Podcast Index

Podcasts

Explora podcasts por categoría, abre episodios recientes y descarga audio para escucharlo sin conexión.

Open Source Security

Tecnología

Open Source Security

Josh Bressers

AIBOM, CBOM, and HBOM with Allan Friedman

June 28, 2026 7:00pm 34 min

Josh chats with Allan Friedman about all things Bill of Materials. Allan did a ton of work to help turn SBOM into what it is today. He has many thoughts and ideas around the new types of BOMs, a concept he's calling the ...

Packagist and Composer security with Jordi Boggiano

June 21, 2026 7:00pm 34 min

Josh welcomes Jordi Boggiano the lead maintainer of Composer and Packagist to explain the truckload of security features they've recently added. Packagist is the PHP package registry, Composer is the dependency manager f...

Sustaining Open VSX with Mike and Thabang

June 14, 2026 7:00pm 36 min

Josh welcomes Mike Milinkovich and Thabang Mashologu from the Eclipse Foundation to talk about their new managed Open VSX registry. This is the first open source package registry to create a commercial operation for larg...

Hacking your CI/CD with François Proulx

June 07, 2026 7:00pm 35 min

Josh welcomes back François Proulx to talk about the absolute madness in the CI/CD universe right now. We also learn about François' new project SmokedMeat which is a tool to help you hack your own CI/CD. When Josh spoke...

Open source verification with Sal Kimmich

May 31, 2026 7:00pm 31 min

Josh chats with Sal Kimmich about the current state of everything, and what we can expect next. Sal has some incredible insight into what we can expect to see due to the current wave of security bugs and incidents. There...

Vulnerability disclosure with Casey Ellis

May 24, 2026 7:00pm 37 min

Josh talks to Casey Ellis about why vulnerability disclosure is so hard, and also so important. Casey is one of the best in this space having been a Bugcrowd founder. There are few people with more experience and insight...

F-Droid the open app store with Hans

May 17, 2026 7:00pm 36 min

Josh talks to Hans-Christoph Steiner about F-Droid, the Free and Open Source Android App Repository. The way F-Droid works looks a lot like a Linux distribution which has some interesting security challenges, but also so...

Open source is critical infrastructure with Kat Cosgrove

May 10, 2026 7:00pm 38 min

Josh talks to Kat Cosgrove about a how companies should be treating open source more like their critical infrastructure than free stuff. Kat has a ton of knowledge about how the interactions between companies and open so...

How to actually test a disaster plan with David Bernstein

May 03, 2026 7:00pm 34 min

Josh and David finish up the disaster recovery and emergency planning trilogy. In this one David tells us how to test the plan he told us how to build in the last episode. There are some great ideas in this one about how...

Open Source Pledge with Vlad-Stefan Harbuz

April 26, 2026 7:00pm 34 min

Josh has a discussion with Vlad-Stefan Harbuz about the Open Source Pledge as well as his recent FOSDEM talk. The Open Source Pledge is all about trying to build a sustainable universe for open source maintainers. This t...

Building a plan for disaster with David Bernstein

April 19, 2026 7:00pm 39 min

Josh welcomes back David Bernstein to talk about creating a disaster recover plan. It's a very timely topic given all the current events. There are more supply chain attacks and compromises than ever before. There are so...

Open Source Malware with Paul McCarty

April 12, 2026 7:00pm 38 min

Josh talks to Paul McCarty of Open Source Malware about ... open source malware. Paul explains why there aren't many good open source malware datasets. We discuss why the existing data is lacking for many use cases. We o...

Package management challenges with Andrew Nesbitt

April 05, 2026 7:00pm 36 min

Josh welcomes back Andrew Nesbitt to discuss some recent blog posts he wrote about the challenges of new ecosystems as well as challenges of no ecosystems like C. There aren't very many people who look at multiple ecosys...

Open Source Security at scale with Michael Winser

March 29, 2026 7:00pm 42 min

Josh talks to Michael Winser about a talk he gave at FOSDEM as well as his work on Alpha Omega at the Linux Foundation. Michael is approaching open source security in a way that nobody has ever tried before. What if we c...

2026 State of the Software Supply Chain with Brian Fox

March 22, 2026 7:00pm 35 min

Josh chats with Brian Fox from Sonatype about their 2026 State of the Software Supply Chain report. Most of the number continue to grow at alarming rates, but there's some new interesting findings in this one. We discuss...

MCP and Agent security with Luke Hinds

March 15, 2026 7:00pm 35 min

Josh talks to Luke Hinds, CEO of Always Further, about MCP and agent security. We start out talking about Luke's new tool, nono which is a sandboxing tool that has AI agents in mind as a use case. We explain what MCP and...

The State of OpenSSL for pyca/cryptography with Alex Gaynor and Paul Kehrer

March 08, 2026 7:00pm 33 min

Josh talks to Paul Kehrer and Alex Gaynor, from the Python Cryptographic Authority. Alex and Paul recently published a statement discuss the challenges posed by modern OpenSSL. We discuss the statement and their relation...

Rust coreutils with Sylvestre Ledru

March 01, 2026 6:00pm 31 min

Josh talks to Sylvestre Ledru about the Rust coreutils project. We've been using GNU coreutils for decades now, and the goal of Rust coreutils is to rewrite these utilities in Rust. The primary reason isn't security, it'...

Goose and the Agentic AI Foundation with Brad Axen

February 22, 2026 6:00pm 29 min

Josh chats with Brad Axen from Block about his creation Goose as well as the Agentic AI Foundation (AAIF). I am quite skeptical of many AI claims, but Brad has a very pragmatic view about where things are today and where...

The Global Vulnerability Intelligence Platform with Olle E. Johansson

February 15, 2026 6:00pm 34 min

Josh chats with Olle E. Johansson about the Global Vulnerability Intelligence Platform (GVIP). It's no secret the current vulnerability systems are reaching a breaking point. Olle is one of the few people with a long ter...

Envía tu emisora ​​favorita

Completa el formulario de abajo. Asegúrate de seleccionar tanto País como Géneros.

Nombre
Categoría
Mantenga presionada la tecla Ctrl (Cmd en Mac) para seleccionar varios.
URL de transmisión
Logo (JPG, JPEG o PNG)

Contáctanos

Envíanos un mensaje abajo. Te responderemos en un plazo de 24 horas.

Asunto
Tu nombre
Correo electrónico
URL de la emisora o de la página
Mensaje
Cuanto es 5 más 5?
También adjuntamos tu país, navegador, página actual y algunos datos técnicos para ayudarnos a investigar.