Why do we keep ignoring CI security with François Proulx

Why do we keep ignoring CI security with François Proulx

François Proulx, a supply chain security researcher at Boost Security, discusses how continuous integration (CI) and build pipeline security represents a critical and overlooked hole in our supply chain security. It seems like most supply chain compromises are actually from CI system breaches rather than direct code compromise, yet we seem to obsess over everything on either side of the CI system. François has a bunch of really good practical suggestions for how we can start to improve our CI security today.

The blog post for this episode can be found at
https://opensourcesecurity.io/2025/2025-02-ignoring_ci_security_francois_proulx/

Avsnitt(526)

Open Source Pledge with Vlad-Stefan Harbuz

Open Source Pledge with Vlad-Stefan Harbuz

Josh has a discussion with Vlad-Stefan Harbuz about the Open Source Pledge as well as his recent FOSDEM talk. The Open Source Pledge is all about trying to build a sustainable universe for open source...

27 Apr 34min

Building a plan for disaster with David Bernstein

Building a plan for disaster with David Bernstein

Josh welcomes back David Bernstein to talk about creating a disaster recover plan. It's a very timely topic given all the current events. There are more supply chain attacks and compromises than ever ...

20 Apr 39min

Open Source Malware with Paul McCarty

Open Source Malware with Paul McCarty

Josh talks to Paul McCarty of Open Source Malware about ... open source malware. Paul explains why there aren't many good open source malware datasets. We discuss why the existing data is lacking for ...

13 Apr 38min

Package management challenges with Andrew Nesbitt

Package management challenges with Andrew Nesbitt

Josh welcomes back Andrew Nesbitt to discuss some recent blog posts he wrote about the challenges of new ecosystems as well as challenges of no ecosystems like C. There aren't very many people who loo...

6 Apr 36min

Open Source Security at scale with Michael Winser

Open Source Security at scale with Michael Winser

Josh talks to Michael Winser about a talk he gave at FOSDEM as well as his work on Alpha Omega at the Linux Foundation. Michael is approaching open source security in a way that nobody has ever tried ...

30 Mars 42min

2026 State of the Software Supply Chain with Brian Fox

2026 State of the Software Supply Chain with Brian Fox

Josh chats with Brian Fox from Sonatype about their 2026 State of the Software Supply Chain report. Most of the number continue to grow at alarming rates, but there's some new interesting findings in ...

23 Mars 35min

MCP and Agent security with Luke Hinds

MCP and Agent security with Luke Hinds

Josh talks to Luke Hinds, CEO of Always Further, about MCP and agent security. We start out talking about Luke's new tool, nono which is a sandboxing tool that has AI agents in mind as a use case. We ...

16 Mars 35min

The State of OpenSSL for pyca/cryptography with Alex Gaynor and Paul Kehrer

The State of OpenSSL for pyca/cryptography with Alex Gaynor and Paul Kehrer

Josh talks to Paul Kehrer and Alex Gaynor, from the Python Cryptographic Authority. Alex and Paul recently published a statement discuss the challenges posed by modern OpenSSL. We discuss the statemen...

9 Mars 33min

Populärt inom Teknik

natets-morka-sida
uppgang-och-fall
elbilsveckan
market-makers
rss-technokratin
bilar-med-sladd
rss-elektrikerpodden
rss-laddstationen-med-elbilen-i-sverige
bli-saker-podden
skogsforum-podcast
rss-veckans-ai
rss-powerboat-sverige-podcast
hej-bruksbil
rss-it-sakerhetspodden
rss-fabriken-2
har-vi-akt-till-mars-an
rss-snacka-om-ai
rss-uppgang-och-fall
rss-en-ai-till-kaffet
developers-mer-an-bara-kod