http://creativecommons.org/licenses/by/4.0/ or send a letter to Creative Commons, PO Box 1866, Mountain View, CA 94042, USA.