Rust coreutils with Sylvestre Ledru
Josh talks to Sylvestre Ledru about the Rust coreutils project. Weβve been using GNU coreutils for decades now, and the goal of Rust coreutils is to rewrite these utilities in Rust. The primary reason...
I had a chat on #OpenSourceSecurity with @sylvestreledru.bsky.social about his Rust coreutils work
Replacing coreutils with Rust is one of those things that I love as a way to improve security but also keep a project fresh in the modern age
I learned a ton from this disucssion
02.03.2026 16:02
π 1
π 1
π¬ 0
π 0
Digital Sovereignty and Nextcloud with Frank Karlitschek
Episode Links Frank Nextcloud Nextcloud getting started Digital Sovereignty Index This episode is also available as a podcast, search for βOpen Source Securityβ on your favorite podcast player.β¦
How does open source business model work, why is user empowerment so important, and when is the right time for digital sovereignty?
Find out in the new episode of the @josh.bressers.name podcast as he is joined by our founder @karlitschek.bsky.social
17.02.2026 18:25
π 5
π 2
π¬ 0
π 0
The Global Vulnerability Intelligence Platform with Olle E. Johansson
Josh chats with Olle E. Johansson about the Global Vulnerability Intelligence Platform (GVIP). Itβs no secret the current vulnerability systems are reaching a breaking point. Olle is one of the few pe...
I had a chat with @oej.edvina.net about The Global Vulnerability Intelligence Platform
Olle is working to build a community around the future of vulnerability identifiers
Don't just give it a listen, but also come help Olle. It's a pretty important problem that nobody can solve alone
16.02.2026 17:47
π 1
π 1
π¬ 0
π 0
The Art of Crisis Management with David Bernstein
Josh talks to David Bernstein about the world of crisis management and business continuity. David is a certified emergency manager and tell us about preparing for both digital and physical disruptions...
This episode of #OpenSourceSecurity I have a chat with David Bernstein about crisis response
I love this topic because responding to a crisis is pretty common in security work, but doesn't have to be a gong show
This is one of those topics that can go deep. David did a nice job covering basics
02.02.2026 15:12
π 1
π 0
π¬ 0
π 0
In a recent episode of Open Source Security, @josh.bressers.name sits down with Victor Julien, founder and lead developer of the #Suricata project.
Tune in now! opensourcesecurity.io/2026/2026-01...
29.01.2026 14:56
π 3
π 1
π¬ 0
π 1
Iocaine poisons bots with Gergely Nagy
Josh talks to Gergely Nagy (algernon) about his tool Iocaine. Iocaine creates a maze to trap scraping bots in a world a fake pages they cannot escape. algernon tells us how Iocaine effectively traps b...
This week on #OpenSourceSecurity I have a chat with Gergely Nagy about Iocaine
Iocaine creates a maze of garbage to trap scraping bots. I love this idea, it has amazing chaotic good energy!
I learn all about how Iocaine works, and even got to see some dashboards showing off the size of the problem
12.01.2026 15:29
π 2
π 1
π¬ 0
π 0
Anubis with Xe Iaso
Josh chats with Xe Iaso, the creator of Anubis the web AI firewall. We discuss how Anubis is tackling bots and scrapers. The discussion around the scrapers is fascinating and challenging, these things...
This week on #OpenSourceSecurity I have a chat with Xe Iaso about #Anubis, the tool that stops web AI scrapers
The scale of web scraping is way worse than I expected, and blocking things is also a lot harder than I expected
This is one of those conversations where I learned how little I know
05.01.2026 14:29
π 2
π 0
π¬ 0
π 0
Rustls with Dirkjan and Joe
Josh talk to Dirkjan and Joe about Rustls (pronounced rustles), a Rust-based TLS library. Dirkjan and Joe are developers on Rustls. We talk about the history that got us to this point. The many many c...
This week on #OpenSourceSecurity I chat with Dirkjan Ochtman and Joe Birr-Pixton about #Rustls. A lot has happened with Rustls in the last few years (and there's a lot more to come). Writing a TLS implementation is incredibly complicated, even when you don't have to worry about memory safety
29.12.2025 14:49
π 5
π 3
π¬ 0
π 0
Daniel Thompson answers: Does the CRA apply to Santa?
Josh welcomes back Daniel Thompson explore the rather silly question of whether Santa Claus needs to be compliant with the Cyber Resilience Act (CRA). This episode was intended to be silly, but it end...
On a very special Christmas episode of #OpenSourceSecurity I asked Daniel Thompson-Yvetot how the #CRA will impact Santa Claus
I meant the episode to be silly, just in time for Christmas, but I think I learned more from Daniel in those 50 minutes than I have in the last 3 years reading about CRA
22.12.2025 17:28
π 0
π 0
π¬ 1
π 0
Linux Foundation Europe with Gabriele Columbro
Josh has a chat with Gabriele Columbro, Executive Director of the Fintech Open Source Foundation and General Manager of Linux Foundation Europe. We of course discuss the Cyber Resilience Act (CRA), th...
This #OpenSourceSecurity episode I chat with Gabriele Columbro from @linuxfoundationeu.bsky.social
We of course chat about the #CRA and how he helped with shaping what we see today
We also cover open source sustainability, vertical foundations, and all the attention open source is receiving
15.12.2025 15:32
π 1
π 1
π¬ 0
π 0
This was so much fun to talk about! If you want to find out how we found this bug, the raw story is here first, in my own words :)
01.12.2025 19:08
π 11
π 4
π¬ 0
π 0
TARmageddon with Alex Zenla
Josh discusses the TARmageddon vulnerability with Alex Zenla, CTO of Edera. In this episode, we explore the discovery of the TARmageddon vulnerability. Itβs especially interesting because itβs Rust, b...
