Episode 413 - PyTorch and NPM get attacked, but it's OK

Episode 413 - PyTorch and NPM get attacked, but it's OK

Josh and Kurt talk about an attack against PyTorch and NPM. The PyTorch attack shows the difficulty of trying to operate a large open source project. The NPM problem is one of the difficulty in trying to backdoor open source. A lot of people are watching and it only takes one person to notice a problem and we all benefit.

Show Notes

Avsnitt(527)

How to actually test a disaster plan with David Bernstein

How to actually test a disaster plan with David Bernstein

Josh and David finish up the disaster recovery and emergency planning trilogy. In this one David tells us how to test the plan he told us how to build in the last episode. There are some great ideas i...

4 Maj 34min

Open Source Pledge with Vlad-Stefan Harbuz

Open Source Pledge with Vlad-Stefan Harbuz

Josh has a discussion with Vlad-Stefan Harbuz about the Open Source Pledge as well as his recent FOSDEM talk. The Open Source Pledge is all about trying to build a sustainable universe for open source...

27 Apr 34min

Building a plan for disaster with David Bernstein

Building a plan for disaster with David Bernstein

Josh welcomes back David Bernstein to talk about creating a disaster recover plan. It's a very timely topic given all the current events. There are more supply chain attacks and compromises than ever ...

20 Apr 39min

Open Source Malware with Paul McCarty

Open Source Malware with Paul McCarty

Josh talks to Paul McCarty of Open Source Malware about ... open source malware. Paul explains why there aren't many good open source malware datasets. We discuss why the existing data is lacking for ...

13 Apr 38min

Package management challenges with Andrew Nesbitt

Package management challenges with Andrew Nesbitt

Josh welcomes back Andrew Nesbitt to discuss some recent blog posts he wrote about the challenges of new ecosystems as well as challenges of no ecosystems like C. There aren't very many people who loo...

6 Apr 36min

Open Source Security at scale with Michael Winser

Open Source Security at scale with Michael Winser

Josh talks to Michael Winser about a talk he gave at FOSDEM as well as his work on Alpha Omega at the Linux Foundation. Michael is approaching open source security in a way that nobody has ever tried ...

30 Mars 42min

2026 State of the Software Supply Chain with Brian Fox

2026 State of the Software Supply Chain with Brian Fox

Josh chats with Brian Fox from Sonatype about their 2026 State of the Software Supply Chain report. Most of the number continue to grow at alarming rates, but there's some new interesting findings in ...

23 Mars 35min

MCP and Agent security with Luke Hinds

MCP and Agent security with Luke Hinds

Josh talks to Luke Hinds, CEO of Always Further, about MCP and agent security. We start out talking about Luke's new tool, nono which is a sandboxing tool that has AI agents in mind as a use case. We ...

16 Mars 35min

Populärt inom Teknik

natets-morka-sida
uppgang-och-fall
elbilsveckan
market-makers
rss-technokratin
bilar-med-sladd
bli-saker-podden
rss-laddstationen-med-elbilen-i-sverige
rss-elektrikerpodden
skogsforum-podcast
hej-bruksbil
rss-veckans-ai
rss-it-sakerhetspodden
rss-powerboat-sverige-podcast
har-vi-akt-till-mars-an
rss-uppgang-och-fall
rss-fabriken-2
rss-en-ai-till-kaffet
rss-snacka-om-ai
developers-mer-an-bara-kod