Josh chats with Erin Schnabel and Rob Nalen about a new effort from Commonhaus and HeroDevs for maintaining end of life open source. This project, the Open Source Sustainability Initiative is a clever way to bring corporations and projects together for maintenance of new and old versions of open source projects. This is pretty new territory for everyone, this project is worth keeping an eye on because it has a very small scope initially. Other similar ideas have gigantic scopes that are almost certainly too large.

This episode is also available as a podcast, search for “Open Source Security” on your favorite podcast player.

Episode Transcript

Josh Bressers (00:00) Today, open source security is talking to Erin Schnabel, Chair of Commonhaus and Rob Nalen the chief operating officer of HeroDevs. Erin and Rob are here to talk about a a very interesting, I think, kind of clearing house for vulnerabilities and and just an effort you’re you’re putting together. So I will let the two of you take it away. Erin, I’ll let you do your intro first, and we’ll let Rob go, and we’ll kind of go from there because I feel like

There’s a lot of clearinghouse things going on right now, but this one feels different and I think it it’s pretty good.

Erin Schnabel (00:30) Yeah, so I don’t know that I would necessarily call it what we’re doing a clearinghouse per se.

Josh Bressers (00:35) Okay, that’s fair.

Erin Schnabel (00:37) it’s well, it’s fine. So like Commonhaus it’s one of those things where you realize I really wanted to start an open source foundation. Why did I do that?

Josh Bressers (00:47) Yeah.

Erin Schnabel (00:48) for me personally. but I realized talking to some of my friends. So I’ve been in the Java community for almost 30 years. So my roots go way back. And

I started to realize there’s a whole population of people who are they run their projects the way they want to run them. they’re very good at it. If you go and look at anything with these vulnerabilities that as ever you know that we’re talking about in the ether right now, solo maintainers, maybe three people at most. They’ve been running their projects forever, they know what they’re doing. and so for a lot of those, some of whom are my friends, it’s like, well

This foundation doesn’t work for me because XYZ. This foundation doesn’t work for me because XYZ. and so I wanted to put together a foundation f basically for them. Like it’s a place where we can work together, where I can start holding assets for you, with the idea being that it should be normal to pass the baton. Right? Everybody at some point ends up being dumb, like done with it. It’s dumb. so they end up being like they’re they should be allowed to be finished.

And so the whole idea behind Commonhaus is I will help you when you’re done. How do we find the next person? How do we make sure that that transition is easy? How do we make sure that your library that everybody loves is maintained when you’re done working on it? that’s kind of the genesis of where that came from. and working with Rob, what we’ve tried to do is like it’s almost a different spin on that. It’s not just when you’re done maintaining the library forever.

It’s what happens when you’re done maintaining that version that you don’t want to think about anymore because you have the new one and you don’t want to have both in your head at once, and you only have time on the weekends anyway, because it’s just you. So you don’t want to think about that one on that version that you don’t want to deal with anymore. So that’s like the that’s the skinny.

Josh Bressers (02:47) All right, Rob, who are you and what does HeroDevs

Rob Nalen (02:48) Yeah.

Josh Bressers (02:50) do?

Rob Nalen (02:50) Yeah, yeah. So I’m the Chief Operating Officer and super excited to be here. So what HeroDevs does is we provide end of life support for open source software, like Erin was was talking about. And what we’ve found is that enterprises in particular, they they rely on on open source software. They’ve built their internal infrastructure, their applications that they’re generating revenue off of, and they’ve gone into this AI toolbox and they keep on pulling it in. And what’s happened now when you look at, you know

Black duck surveys, the average application has like 1200 open source dependencies. And so keeping those up to date is a task in and of itself. It’s really, really tough, let alone doing that, and then trying to work on you know efficiencies and you know deal with the latest and greatest AI. And so what HeroDevs does, and we started back in 2018, is we give enterprises the ability to elongate that product lifecycle for those open source components, and so they can decide when to

modernize and most importantly enterprises they’re subject to a litany of compliance and and industry and regulatory standards and without upgrading they could they could end up being out of compliance and so things like pci things like HIPAA FedRAMP and then you know those those are those are examples of some regulatory and some industry standards but more importantly what we’re finding especially due to AI we can get into that in a minute is there’s more

