Episode · Open Source Security
Building a plan for disaster with David Bernstein
20 Apr 2026 · 39 min
Episode · Open Source Security
20 Apr 2026 · 39 min
Josh welcomes back David Bernstein to talk about creating a disaster recover plan. It's a very timely topic given all the current events. There are more supply chain attacks and compromises than ever before. There are some great resources for this planning, but as David tells us, it's really not that hard to put some plans together. It's easy to over-plan, David gives some great tips on getting started with our planning for an eventual incident. The show notes and blog post for this episode can be found at https://opensourcesecurity.io/2026/2026-04-disaster-planning-david-bernstein/
by Josh Bressers · English · Tech & Science
Open Source Security is a media project to help showcase and educate on open source security. Our goal is to give the community a platform educate both developers and users on how open source security works. There's a lot of good work happening that doesn't get attention because there's no…
11 May 2026 · 38 min
Josh talks to Kat Cosgrove about a how companies should be treating open source more like their critical infrastructure than free stuff. Kat has a ton of knowledge about how the interactions between companies and open source communities can work well, or not work at all. Kat's time on the Kubernetes Release Team. We touch on how a project like Kubernetes is super successful, while another, Ingress NGINX, was not. It's a super insightful discussion with a ton of lessons and advice for everyone. The show notes and blog post for this episode can be found at…
4 May 2026 · 35 min
Josh and David finish up the disaster recovery and emergency planning trilogy. In this one David tells us how to test the plan he told us how to build in the last episode. There are some great ideas in this one about how to test the process not the people. How to construct the plan, and even some tips to go from a plan to some actual real world testing. It's another episode filled with great and practical advice. The show notes and blog post for this episode can be found at https://opensourcesecurity.io/2026/2026-05-testing-the-plan-david-bernstein/
27 Apr 2026 · 35 min
Josh has a discussion with Vlad-Stefan Harbuz about the Open Source Pledge as well as his recent FOSDEM talk. The Open Source Pledge is all about trying to build a sustainable universe for open source maintainers. This ties into Vlad's FOSDEM talk which was all about the challenge of just knowing what open source you are using. The importance of trying to make open source sustainable is a really important topic, but it's also a really hard topic. Vlad helps explain all of this as well as some ideas for the solving this in the future. The show notes and blog post for this episode can be found…
13 Apr 2026 · 38 min
Josh talks to Paul McCarty of Open Source Malware about ... open source malware. Paul explains why there aren't many good open source malware datasets. We discuss why the existing data is lacking for many use cases. We of course touch on AI and the malware in skills problems and challenges. It's a fun discussion with a lot of new and interesting problems we all have to deal with. The show notes and blog post for this episode can be found at https://opensourcesecurity.io/2026/2026-04-open-source-malware-paul-mccarty/
6 Apr 2026 · 36 min
Josh welcomes back Andrew Nesbitt to discuss some recent blog posts he wrote about the challenges of new ecosystems as well as challenges of no ecosystems like C. There aren't very many people who look at multiple ecosystems in the way Andrew does. He has thoughts on why it's so hard to create a new ecosystem as well as some of the reasons we don't see a C language ecosystem. Andrew has a ton of interesting ideas and insight for us about both existing, new, and nonexistent ecosystems. The show notes and blog post for this episode can be found at…
30 Mar 2026 · 43 min
Josh talks to Michael Winser about a talk he gave at FOSDEM as well as his work on Alpha Omega at the Linux Foundation. Michael is approaching open source security in a way that nobody has ever tried before. What if we could fund some really big, really hard projects? It's not cheap or easy, but he's getting it done. We spend a lot of the time discussing package registries, which are a huge topic. Michael is doing some amazing work helping package registries which is the first step in a very long journey. The show notes and blog post for this episode can be found at…
5 Oct 2026 · 32 min
Josh chats with James Matchett from Cloudsmith about a new report they put out. It has some scary looking statistics in it about how organizations are using dependencies. There are some surprising numbers in there, but the story is really one of defense in depth. There's no single thing we can do here, it's all about knowing what you have every step of the way. It's easy to say, but certainly a challenge to do right. James is a ton of fun to chat with and filled with energy and knowledge. The show notes and blog post for this episode can be found at…
28 Sep 2026 · 35 min
Josh welcomes Amanda Brock from OpenUK to chat about sovereignty, policy, open source, and a whole host of other topics. Amanda has front row seat into how sovereignty decisions can affect a county and its open source. It seems sometimes like open source is a global phenomenon, but there are always country wide considerations. This is what the OpenUK is doing in the UK. The discussion is great and the things the OpenUK is dealing with will affect many of us moving forward, even if we would prefer to ignore our digital borders. The show notes and blog post for this episode can be found at…
21 Sep 2026 · 33 min
Josh chats with Daniel and Stefan from curl about their summer of bliss. Curl stopped taking vulnerability reports for a month and nothing much happened really. Daniel and Stefan have a really pragmatic view of all the new LLM powered vulnerability detection tools. The cost of finding a vulnerability has dropped dramatically, but the cost of fixing those bugs hasn't changed. Taking some time off is important for anyone in the middle of these reports. Daniel and Stefan have some great experience and ideas on how to make this all happen. It's great advice for anyone working on software, not…
14 Sep 2026 · 41 min
Josh welcomes back Daniel Thompson to explain what just happened regarding vulnerability reporting and the CRA on September 11. The very first CRA requirements kicked in, but what does it really mean? Daniel explains it's not too bad. There are plenty more requirements coming, but this one feels very approachable. The show notes and blog post for this episode can be found at https://opensourcesecurity.io/2026/2026-09-daniel-cra