Episode notes
Josh welcomes Josh Marpet for a discussion about abandoned open source packages. Josh Marpet has a foundation called Value Chain Risk Institute that has a report discussion how to start measuring if an open source package might be abandoned. There's a lot of data, but not a lot of groups using that data to help make informed decisions about using open source. VCRI is one of those places that's starting to do this. The show notes and blog post for this episode can be found at https://opensourcesecurity.io/2026/2026-07-VCRI-josh-marpet
Open Source Security
by Josh Bressers · English · Tech & Science
Open Source Security is a media project to help showcase and educate on open source security. Our goal is to give the community a platform educate both developers and users on how open source security works. There's a lot of good work happening that doesn't get attention because there's no…
More from Open Source Security
-
10 Aug 2026 · 35 min
Cleanup, Speedup, Levelup open source at e18e
Josh chats with James from e18e. This is a project that is working on improving Javascript packages by cleaning up, speeding up, and leveling up the dependencies. The way the e18e project handles this work is very human open source. It's all about building up connections and trust with the package communities, which is no small effort. James fills us in on what they're doing as well as how we can get involved. It's a truly amazing effort The show notes and blog post for this episode can be found at https://opensourcesecurity.io/2026/2026-08-e18e-james
-
3 Aug 2026 · 37 min
VulnCheck's State of Exploitation Report with Patrick Garrity
Josh chats with Patrick Garrity about the VulnCheck State of Exploitation 1H-2026 report. Patrick explains the current trends we are seeing around vulnerabilities right now. While the number of CVEs is way up, the number of actually exploited vulnerabilities isn't growing year over year. This tells us there is a lot of FUD and hype. We also ask where are all the vulnerabilities that project Glasswing found. They should be going public by now, but we're not seeing that play out in the data. The show notes and blog post for this episode can be found at…
-
27 Jul 2026 · 36 min
Securing critical infrastructure with Josh Corman
Open Source Security welcomes Josh Corman to talk about the challenges around securing our critical infrastructure. Specifically the discussion centers around our water supplies. There are a lot of really wild things happening right now with attacks like Volt Typhoon and Salt Typhoon. Josh has an amazing ability to make these sort of discussions easy to understand without spreading FUD. Josh also has suggestions for actions that need to be taken to help deal with these problems. It's not all technical solutions, there are non technical things we can do to help reduce the risk posed by our…
-
13 Jul 2026 · 33 min
Red Hat's Project Lightwell with Mo Duffy
Josh welcomes Mo Duffy from Red Hat to chat about project Lightwell. The idea is to leverage the resources and understanding Red Hat has built up over the years to help deal with the deluge of vulnerability reports that are overwhelming open source projects. Mo does a really good job of explaining why this is fundamentally a people problem, not a technology problem. But it's a people problem we can probably use technology to help. It will be interesting to see where Lightwell goes in the next few years. The show notes and blog post for this episode can be found at…
-
6 Jul 2026 · 33 min
Rust Foundation Maintainers Fund with Lori and Niko
Josh chats with Lori Lorusso and Niko Matsakis about the Rust Foundation Maintainers Fund. This is a new project the Rust Foundation has create to help fund Rust maintainers. It's a great discussion where Lori and Niko cover all the ways they expect to fund the maintainers which is never as easy as one initially expects. Funding open source is a huge topic right now, it sounds like the Rust Foundation has some great ideas. The show notes and blog post for this episode can be found at https://opensourcesecurity.io/2026/2026-07-rfmf-lori-niko
-
29 Jun 2026 · 35 min
AIBOM, CBOM, and HBOM with Allan Friedman
Josh chats with Allan Friedman about all things Bill of Materials. Allan did a ton of work to help turn SBOM into what it is today. He has many thoughts and ideas around the new types of BOMs, a concept he's calling the OmniBOM. Allan is always fun to chat with and he brings a ton of knowledge and advice. The show notes and blog post for this episode can be found at https://opensourcesecurity.io/2026/2026-06-allan-omnibom
-
5 Oct 2026 · 32 min
Dependency attacks in 2026 with James Matchett
Josh chats with James Matchett from Cloudsmith about a new report they put out. It has some scary looking statistics in it about how organizations are using dependencies. There are some surprising numbers in there, but the story is really one of defense in depth. There's no single thing we can do here, it's all about knowing what you have every step of the way. It's easy to say, but certainly a challenge to do right. James is a ton of fun to chat with and filled with energy and knowledge. The show notes and blog post for this episode can be found at…
-
28 Sep 2026 · 35 min
Sovereignty, policy, and OpenUK with Amanda Brock
Josh welcomes Amanda Brock from OpenUK to chat about sovereignty, policy, open source, and a whole host of other topics. Amanda has front row seat into how sovereignty decisions can affect a county and its open source. It seems sometimes like open source is a global phenomenon, but there are always country wide considerations. This is what the OpenUK is doing in the UK. The discussion is great and the things the OpenUK is dealing with will affect many of us moving forward, even if we would prefer to ignore our digital borders. The show notes and blog post for this episode can be found at…
-
21 Sep 2026 · 33 min
The curl summer of Bliss with Daniel and Stefan
Josh chats with Daniel and Stefan from curl about their summer of bliss. Curl stopped taking vulnerability reports for a month and nothing much happened really. Daniel and Stefan have a really pragmatic view of all the new LLM powered vulnerability detection tools. The cost of finding a vulnerability has dropped dramatically, but the cost of fixing those bugs hasn't changed. Taking some time off is important for anyone in the middle of these reports. Daniel and Stefan have some great experience and ideas on how to make this all happen. It's great advice for anyone working on software, not…
-
14 Sep 2026 · 41 min
CRA vulnerability reporting with Daniel Thompson
Josh welcomes back Daniel Thompson to explain what just happened regarding vulnerability reporting and the CRA on September 11. The very first CRA requirements kicked in, but what does it really mean? Daniel explains it's not too bad. There are plenty more requirements coming, but this one feels very approachable. The show notes and blog post for this episode can be found at https://opensourcesecurity.io/2026/2026-09-daniel-cra