More compliance standards arising out of the EU and the United States geared at ensuring that infrastructure is protected. And so things like Dora, NIS2 EU CRA, which which hits reporting and auditing standards in September of this year alone, those are those are extremely important for enterprises in order to secure their environment. And so HeroDevs comes in and says: great, we will provide you with that.

That ongoing monitoring and CVE remediation across the most mission critical open source software.

Josh Bressers (04:57) Yeah. Okay. So let’s talk about what that means. So I’ve I’ve got your website pulled up here. You have something called the Open Source Sustainability Initiative, which is a mouthful. And and Erin, I

Erin Schnabel (05:08) Ha ha.

Josh Bressers (05:08) I incorrectly referred to this as a clearinghouse for vulnerabilities, which you are right, I would say it is not, because it’s very tightly scoped, which is very cool. So I will

Erin Schnabel (05:16) Yes.

Josh Bressers (05:17) let the two of you argue about who wants to describe what this is and what you’re doing, but tell us about the can I call it the OSSI? Is that acceptable? Okay, let’s call it that.

Erin Schnabel (05:24) Absolutely. I think I put the acronym

right there because it’s really long. But I want Rob to talk about it because he named it. Nope,

Rob Nalen (05:27) That is. That’s it. Erin, I’ll I’ll defer to you.

Erin Schnabel (05:32) he named it.

Rob Nalen (05:33) I named it. Alright. Alright. So

I named it. That’s fine. So so we’ve partnered with, you know, obviously Commonhaus. We’ve also partnered with the OpenJS Foundation, the Drupal Association, and a bunch of other open source projects, Bootstrap View. And the what we try to do with these open source communities is is and to Erin’s point, we want to to partner with the communities and we want to do two things. Number one, we want to directly invest into those communities so that they can continue to do the best.

Best things that they work on, which is how do they create new stuff, right? And so these open source communities for a long time, they they don’t they they can’t work on new stuff while also trying to deal with the backlog of enterprises raising their hand and saying, hey, we’re still relying on this. And so we want to we want to partner, and by doing so, we either provide a revenue share or we provide a direct commitment of investment. And we do that through the open source sustainability fund that Heroes.

Devs launched last year where we’re pledging 20 million dollars to support open source software and so that’s the first part is we want to we want to invest in the communities and we do we we make sure that they find value out of the enterprises that are still relying on that that end of life open source the second thing we want to do is as we’re composed of really well-versed maintainers or or you know just users of these open source communities we want to actually

Help the communities where we can. So we don’t want to just come in and say, here’s some investment, good luck. We actually want to help them with how do we ensure that there’s not any, you know, zero day zero vulnerabilities that are arising. How can we help them with current supported versions that maybe we find a vulnerability that’s impacting a legacy version? How do we help out? And so we’ve partnered with Commonhaus to identify the open source sustainability initiative, right? Is how do we build a program to ensure

that when someone comes to these projects, whether it’s Hibernate Jackson or Quarkus, if I’m an enterprise, who can I go to in order to receive this ongoing CVE remediation? And they the the open source communities themselves, they can point to hero devs. And so that that’s the idea of the OSSI.

Erin Schnabel (07:53) Yeah. It for for me it’s about two things. There is the I’m the relationship that is being formed between the projects and HeroDevs is very constructive, right, and helpful. and I’m hoping like right now we are starting with three projects. So it’s not like all of the Commonhaus projects. but I’m hoping over time like we end up with more of our projects involved as the support matures.

as the program matures, I guess you’d say. the weird thing with Commonhaus, y weird, unique, is that every project really is their own. It’s their choice to opt in. Like they are very much masters of their own destiny, importantly. but like I know Jackson especially is happy for the help. Right there. Like it’s that’s a that’s a very small team trying to maintain a library that literally the entire

Java ecosystem uses.

