Episode 286 - Open source supply chain with Google's Dan Lorenc

Episode 286 - Open source supply chain with Google's Dan Lorenc

Josh and Kurt talk to Dan Lorenc from Google about supply chain security. What's currently going on in this space and what sort of new thing scan we look forward to? We discuss Google's open source use, Project Sigstore, the SLSA framework and more.

Show Notes

Denne episoden er hentet fra en åpen RSS-feed og er ikke publisert av Podme. Den kan derfor inneholde annonser.

Episoder(527)

Open source microprocessors with Jan Pleskac

Open source microprocessors with Jan Pleskac

In this episode Jan Pleskac, CEO and co-founder of Tropic Square, shares insights on the challenges and innovations in creating open and auditable hardware. While most hardware is very closed, Tropic ...

21 Jul 202530min

Package URLs with Philippe Ombredanne

Package URLs with Philippe Ombredanne

I'm joined by Philippe Ombredanne, creator of the Package URL (PURL), to discuss the surprisingly complex and messy problem of simply identifying open source software packages. We dive into how PURLs ...

23 Jun 202536min

Hobbyist Maintainers with Thomas DePierre

Hobbyist Maintainers with Thomas DePierre

Thomas DePierre joins Open Source Security to discuss the central idea from his blog post, "You are all on the hobbyist maintainers turf now," exploring the massive disconnect between the corporate wo...

16 Jun 202549min

STIG automation with Aaron Lippold

STIG automation with Aaron Lippold

I chat with Aaron Lippold, creator of MITRE's Security Automation Framework (SAF), to discuss how to escape the pain of manual STIG compliance. We explore the technical details of open-source tools li...

9 Jun 202533min

Ecosyste.ms with Andrew Nesbitt

Ecosyste.ms with Andrew Nesbitt

I recently chatted with Andrew Nesbitt about his project, Ecosyste.ms. Ecosyste.ms catalogs open source projects by tracking packages, dependencies, repositories, and more. With this dataset Andrew is...

2 Jun 202535min

Curl vs AI with Daniel Stenberg

Curl vs AI with Daniel Stenberg

Daniel Stenberg, the maintainer of Curl, discusses the increase in AI security reports that are wasting the time of maintainers. We discuss Curl's new policy of banning the bad actors while establishi...

26 Mai 202534min

Repository signing with Kairo De Araujo

Repository signing with Kairo De Araujo

I recently had a chat with Kairo about a project he maintains called Repository Service for TUF (RSTUF). We explain why TUF is tough (har har har), what RSTUF can do, and some of the challenges around...

19 Mai 202533min

Securing GitHub Actions with William Woodruff

Securing GitHub Actions with William Woodruff

William Woodruff discussed his project, Zizmor, a security linter designed to help developers identify and fix vulnerabilities within their GitHub Actions workflows. This tool addresses inherent secur...

12 Mai 202531min

Populært innen Teknologi

lydartikler-fra-aftenposten
romkapsel
teknisk-sett
tomprat-med-gunnar-tjomlid
energi-og-klima
rss-impressions-2
nasjonal-sikkerhetsmyndighet-nsm
rss-heis
fornybaren
elektropodden
rss-ai-forklart
smart-forklart
shifter
hans-petter-og-co
teknologi-og-mennesker
pedagogisk-intelligens
rss-alt-vi-kan
rss-kvantespranget
rss-ki-praten
rss-grenser-for-ki