Open Source Security

Open Source Security

Josh Bressers

English Technology Explicit
Episodes 532
Avg. Duration 33m
Activity Highly Active
Apple Rating 4.7 (40)
Since Sep 2016
Latest Episode Jun 2026

Outreach Signals

Features Guests

Publishing Details

Schedule
Weekly
Format
Episodic
Consistency
100%
Hosting
rss.libsyn.com

Contact & Outreach

About This Podcast

Open Source Security is a media project to help showcase and educate on open source security. Our goal is to give the community a platform educate both developers and users on how open source security works. There's a lot of good work happening that doesn't get attention because there's no marketing department behind it, they don't have a developer relations team posting on LinkedIn every two hours. Let's focus on those people and teams then learn what they do and how they do it. The goal is to hear from the people doing the work, they know what's up, they have a lot to teach us. We just have to listen.

Explore Statistics

Recent Episodes

Hacking your CI/CD with François Proulx

Jun 08, 2026 35m

Josh welcomes back François Proulx to talk about the absolute madness in the CI/CD universe right now. We also learn about François' new project SmokedMeat which is a tool to help you hack your own…

Open source verification with Sal Kimmich

Jun 01, 2026 31m

Josh chats with Sal Kimmich about the current state of everything, and what we can expect next. Sal has some incredible insight into what we can expect to see due to the current wave of security bugs…

Vulnerability disclosure with Casey Ellis

May 25, 2026 37m

Josh talks to Casey Ellis about why vulnerability disclosure is so hard, and also so important. Casey is one of the best in this space having been a Bugcrowd founder. There are few people with more…

F-Droid the open app store with Hans

May 18, 2026 36m

Josh talks to Hans-Christoph Steiner about F-Droid, the Free and Open Source Android App Repository. The way F-Droid works looks a lot like a Linux distribution which has some interesting security…

Open source is critical infrastructure with Kat Cosgrove

May 11, 2026 38m

Josh talks to Kat Cosgrove about a how companies should be treating open source more like their critical infrastructure than free stuff. Kat has a ton of knowledge about how the interactions between…

How to actually test a disaster plan with David Bernstein

May 04, 2026 34m

Josh and David finish up the disaster recovery and emergency planning trilogy. In this one David tells us how to test the plan he told us how to build in the last episode. There are some great ideas…

Open Source Pledge with Vlad-Stefan Harbuz

Apr 27, 2026 34m

Josh has a discussion with Vlad-Stefan Harbuz about the Open Source Pledge as well as his recent FOSDEM talk. The Open Source Pledge is all about trying to build a sustainable universe for open…

Building a plan for disaster with David Bernstein

Apr 20, 2026 39m

Josh welcomes back David Bernstein to talk about creating a disaster recover plan. It's a very timely topic given all the current events. There are more supply chain attacks and compromises than ever…

Open Source Malware with Paul McCarty

Apr 13, 2026 38m

Josh talks to Paul McCarty of Open Source Malware about ... open source malware. Paul explains why there aren't many good open source malware datasets. We discuss why the existing data is lacking for…

Package management challenges with Andrew Nesbitt

Apr 06, 2026 36m

Josh welcomes back Andrew Nesbitt to discuss some recent blog posts he wrote about the challenges of new ecosystems as well as challenges of no ecosystems like C. There aren't very many people who…

Open Source Security at scale with Michael Winser

Mar 30, 2026 42m

Josh talks to Michael Winser about a talk he gave at FOSDEM as well as his work on Alpha Omega at the Linux Foundation. Michael is approaching open source security in a way that nobody has ever tried…

2026 State of the Software Supply Chain with Brian Fox

Mar 23, 2026 35m

Josh chats with Brian Fox from Sonatype about their 2026 State of the Software Supply Chain report. Most of the number continue to grow at alarming rates, but there's some new interesting findings in…

MCP and Agent security with Luke Hinds

Mar 16, 2026 35m

Josh talks to Luke Hinds, CEO of Always Further, about MCP and agent security. We start out talking about Luke's new tool, nono which is a sandboxing tool that has AI agents in mind as a use case. We…

The State of OpenSSL for pyca/cryptography with Alex Gaynor and Paul Kehrer

Mar 09, 2026 33m

Josh talks to Paul Kehrer and Alex Gaynor, from the Python Cryptographic Authority. Alex and Paul recently published a statement discuss the challenges posed by modern OpenSSL. We discuss the…

Rust coreutils with Sylvestre Ledru

Mar 02, 2026 31m

Josh talks to Sylvestre Ledru about the Rust coreutils project. We've been using GNU coreutils for decades now, and the goal of Rust coreutils is to rewrite these utilities in Rust. The primary…

Goose and the Agentic AI Foundation with Brad Axen

Feb 23, 2026 29m

Josh chats with Brad Axen from Block about his creation Goose as well as the Agentic AI Foundation (AAIF). I am quite skeptical of many AI claims, but Brad has a very pragmatic view about where…

The Global Vulnerability Intelligence Platform with Olle E. Johansson

Feb 16, 2026 34m

Josh chats with Olle E. Johansson about the Global Vulnerability Intelligence Platform (GVIP). It's no secret the current vulnerability systems are reaching a breaking point. Olle is one of the few…

Digital Sovereignty and Nextcloud with Frank Karlitschek

Feb 09, 2026 32m

Josh talk to the founder and CEO of Nextcloud, Frank Karlitschek about digital sovereignty. There's a lot of attention lately around digital sovereignty and often that conversation also includes…

The Art of Crisis Management with David Bernstein

Feb 02, 2026 35m

Josh talks to David Bernstein about the world of crisis management and business continuity. David is a certified emergency manager and tell us about preparing for both digital and physical…

WTF is a passkey with William Brown

Jan 26, 2026 1h 2m

William Brown is back! This time Josh chats with him about Passkeys. WTF are they? A Passkey is a form of multi factor authentication, but it's not super obvious what that really means. William does…

Frequently Asked Questions

How many episodes does Open Source Security have?

Open Source Security has published 532 episodes since September 2016, covering topics in Technology.

Is Open Source Security still active?

Open Source Security is currently highly active with new episodes weekly. Average episode length is 33m.

How do I contact Open Source Security for sponsorship or guest appearances?

Sign up on Grep.FM to access contact details for Open Source Security, including email and social media links.

Similar Podcasts