Josh Bressers (08:53) I know, right?

Erin Schnabel (08:56) so that for ex that’s a really good example of of a very functional relationship, I think, I would say.

Josh Bressers (09:03) Okay, so let me ask a question then. So why why work with someone like Commonhaus instead of going directly to the projects, Rob?

Rob Nalen (09:12) Yeah, it’s it’s a great question. So a lot of these these projects to w what what the great work that Erin’s doing is helping organize and and she probably downplays it, right? Is helping organize the projects because these these a lot of these folks they have day jobs. They have things that they they have to do. And whether we like it or not, there’s there’s an infrastructure that has to be built. If you’re a non profit, right, you have to have as as Erin knows, you have to work with attorneys, you have to work with accountants, you have to do this type of stuff. And so

These consortiums, what what I found is they’re really powerful at enabling folks to just work on what they need to, and the amazing people like Erin and others, they help pull everything together, right? And so we do work from time to time with various individual projects and we’ll go and meet with those folks, but where we find large communities, that’s that to me is where that ecosystem play is huge because we know the enterprises are coming in and they’re visiting that ecosystem, whether it’s the Linux Foundation, whether it’s OpenJS.

Or whether it’s Commonhaus, right? We want there to be you know, this this sort of universal layer of support across all of those projects. And so you’ll see us from time to time. I think there’s Bootstrap’s probably a great example. We’ve partnered with them. you can check out and see that that we’re supporting legacy versions there. But in general, we really want to work with with these consortiums to make sure that they’re they’re supported across the entire portfolio.

Josh Bressers (10:37) Okay, I have one more housekeeping question before we get into some of the meat and potatoes here. And this this one’s for you, Erin, is if I’m a project, what is like what is the value? Why would I want to work with something someone like,

Commonhaus? Like what’s the value in that versus just kind of staying a random repo on GitHub forever?

Erin Schnabel (10:56) This is a hard one because sometimes when I talk to project leaders, that’s exactly the attitude that I have. Why can’t I just remain a GitHub thing forever? And the answer is if you don’t want to, you don’t have to, and that’s great. I you know, I can’t I’m not gonna try to sell them on this, but for most projects, for example, I’m handling trademarks, registered or not. I do handle legal questions if they have legal questions. I have a

Like if they want to take donations, guess what I have the ability to do for them? Is accept donations. We can do expense reports. We could do s stickers. We could do like there’s little things that we can do to help you know, individual project leaders like maintain their stuff. The biggest thing though is we do take and I do it in there’s ways that I do it to be non-invasive, right? But we do have administrative access to our

project repositories, right? And I try to main to do it in a secure way that reduces blast radius and like all the stuff that you know, that you have to think about these days. But the general gist is mitigating the bus factor, for one. and and really just making sure you already have the support that you want for when you want to bring on the next generation. Because it I mean let’s think about this honestly, right? When were app servers born?

Nineteen eighty five, nineteen ninety-six, a whole bunch of our libraries are about that age. Guess who’s about to tap out? Like

Josh Bressers (12:34) Yep. Yep.

Erin Schnabel (12:35) we’re at the stage where the generations are gonna roll over, right? Like that’s just for the Java ecosystem, that’s where we are. And speaking of people who are maintaining old versions of libraries, ChainGuard, a little while ago, had a really good blog post.

They have a whole series. This shit is hard, which is just the best title for a blog post

Josh Bressers (12:56) Yes.

Erin Schnabel (12:57) ever. but they were talking about, I forget the exact title, but it was like Java archaeology at scale or something. It was like what they’re doing to try to support the Java ecosystem. And the reason I found that blog post so interesting is because they have a good like, we’re gonna try to support we’re gonna start with this version of s you know, pick a package, probably a spring one, let’s be honest.