This episode of #OpenSourceSecurity I chat with @alex.zenla.io from @edera.dev about the #TARmageddon vulnerability they found
I've coordinated a lot of vulnerabilities in my day, but never have I had to even think about something as difficult as this one
01.12.2025 19:04
π 7
π 2
π¬ 0
π 2
Python Security with Seth Larson
In this episode Seth Larson gives us a cornucopia of topics relating to Python security. Seth discusses the Python Software Foundationβs decision to reject a significant grant NSF. Diversity is a big ...
#OpenSourceSecurity has a chat with @sethmlarson.dev about @python.org security
Seth has a new whitepaper, there's a CFP open (which you should submit a paper to), and some discussion about the PSF grant situation
It's always fun to chat with Seth, I learn a ton every time!
24.11.2025 15:58
π 9
π 5
π¬ 0
π 0
NPM supply chain attacks with Charlie Eriksen
Josh chats with Charlie Eriksen, a security researcher at Aikido Security. We discuss the recent NPM supply chain attacks that affect hundreds of packages. Charlie shares his experiences dealing with ...
I had a chat with @charlieeriksen.bsky.social about the recent NPM attacks
We chat about what happened (now that the dust settled), and we discuss what's next.
Charlie is doing some great work in this space, he understands the problem better than most
10.11.2025 14:58
π 2
π 1
π¬ 0
π 0
Detecting XZ in Debian with Otto KekΓ€lΓ€inen
In this episode, Josh and Otto dive into the world of Debian packaging, exploring the challenges of supply chain security and the importance of transparency in open source projects. They discuss Ottoβ...
This week on #OpenSourceSecurity I talk to @ottoke.bsky.social about his blog post about detecting an attack like xz in Debian
It's a fascinating conversation about a very complicated topic
There are things that could be detected, but this one would have been very very difficult
03.11.2025 15:11
π 1
π 0
π¬ 0
π 1
Rock over London, rock on Chicago
01.11.2025 00:18
π 3
π 0
π¬ 0
π 0
Eclipse Foundation SBOMs with Mikael Barbero
In this conversation, Josh speaks with Mikael Barbero, head of security at the Eclipse Foundation. They discuss the foundationβs role in enhancing the security posture of open source projects, the imp...
I chat with @mikael.barbero.tech about security happenings at the Eclipse Foundation
My favorite project they have is helping projects generate #SBOMs, but there's a lot happening. If you want to see some public examples of how to do security right, give it a listen!
20.10.2025 14:34
π 1
π 0
π¬ 0
π 1
π Just wrapped a fantastic conversation with @josh.bressers.name. We dive deep into enhancing open source security and how we do it at the @eclipse.org
Can't wait for you to hear the full episode, coming soon!
16.10.2025 16:18
π 3
π 1
π¬ 1
π 0
Sustaining Package Repositories with Brian Fox
Brian Fox discusses the challenges and future of open source package repository infrastructure. We discuss the complexities of managing public registries, the impact of overconsumption, and the import...
On #OpenSourceSecurity I had a chat with @brianfox.bsky.social about the sustainability letter from the open source package registries
This one is a big deal. The costs for open source are paid by someone, if you don't know who, you need to read this letter
opensourcesecurity.io/2025/2025-10...
06.10.2025 14:26
π 2
π 1
π¬ 0
π 0
MCP is having a moment. @josh.bressers.name wanted to know: what are we actually shipping?
9,000 vulns
263 critical findings
36K+ NPM packages
Outdated base images
Not fear-mongeringβjust data-driven real... https://anchore.com/blog/analyzing-the-top-mcp-docker-containers/
#MCP #ContainerSecurity
02.10.2025 22:50
π 1
π 1
π¬ 0
π 0
Arch Linux Security with Foxboron and Anthraxx
Join us for a conversation with Foxboron (Morten Linderud) and Anthraxx (Levente Polyak), members of the Arch Linux security team. We talk about the difficulties of maintaining a Linux distribution, t...
This week on #OpenSourceSecurity I chat with @foxboron.bsky.social and Levente Polyak about Arch Linux security. It's a great chat where we talk about all the difficulties and oddities of trying to keep a Linux distribution secure
I learned a ton, I'm sure you will too
29.09.2025 15:00
π 3
π 1
π¬ 0
π 0
OpenSSL with Hana Andersen and Anton Arapov
I discuss all things OpenSSL with Hana Andersen and Anton Arapov from the OpenSSL Corporation. Discover the intricacies of organizing the first-ever OpenSSL conference in Prague, the importance of pos...
This episode of #OpenSourceSecurity I chat with Hana Andersen and Anton Arapov about their upcoming #OpenSSL conference
They also answer a bunch of my questions about the structure of the OpenSSL project, how we got where we are today, and what's coming next
opensourcesecurity.io/2025/2025-09...
22.09.2025 14:27
π 0
π 0
π¬ 0
π 0
Donβt miss this podcast episode with the PSFβs Executive Director, @eximious.bsky.social, on funding open source, PyCon US, global community support & the importance of sustainability!
17.09.2025 12:51
π 7
π 6
π¬ 1
π 0
The Python Software Foundation with Deb Nicholson
In this episode I discuss the Python Software Foundation with Deb Nicholson. We discuss their contributions to the Python programming community. Learn how this dedicated organization supports the grow...
This episode of #OpenSourceSecurity I chat with Deb Nicholson about the Python Software Foundation. We discuss what they do, their current grant program, and how you can get involved
The PSF is the group behind the legendary Python community. It's a fun chat, Deb has so much knowledge to share
15.09.2025 15:52
π 2
π 1
π¬ 0
π 1