snake-package-wide

Episode 371 - pip install is the tool we deserve but not the tool we need

Josh and Kurt talk about a blog post about pip and virtual environments. This eventually turns into a larger conversation around packaging tools and how we see incremental changes over time. The package ecosystems were what we needed a few years ago, but our needs have changed. https://traffic.libsyn.com/opensourcesecuritypodcast/Episode_371_-_pip_install_is_the_tool_we_deserve_but_not_the_tool_we_need.mp3 Show Notes One Does Not Simply ‘pip install’ Dag Wieers RPM Webfinger GitHub repo

April 17, 2023
wide-stars

Episode 370 - Open Source is bigger than you can imagine

Josh and Kurt talk about some data on the size of NPM. Josh wrote a blog post and a report about the amount of SEO spam in NPM was released. Open source is enormous, and it’s mostly one person. It’s hard to imagine how this all works sometimes and this lack of understanding can create challenges. https://traffic.libsyn.com/opensourcesecuritypodcast/Episode_370_Open_Source_is_bigger_than_you_can_imagine.mp3 Show Notes Josh’s blog on the size of NPM One In Two New Npm Packages Is SEO Spam Right Now Linux Kernel power distribution graph

April 10, 2023
wide-DALL·E 2023-03-30 08.05.03 - a steampunk robot writing the word blame on a chalkboard in a school classroom

Episode 369 - OpenAI broke ChatGPT then tried to blame open source

Josh and Kurt talk about OpenAI having a bug in ChatGPT, then they tried to blame open source. It didn’t go very well. In this episode Josh and Kurt argue a lot, maybe someday we’ll know who was the least wrong. https://traffic.libsyn.com/opensourcesecuritypodcast/Episode_369_OpenAI_broke_ChatGPT_then_tried_to_blame_open_source.mp3 Show Notes ChatGPT Tweet ChatGPT Blog redis bug

April 3, 2023
wide-STF_logo_blank

Episode 368 - The Sovereign Tech Fund with Fiona Krakenbürger

Josh and Kurt talk to Fiona Krakenbürger about the Sovereign Tech Fund. This is a fund created by Germany to fund important open source projects. Fiona has amazing insight into how this fund was created, what it’s doing today to help fund open source. She discusses where we go from here and what the future will look like. The Sovereign Tech Fund is a forward thinking program to fund open source across the world. This episode is a window into the future. ...

March 27, 2023
wide-change-671374

Episode 367 - Open source will never be the same

Josh and Kurt talk about GitHub enforcing sanctions against an open source developer and Docker changing how their registry works. There’s a lot to unpack in this one. There’s a lot of happenings going on in the world of open source. We are seeing governments paying attention to open source like never before, change is coming and everything is going to change. https://traffic.libsyn.com/opensourcesecuritypodcast/Episode_367_Open_source_will_never_be_the_same.mp3 Show Notes ipmitool Repository Archived, Developer Suspended By GitHub Elixir: Docker now charges open source orgs $300

March 20, 2023
crash-test-gfd5276214_1920

Episode 366 - Software liability is coming

Josh and Kurt talk about the number of dependencies that is now normal. Keeping track of thousands of dependencies used to be impressive, now it’s normal. In what instances should we know everything about our open source? The days of being able to ignore your software liability is looking like it’s coming to an end. https://traffic.libsyn.com/opensourcesecuritypodcast/Episode_366_Software_liability_is_coming.mp3 Show Notes LTT millenial pause The perverse incentive of vulnerability counting National Cybersecurity Strategy

March 13, 2023
wide-port

Episode 365 - "I am not your supplier" with Thomas Depierre

Josh and Kurt talk to Thomas Depierre about his “I am not a supplier” blog post. We drink from the firehose on this one. Thomas describes the realities and challenges of being an open source maintainer. What open source and society owe each other. How safety can help describe what we see. There’s too many topics to even list. The whole episode is an epic adventure through modern open source. https://traffic.libsyn.com/opensourcesecuritypodcast/Episode_365_I_am_not_your_supplier_with_Thomas_Depierre.mp3 Show Notes Thomas on Mastodon I am not a supplier The Treachery of Images (Ceci n’est pas une pipe) Atlantic Council report The Field Guide to Understanding ‘Human Error’ Google wants new rules for developers working on ‘critical’ projects Roads and Bridges:The Unseen Labor Behind Our Digital Infrastructure Sovereign Tech Fund

March 6, 2023
wide-robot-sbom

Episode 364 - Using SBOMs is hard

Josh and Kurt talk about SBOMs. Quite a bit has happened in the world of SBOMs in the last year or so. There are going to be different types of SBOMs, like build, source, or runtime. Each will tell us different things depending on what we need to know. We also cover some of the community efforts happening around SBOMs. They’re still not easy to use, but it’s better better. https://traffic.libsyn.com/opensourcesecuritypodcast/Episode_364_Using_SBOMs_is_hard.mp3 Show Notes SBOM Types draft SBOM Drift OpenSSF SBOM Everywhere

February 27, 2023
wide-robot-computer

Episode 363 - Joylynn Kirui from Microsoft on DevSecOps

Josh and Kurt talk to Joylynn Kirui about DevSecOps in the Microsoft universe. Joylynn gives us an overview of the current state of devops and tells us about some of the tools Microsoft has made available to the open source universe. https://traffic.libsyn.com/opensourcesecuritypodcast/Episode_363_Joylynn_Kirui_from_Microsoft_on_De_SecOps.mp3 Show Notes Joylynn Kirui Joylynn on DVT Tech Insights Episode 174 - a chat with GitHub about CodeQL S2C2F Azure Open Source Day

February 20, 2023
wide-Rust_programming_language_black_logo

Episode 362 - A lesson in Rust from Carol Nichols

Josh and Kurt talk to Carol Nichols about Rust. Carol is an authority on Rust and helps us understand how Rust works, why it’s different. Why Rust doesn’t have the same problems C and C++ have, and what the future of it all could look like. It’s a really fun show with some great questions from Carol along the way. https://traffic.libsyn.com/opensourcesecuritypodcast/Episode_362_A_lesson_in_Rust_from_Carol_Nichols.mp3 Show Notes Carol Nichols on Mastodon The Rust Programming Language, 2nd Edition Rust book online Netflix tech blog on Java performance Rust in the context of Railroad Brakes Kees Cook blog - Bounded Flexible Arrays in C Consumer Reports on memory safety OSS-Fuzz and Rust

February 13, 2023