And then there’s how it cascades to like all of its dependencies and you end up with this like great big tree. but they started talking about the challenges that they had just to build this stuff, and how even if you have the manifest data in Maven Central, sometimes it’s inaccurate, sometimes it’s pretend, sometimes it points to commits that don’t exist, and sometimes stuff is in like Google Code doesn’t exist anymore. Sometim like so sometimes the source is just gone.

And so part of what I’m trying to set up here is to have something help you so that that part doesn’t happen, right? So that this library you’ve poured your heart and soul in doesn’t end up being abandoned where, right? Like w what happens to it when you’re done with it? Because that should be a question all of us are asking when you have people maintaining this stuff or creating a library to scratch an itch on the weekend.

Josh Bressers (14:13) And and I’ve spoken in the past. I just talked to a guy named Josh Marpet and I’ve talked to Andrew Nesbitt many times. Josh does a value chain risk initiative, Andrew does ecosystem.ms, I don’t know how to pronounce it. But

Erin Schnabel (14:24) Mm-hmm.

Josh Bressers (14:25) like abandoned open source is becoming like a real and serious thing that’s happening. And in many instances, like we don’t even know who to go ask ‘cause the the the open source project is in some random person’s GitHub account that has zero contact information. Like, what do you do? You know? I don’t know. Nothing.

Erin Schnabel (14:41) That’s exactly

the problem I’m trying to solve. And in fairness, like that’s what Apache’s for, and that’s what Eclipse is for. And that’s what Linux

Josh Bressers (14:47) Yes. Yes.

Erin Schnabel (14:49) Foundation is for. And that’s what I So like it’s not like I’m the only foundation in this position. We’re trying to solve this problem.

Josh Bressers (14:56) Right, right.

Erin Schnabel (14:58) the the the differentiator I guess just for Commonhaus is I’m really trying to let projects be self governing. Right? I’m really like, I’m okay with benevolent dictator for life.

as long as the benevolent dictator understands that they do have to work with me and you know that there’s some things that we have to do. But like there are some positions, like some people in the community at large who will say, well a benevolent dictator is not really open source. It’s like, but that’s like most of the ecosystem like

Josh Bressers (15:30) I got bad news for ya.

Erin Schnabel (15:32) it’s a kind of bread and butter for the random person in Nebraska. You know, like you know that that’s who it is.

So I try to give that person a good home with minimal overhead, right? It’s i it’s like here’s what we have to do to make sure that we both understand what all the rules are, that if something happens to you we can pick it up and run with it, you know, we try to keep it tight.

Josh Bressers (15:58) Sure. All right, Rob, I wanna let’s let’s get into the nitty-gritty here now. So we’ve set I we just spent what 20 minutes defining the problem. But I’m curious, so so like what does this look like, right? Like let’s talk about the actual technical issues behind something like this, right? Because it’s not just fixing vulnerabilities and old stuff or new stuff, you’re you’re straddling this line between you know things that are released and in use versus the the bleeding edge next version because

I know everyone’s always saying, just you have to upgrade your dependencies. You have to stay cutting edge. And it’s like, you have never written software if you say that out loud. Like that is one of those things, right?

Rob Nalen (16:40) Agreed, agreed. And it’s it’s one of those things where engineering groups and and developers are being told over and over again, do more with less. And part of that story is, well just throw AI at it. That that’ll work,

Josh Bressers (16:53) Obviously.

Rob Nalen (16:54) right? Like that’ll help. And and what what we found with specifically with AI is AI is really good at building from scratch.

Josh Bressers (17:03) Yes.

Rob Nalen (17:03) It’s

not really good at migrating complex where you’re dealing with a litany of direct and in and and transitive dependencies. And most notably, what we found is AI, even with some of the best prompting, it is it is gonna build what you’re asking for, but it’s not looking at what is end of life. It’s not look it certainly doesn’t have the heuristics to understand something that’s that’s abandoned, for example, right? And so people are actually pulling in these these engineering.

