Skip to content
PodcastsTechnologyOpen Source Security

Open Source Security

Josh Bressers
Open Source Security
Latest episode

546 episodes

  • Open Source Security

    Finding difficult vulnerabilities with Jaya Baloo from AISLE

    2026/09/07 | 29 mins.
    Josh chats with Jaya Baloo from AISLE about their vulnerability scanner. If you follow open source vulnerabilities AISLE is a name you've seen popping up recently. They have a vulnerability scanner that is outperforming most of the existing scanners like Mythos. Jaya gives us some insight into how this all works and why they're different. We also learn about some scary new attacks that can be conducted on LLM models. Jaya was a ton of fun and filled with insights.
    The show notes and blog post for this episode can be found at
    https://opensourcesecurity.io/2026/2026-09-jaya-aisle
  • Open Source Security

    Sovereign Tech Agency with Erik Möller

    2026/08/31 | 36 mins.
    Josh chats with Erik Möller from the Sovereign Tech Agency about what they're doing. The Sovereign Tech Agency is doing some amazing work around funding open source maintainers and projects. Eric breaks down what they're doing, how it works, and how you can apply for funding. We even learn about some similar projects happening in the EU. Hopefully in the near future we will see the work Sovereign Tech Agency is doing happening in every country.
    The show notes and blog post for this episode can be found at
    https://opensourcesecurity.io/2026/2026-08-erik-sta
  • Open Source Security

    CVEs vs Advisories with Paul Asadoorian

    2026/08/24 | 38 mins.
    Josh chats with Paul Asadoorian about a tool he wrote called fettle and a recent report Paul published on CVEs. Fettle is a tool to help update and manage Linux systems. The big sell on this one is checking if your firmware is out of date. We then talk about a report Paul created that doesn't obsess over CVEs, but rather the vendor updates. It makes more sense to worry about advisories as those are actionable, where CVEs often are not. It's a great chat and Paul is a legend in the industry.
    The show notes and blog post for this episode can be found at
    https://opensourcesecurity.io/2026/2026-08-paul-fettle-cve
  • Open Source Security

    Maintaining EOL Open Source with Commonhaus and HeroDevs

    2026/08/17 | 34 mins.
    Josh chats with Erin Schnabel and Rob Nalen about a new effort from Commonhaus and HeroDevs for maintaining end of life open source. This project, the Open Source Sustainability Initiative is a clever way to bring corporations and projects together for maintenance of new and old versions of open source projects. This is pretty new territory for everyone, this project is worth keeping an eye on because it has a very small scope initially. Other similar ideas have gigantic scopes that are almost certainly too large.
    The show notes and blog post for this episode can be found at
    https://opensourcesecurity.io/2026/2026-08-commonhaus-herodevs
  • Open Source Security

    Cleanup, Speedup, Levelup open source at e18e

    2026/08/10 | 35 mins.
    Josh chats with James from e18e. This is a project that is working on improving Javascript packages by cleaning up, speeding up, and leveling up the dependencies. The way the e18e project handles this work is very human open source. It's all about building up connections and trust with the package communities, which is no small effort. James fills us in on what they're doing as well as how we can get involved. It's a truly amazing effort
    The show notes and blog post for this episode can be found at
    https://opensourcesecurity.io/2026/2026-08-e18e-james
More Technology podcasts
About Open Source Security
Open Source Security is a media project to help showcase and educate on open source security. Our goal is to give the community a platform educate both developers and users on how open source security works. There's a lot of good work happening that doesn't get attention because there's no marketing department behind it, they don't have a developer relations team posting on LinkedIn every two hours. Let's focus on those people and teams then learn what they do and how they do it. The goal is to hear from the people doing the work, they know what's up, they have a lot to teach us. We just have to listen.
Podcast website

Listen to Open Source Security, Darknet Diaries and many other podcasts from around the world with the radio.net app

Get the free radio.net app

  • Stations and podcasts to bookmark
  • Stream via Wi-Fi or Bluetooth
  • Supports Carplay & Android Auto
  • Many other app features
Open Source Security: Podcasts in Family