A ledger page with numbers

Cleanup, Speedup, Levelup open source at e18e

Josh chats with James from e18e. This is a project that is working on improving Javascript packages by cleaning up, speeding up, and leveling up the dependencies. The way the e18e project handles this work is very human open source. It’s all about building up connections and trust with the package communities, which is no small effort. James fills us in on what they’re doing as well as how we can get involved. It’s a truly amazing effort ...

August 10, 2026 · Josh Bressers
A person in a maze

Blog - You don't have a supply chain, you have supply soup

2026 has been a wild year. There are more vulnerabilities than anyone can count. We seem to keep talking about the number itself instead of things like how we got here or what we’re going to do about it, which is neat. The number of attacks against open source is basically an uncountable mess. Also very neat. And the cherry on top of this poop sundae is number of companies that have promised us they are going to “fix” open source, and when they use the word fix they really mean sell you a solution for a problem they mostly made up. Very cool, very cool. ...

July 30, 2026 · Josh Bressers
A water wheel

Securing critical infrastructure with Josh Corman

Open Source Security welcomes Josh Corman to talk about the challenges around securing our critical infrastructure. Specifically the discussion centers around our water supplies. There are a lot of really wild things happening right now with attacks like Volt Typhoon and Salt Typhoon. Josh has an amazing ability to make these sort of discussions easy to understand without spreading FUD. Josh also has suggestions for actions that need to be taken to help deal with these problems. It’s not all technical solutions, there are non technical things we can do to help reduce the risk posed by our technical systems failing. ...

July 27, 2026 · Josh Bressers
An old rusty chain

Abandoned open source with Josh Marpet

Josh welcomes Josh Marpet for a discussion about abandoned open source packages. Josh Marpet has a foundation called Value Chain Risk Institute that has a report discussion how to start measuring if an open source package might be abandoned. There’s a lot of data, but not a lot of groups using that data to help make informed decisions about using open source. VCRI is one of those places that’s starting to do this. ...

July 20, 2026 · Josh Bressers
A circuit board

AIBOM, CBOM, and HBOM with Allan Friedman

Josh chats with Allan Friedman about all things Bill of Materials. Allan did a ton of work to help turn SBOM into what it is today. He has many thoughts and ideas around the new types of BOMs, a concept he’s calling the OmniBOM. Allan is always fun to chat with and he brings a ton of knowledge and advice. Episode Links Allan’s Linkedin Dirk Gently’s Holistic SBOM Agency Allan’s AIBOM paper HBOM Cryptography Bill of Materials (CBOM) This episode is also available as a podcast, search for “Open Source Security” on your favorite podcast player. ...

June 29, 2026 · Josh Bressers
A person in a maze

Blog - We have to change the rules of security

I recently talked to Sal Kimmich on the podcast. The topic centered around solutions to many of our existing systemic problems, Sal has an impressive understanding of the current problems as well as how to fix those problems with systemic long term solutions. But systemic fixes are the long game. Things that will help future me are not helpful to present me. And present me, present everyone, is drowning in security problems right now. ...

June 9, 2026 · Josh Bressers
Hot coals

Hacking your CI/CD with François Proulx

Josh welcomes back François Proulx to talk about the absolute madness in the CI/CD universe right now. We also learn about François’ new project SmokedMeat which is a tool to help you hack your own CI/CD. When Josh spoke to François a year ago, the world was a very different place than it is today. François has a ton of knowledge about how we got here and what we can do moving forward. Boost Security has a bunch of amazing open source tools François built that can help keep CI/CD systems understood and locked down. ...

June 8, 2026 · Josh Bressers
A toy cash register

The lopsided economics of vulnerabilities

There was recently a really good thread about the Copy Fail vulnerability between Will Dormann and Greg K-H. The TL;DR is that vulnerability reporting and disclosure is in a weird state of flux. This discussion got me wondering what’s going on, and I think we’re seeing the extremes emerging of how vulnerabilities have always worked. The middle of the bell curve has been removed. There are three groups in this story. The Security Researchers, the Companies, and Open Source developers. In the above discussion Will is a security research (one of the best I’ve ever seen). Greg is part of open source. There isn’t a great company representative, but that’s OK. ...

May 3, 2026 · Josh Bressers
A microscope

Linus's Law, but vulnerabilities

given enough eyeballs, all bugs are shallow – Linus’s Law A long time ago we thought Linus’s Law was a real thing and it was why open source was better than closed source. It seems pretty accepted now that Linus’s Law wasn’t ever really a thing. It’s far more likely the reason a lot of open source was pretty good is because the authors were worried someone WOULD look and judge them if the code looked like crap. We all have dark corners of private GitHub repos that are the code equivalent of a festering boil. ...

April 28, 2026 · Josh Bressers
A dinosaur fossil

Open source was never about trust

It’s been a rough couple of weeks for open source There have been some high profile attacks like the TeamPCP events. Anthropic has a new model that’s going to create more security vulnerabilities than anyone can count. The number of security bug reports is going through the roof. AI slop is running rampant through GitHub. And let’s not even try to count all the hot takes from the LinkedInIstas. It’s clear we should never trust open source again, but we should trust someone on linkedin whose company is built on top of all open source and uses AI to do everything. This feels like animal farm but the animals have all been replaced with frozen burritos. All burritos are equal, but some burritos like my linkedin posts! ...

April 11, 2026 · Josh Bressers