Groups are actually pulling in through AI more and more software that has shorter and shorter product lifecycle. And they’re just sort of they’re not even kicking the can down the road, they’re just making the can bigger and harder to kick currently, right?

Josh Bressers (17:45) Yes.

Rob Nalen (17:47) and so we’ve we found that, and you all were talking about you know abandonment. We have, and this is completely free. Everyone can go look at it. There’s a it’s it’s it you can run it as a as a CLI, it’s called end-of-life data set, and so

Josh Bressers (18:00) Yes.

Rob Nalen (18:01) we simply want.

To help folks identify open source software that has gone end-to-life or could have just been abandoned. And SCAs have have developed, they’re really, really good at notifying you of publicly disclosed CVEs, which is great. We’re we’re a CNA, so we we understand how important that is. With end-of-life data set, folks can run this and they get a much more detailed photo of and a snapshot of the open source software they’re using and what

What is not only end of life, but what also what we’ve determined is most likely abandoned. And it’s yeah.

Josh Bressers (18:38) Okay, I wanna I wanna stop you for a second. I

want us to define some terms here because like

Rob Nalen (18:42) Heck yeah.

Josh Bressers (18:43) abandoned has how to define that is contentious. And I don’t I don’t envy you at all having to do that. But even end of life, like when we think of end of life, I think we often

Rob Nalen (18:54) Mm-hmm.

Josh Bressers (18:55) think of like Windows XP as end of life. Right. We don’t

Rob Nalen (18:57) Yeah.

Josh Bressers (18:58) think of open source as end of life because an example being like, I’ll pick on Jackson. You know, Jackson has been around, it feels like forever, and I assume it will continue to exist almost forever. But

I don’t actually know what the current version of Jackson is, but like there are versions that were released, let’s say two years ago, that would be considered end of life versus the current version that’s being released. And I don’t know, I don’t remember what Jackson’s policy is, but like some open source projects, like OpenSSL is a great example. They maintain

Rob Nalen (19:24) Mm-hmm.

Josh Bressers (19:25) older trees, whereas a lot of projects, they have like one main tree and that’s all they maintain. So right, when we’re that like end of life and open source is really weird and hard to define sometimes.

Rob Nalen (19:36) Yeah, yeah. Alright. That it’s actually probably good to level set. It’s one of the things that, you know, at HeroDevs like, end of life, and everyone’s got that. So we’ll we’ll yeah.

Josh Bressers (19:41) Yeah. Right. Everyone knows what that means.

Rob Nalen (19:45) So we’ll we’ll break it up into two buckets, right? So end of life means a project ceases to exist. The the folks that created it are like, we’re done. We’re not supporting it, you can move. So best example I can give would be Angular JS, for example. So Google was supporting

Josh Bressers (20:01) Yes.

Rob Nalen (20:02) Angular JS.

And they were done, right? And they said you can move to Modern Angular or you can move to React.

But we’re you’re not getting any more support. And the reason why I give that reference is that’s that’s where HeroDevs started, right? So in in 2018, Aaron Frost, our our founder and CEO, right, he had deep ties through ngconf with Google. And originally, HeroDevs was helping people migrate. It was meant to deal with how do you go from Angular.js to Angular to React. Well, a few customers back in 2018 said, Well, what if I just can I just stay on this while I figure it out? Can I get some time? And can you make sure I can pass?

my PCI audit? Can you make sure I’m compliant with Federamp or HIPAA or how does that work? And so that’s where the our subscription came from. And Google said, you know what, we’d love for you to do this because we don’t want to continue to take on AngularJS. And so they pointed to HeroDevs. So that’s one example of end of life, it’s it’s gone.

The other example is versions. So you’re using, for example, Spring. We’ll we’ll pick on Spring, just Java.

