DiscoverOpen Source Security
Open Source Security
Claim Ownership

Open Source Security

Author: Josh Bressers

Subscribed: 822Played: 31,643
Share

Description

Open Source Security is a media project to help showcase and educate on open source security. Our goal is to give the community a platform educate both developers and users on how open source security works.

There's a lot of good work happening that doesn't get attention because there's no marketing department behind it, they don't have a developer relations team posting on LinkedIn every two hours. Let's focus on those people and teams then learn what they do and how they do it. The goal is to hear from the people doing the work, they know what's up, they have a lot to teach us. We just have to listen.
547 Episodes
Reverse
Josh chats with Daniel and Stefan from curl about their summer of bliss. Curl stopped taking vulnerability reports for a month and nothing much happened really. Daniel and Stefan have a really pragmatic view of all the new LLM powered vulnerability detection tools. The cost of finding a vulnerability has dropped dramatically, but the cost of fixing those bugs hasn't changed. Taking some time off is important for anyone in the middle of these reports. Daniel and Stefan have some great experience and ideas on how to make this all happen. It's great advice for anyone working on software, not just open source. The show notes and blog post for this episode can be found at https://opensourcesecurity.io/2026/2026-09-curl-bliss-stefan-daniel  
Josh welcomes back Daniel Thompson to explain what just happened regarding vulnerability reporting and the CRA on September 11. The very first CRA requirements kicked in, but what does it really mean? Daniel explains it's not too bad. There are plenty more requirements coming, but this one feels very approachable. The show notes and blog post for this episode can be found at https://opensourcesecurity.io/2026/2026-09-daniel-cra    
Josh chats with Jaya Baloo from AISLE about their vulnerability scanner. If you follow open source vulnerabilities AISLE is a name you've seen popping up recently. They have a vulnerability scanner that is outperforming most of the existing scanners like Mythos. Jaya gives us some insight into how this all works and why they're different. We also learn about some scary new attacks that can be conducted on LLM models. Jaya was a ton of fun and filled with insights. The show notes and blog post for this episode can be found at https://opensourcesecurity.io/2026/2026-09-jaya-aisle    
Josh chats with Erik Möller from the Sovereign Tech Agency about what they're doing. The Sovereign Tech Agency is doing some amazing work around funding open source maintainers and projects. Eric breaks down what they're doing, how it works, and how you can apply for funding. We even learn about some similar projects happening in the EU. Hopefully in the near future we will see the work Sovereign Tech Agency is doing happening in every country. The show notes and blog post for this episode can be found at https://opensourcesecurity.io/2026/2026-08-erik-sta  
Josh chats with Paul Asadoorian about a tool he wrote called fettle and a recent report Paul published on CVEs. Fettle is a tool to help update and manage Linux systems. The big sell on this one is checking if your firmware is out of date. We then talk about a report Paul created that doesn't obsess over CVEs, but rather the vendor updates. It makes more sense to worry about advisories as those are actionable, where CVEs often are not. It's a great chat and Paul is a legend in the industry. The show notes and blog post for this episode can be found at https://opensourcesecurity.io/2026/2026-08-paul-fettle-cve  
loading
Comments