Episode 286 - Open source supply chain with Google's Dan Lorenc

Episode 286 - Open source supply chain with Google's Dan Lorenc

Josh and Kurt talk to Dan Lorenc from Google about supply chain security. What's currently going on in this space and what sort of new thing scan we look forward to? We discuss Google's open source use, Project Sigstore, the SLSA framework and more.

Show Notes

Det här avsnittet är hämtat från ett öppet RSS-flöde och publiceras inte av Podme. Det kan innehålla reklam.

Avsnitt(527)

Open source microprocessors with Jan Pleskac

Open source microprocessors with Jan Pleskac

In this episode Jan Pleskac, CEO and co-founder of Tropic Square, shares insights on the challenges and innovations in creating open and auditable hardware. While most hardware is very closed, Tropic ...

21 Juli 202530min

Package URLs with Philippe Ombredanne

Package URLs with Philippe Ombredanne

I'm joined by Philippe Ombredanne, creator of the Package URL (PURL), to discuss the surprisingly complex and messy problem of simply identifying open source software packages. We dive into how PURLs ...

23 Juni 202536min

Hobbyist Maintainers with Thomas DePierre

Hobbyist Maintainers with Thomas DePierre

Thomas DePierre joins Open Source Security to discuss the central idea from his blog post, "You are all on the hobbyist maintainers turf now," exploring the massive disconnect between the corporate wo...

16 Juni 202549min

STIG automation with Aaron Lippold

STIG automation with Aaron Lippold

I chat with Aaron Lippold, creator of MITRE's Security Automation Framework (SAF), to discuss how to escape the pain of manual STIG compliance. We explore the technical details of open-source tools li...

9 Juni 202533min

Ecosyste.ms with Andrew Nesbitt

Ecosyste.ms with Andrew Nesbitt

I recently chatted with Andrew Nesbitt about his project, Ecosyste.ms. Ecosyste.ms catalogs open source projects by tracking packages, dependencies, repositories, and more. With this dataset Andrew is...

2 Juni 202535min

Curl vs AI with Daniel Stenberg

Curl vs AI with Daniel Stenberg

Daniel Stenberg, the maintainer of Curl, discusses the increase in AI security reports that are wasting the time of maintainers. We discuss Curl's new policy of banning the bad actors while establishi...

26 Maj 202534min

Repository signing with Kairo De Araujo

Repository signing with Kairo De Araujo

I recently had a chat with Kairo about a project he maintains called Repository Service for TUF (RSTUF). We explain why TUF is tough (har har har), what RSTUF can do, and some of the challenges around...

19 Maj 202533min

Securing GitHub Actions with William Woodruff

Securing GitHub Actions with William Woodruff

William Woodruff discussed his project, Zizmor, a security linter designed to help developers identify and fix vulnerabilities within their GitHub Actions workflows. This tool addresses inherent secur...

12 Maj 202531min

Populärt inom Teknik

uppgang-och-fall
elbilsveckan
natets-morka-sida
market-makers
rss-laddstationen-med-elbilen-i-sverige
skogsforum-podcast
rss-technokratin
bli-saker-podden
gubbar-som-tjotar-om-bilar
rss-veckans-ai
rss-elektrikerpodden
rss-powerboat-sverige-podcast
bilar-med-sladd
hej-bruksbil
developers-mer-an-bara-kod
rss-uppgang-och-fall
rss-fabriken-2
rss-sakerhetspodcasten
rss-upplyst-entreprenordirektor
rss-generativet