You’re using Spring, right? And you’re on let’s say you’re on Spring Boot 2.5. Well, that’s that’s gone end of life. The the community has moved on. if there’s if there’s a commercial vendor that offers LTS, that’s also expired. And so if you’re an enterprise and you’re you’re, you know, let’s say you’re using a runtime that’s Java 8 dependent, you’ve built on legacy spring, so you’re on Spring Boot 2.5, your choices now are you have to go through not only the spring migration, but you maybe have to upgrade.

From Java 8 to some scary number while working on Spring. And so for us, we would consider, and if you go to like endolife.date, we would consider Spring Boot 2.5 as being end of life. And so we say, Great, you’re stuck on that. Let’s let’s make sure you can pass all of your compliance and industry standards. And so we fork the latest minor version that was supported. We we provide that to our customers, and that’s the version where we provide our

patches and our ongoing remediation. And specifically for spring, you talk about what AI is doing. In in 2025, I believe there were something like 17 CVEs that impacted spring. We are now up to 109 this year alone.

We had 66 hit in a single week. And so we know that AI is driving more and more vulnerabilities. And so what we do is we ensure that folks that are on those legacy versions, which if you’re on the supported version, that’s great. The community’s gonna try and keep up with that, and that’s where those clearing houses come in. the the supported versions, they’re gonna try to keep up, but if you’re on the legacy version, well, now you have two problems. Number one, the compliance standards that we’re talking about, NIS2 Dora, CRA, PCI.

They specifically state that using an unsupported version is no longer in compliance. So you you’ve already had an issue, number one. Number two, you’re also using a version with known critical and high CVEs, which could have an immediate impact on your business. Worst case scenario could be something like what we saw in 2017 with the Equifax breach, which was caused entirely to an unpatched version of Apache Struts. I think it was Apache Struts 1.1.

gave rise to over half a billion dollars worth of direct damages that were that were assigned and millions of of people’s personal data being exposed. And so we view end of life as you’re stuck on this version, the community’s moved off. Let’s give you that time. Let’s make sure you can you can actually modernize. Our our end goal of course though is you need to get to the latest and greatest because that’s where the best features are, that’s where optimal uses are, that’s where you need to go.

Josh Bressers (23:55) Okay, now let’s tie it together. So why can’t you just do this on your own? What is the advantage to working with Erin on this project?

Rob Nalen (24:04) Yeah, love it. So for working with Commonhaus is we want to set a standard. So we could go talk to just to to pick on the three communities that we started out with, right? Hibernate, Cor Corcus, and Jackson. We could go s

Josh Bressers (24:17) And you don’t even have to talk

to them, right? Like it’s open source. You could just publish patches with zero

Rob Nalen (24:21) true. Yeah.

Josh Bressers (24:22) like conversation or interaction with the upstreams.

Rob Nalen (24:26) Yeah, and and some folks do this, right? And and they what what I’ve found is there’s there’s a lot of folks that will go out and say, well, we offer support to to open source. And when you start to dig in, you start to realize, well, support means they will answer the call. They’ll they’ll answer the call, right? They’re not doing proactive monitoring. They’re not doing C V E remediation. they’re they’re they can’t provide the VEX statements, right, to show that the CVEs have been remediated. we we wanna partner with the communities for for two reasons.

Number one, we are stewards of open source. We know that these communities have put a lot of effort and love into what they’ve built. And what they’ve built is extremely influential and necessary for enterprises. And so we want to take that value and we wanna provide it back to the communities, right? There’s no reason not to. Number one. Number two, we wanna help the community still. We’re comprised of

Of the world’s best engineers. I won’t name drop any of them. They’re incredible though. And Erin’s worked with a bunch of them. They are really amazing people that have deep ties to the communities themselves. So we want to partner with those communities because you’re right, we could pull things down, fix it, patch it, here you go. We by doing that though, we’re not helping the community at large, number one. And number two, if we’re not following a CVD policy, we could be creating some really hairy situations for those supported versions upstream. And so

So we want to be we want to be ambassadors with with the open source community and make sure we’re working in tandem with them and not doing something that could that could hurt the the current ecosystem of supported users.

Josh Bressers (26:09) Erin, what’s your take on all this? I’m curious what you how you feel like you fit into this story.

Erin Schnabel (26:15) So what I do is help Rob connect the dots to make sure that he can actually talk to the leaders of the project who may not otherwise make themselves socially available. and you know, that’s with their consent and interest, of course. trying to be respectful. But we have a lot of people who are random IDs on GitHub. They may not

socialize a lot of their information for whatever reason that they have. And so we try to create a trusted system for information exchange and for collaboration that respects everyone’s time. and I think part of what we’re doing, and I mean Rob HeroDevs does also great things with OpenJS Foundation and like you mentioned the other ones, there’s a certain amount of consistency there also, which I think is nice.

in terms of what others in the ecosystem or other companies or whatever can start to e expect a little bit. It’s like, that’s what this is, and this is how this behaves, and this is the kind of expectation that I have in terms of a relationship with the projects and what that interaction is. and I think that’s also a benefit to having a program defined. People understand what the expectations are, they understand how to play in the space, they understand

what members of that program are agreeing to do and to provide, which is also useful for the projects who are part of the foundation because then they also know what the expectations are. So it’s a little bit of level setting, trust establishment, making sure there are operating rules of the road, appeals process, disagreement pro that’s the other thing I didn’t say earlier, that that we help with for single maintainer projects, right?

It’s an expectation these days that you have a code of conduct of some kind, right?

Josh Bressers (28:09) Yes. Yes.

Erin Schnabel (28:11) If you have a solo maintainer, where does the report go?

Josh Bressers (28:16) Write the trash can.

Erin Schnabel (28:19) Exactly. So that’s another thing that we do, right? That that our council that that’s you know that our foundation can provide is okay, so if someone has a code of conduct issue, which I mean in fairness, a lot of that is miscommunication.

I mean, we’re all neurodivergent in our own different different ways and text is the worst communication mechanism ever. So establishing trust, making sure we have methods of communication and ways that we can resolve issues and like that’s what a working with a foundation brings, more than just working directly with a project.

Josh Bressers (28:56) Yeah, yeah, for sure. And and look, there’s I feel like when when I do single person open source, I’m like, I don’t need all that stuff, right? Like who cares if I have a code of conduct? Who cares if I have a proper open source license? Right. And lots of people say

Erin Schnabel (29:09) You would not be the only one to say that.

Josh Bressers (29:12) that, but it it really is important. And and I’ve seen many instances where projects that don’t have that sort of plumbing, the kind of things you just talked about, have huge problems, especially as they start to grow. So it’s like such a big deal. And it’s so hard to

Like figure this out without helping.

Erin Schnabel (29:29) Yeah. So we try to provide that help without being super invasive into the way they wanna roll, right? So that’s the balance we try to set. but then we’re also doing all of that other mediation and

Josh Bressers (29:45) Yeah, and and and I want to point out, like a

Erin Schnabel (29:46) Establishing of relationships.

Josh Bressers (29:47) lot of other foundations, if you join their foundation, they basically say, here are the rules. If you don’t like it, leave. And you you make it very clear on your website. That is not how it works at Commonhaus.

Erin Schnabel (29:57) Not how it works. Yeah.

Josh Bressers (29:59) Which I I’m impressed by, but also I’m like, that’s a big job, it sounds like. Giving them a lot of rope.

Erin Schnabel (30:05) It’s a

it’s yes, that’s actually the hardest part is it is a trust walk, basically, right? We’re trusting

Josh Bressers (30:15) Yeah, yeah.

Erin Schnabel (30:15) you to like I do have a few rules, right? Like there are a few things that you have to do because if you don’t, then I cannot actually help you. but

you know, I try to keep those as minimally invasive as I can. And

Josh Bressers (30:37) Yeah, yeah.

Erin Schnabel (30:39) when I was first looking at how to establish the foundation, I was talking, of course, to legal counsel because everything ends up with lawyers. I started to appreciate a little more why some foundations operate the way that they do. for example, trademarks.

Right, it’s much easier to have the one umbrella trademark and everybody underneath that than it is to allow projects to independently register trademarks, which ends up being very expensive. so that’s an interesting lesson, alone. But, you know, I’m very much about allowing projects to be themselves, their own brand, their own reputation, their own

Personality.

Josh Bressers (31:26) Yeah.

That’s awesome. I mean, i yeah, it’s a lot of work, but I I dig it. I like it. So all right, let’s land this plane. So what kind of what’s next, right? What can people expect? If there’s people interested in learning more, you know, where can they go to look for this? I’m I’m very interested in watching this particular project develop because I feel like I feel like the two of you have put together some really clever ideas and you’ve also given yourself a very narrow scope, which

Coming out of the gate with an infinite scope is like failure is literally the only option for that project. So

Erin Schnabel (31:57) Ha ha ha.

Josh Bressers (31:58) this is this looks great. So what’s next? Rob, I’ll start with you and then Erin, you can you can finish this up.

Rob Nalen (32:04) Yeah, yeah. So for us as as Erin talked about, right, we we want to expand and and help more of the projects that are a part of Commonhaus, right? and so there’s there’s like, you know, breadth and then even more importantly, we want to help the the existing and all those that we work with to continue to become more tightly aligned with the community. And so we’re gonna keep on doing that. We’re we’re meeting with the Jackson folks to understand how can we help there, right? There’s there’s increasing demand that’s taking place and so

So how do we help them, whether it’s just the triage process for security intake, if is it you know dealing with you know going through MITRE, if there is a CVE found, things like that. So we’re really excited about you know partnering with more of the Commonhaus Foundation projects and making sure that when when enterprises come to Commonhaus and they go and visit these projects, they know, okay, the the OSSI has a structure and it has an apparatus so that we know.

know we can meet our needs and and for the community they know that HeroDevs is here to not only invest in them but also to to partner with what they’re working on currently.

Josh Bressers (33:16) All right Erin, take us home.

Erin Schnabel (33:19) Well, I’m looking forward to while both HeroDevs expanding to more of our projects. but I also do want some more corporates corporations to join the OSSI so that ultimately it’s good for the projects, to have more people supporting them. It ends up being a coordination and communication fiesta, party, whatever. But I I’m looking at

How best to help the holistic view of my projects as we continue to grow, to get the support that they need, especially for the solo maintainer or the few maintainer situations, because the number of CVEs that are coming in is huge. It’s becoming more of a burden

Josh Bressers (34:07) Yes.

Erin Schnabel (34:07) rather than less. And so for me, getting this program to grow, connecting more of them, like the way Commonhaus works with sponsorships too, is we have

advisory board representation, for example. And so having more of our project leaders being able to have members of the advisory board that they can ask questions of, members of the OSSI that they can work with in terms of coordinating CVE responses, like that for me is really important for our projects to help them cope with what is happening right now.

Josh Bressers (34:42) Yeah, no, that’s great. And I will put links in the show notes to the Commonhaus Foundation and the OSSI and and all of the fun stuff. So anyone interested, just hit up the show notes. I’ll I’ll get you where you need to go. So Rob Erin, I wanna thank you for the time. I’ve learned an amazing amount. I’m very excited to see where this goes in the future. It is again, like I said, I have a lot of hope for this one ‘cause it it feels like attainable versus we’re gonna secure the whole world, everybody. It’ll be fine.

So this is awesome. Just yeah. Thanks. And you’ll have to have me come back and maybe in a year or two and we’ll see how it’s going. So I love it.

Rob Nalen (35:19) Sounds good?

Erin Schnabel (35:19) We’d love

to be here. Thanks for having us.

Josh Bressers (35:22) Awesome. Thank you.