Skip to content

Podcasts

Open Source Security

Hosted by Josh Bressers

Half-hour conversations with the maintainers and foundations who keep open source secure.

Interview Weekly 30–60 min· ~548 episodes· Started 2016
Level
Practitioner, assumes you work in or study security
Status
Active, last episode
Who's behind it
Independent, Josh Bressers source
Last verified
Transcripts for some episodes

Listed underAppSec

Editorial take

The best show for understanding the software supply chain from the maintainer's side. Josh Bressers interviews one guest a week for about 35 minutes, and the guests are the people doing the work: Daniel Stenberg on AI slop bug reports against curl, the Debian packager who explains why the XZ backdoor was nearly undetectable, Python and Rust security leads, registry operators, and EU Cyber Resilience Act experts. It is unusually good on policy that will reach every developer, such as the CRA, CVE program changes, and SBOMs. The limitation is narrowness by design: almost everything is seen through open source, and there is little on incident response, cloud, or enterprise programs. The show has run since 2016, first as a two-host news show with Kurt Seifried, now as Josh's solo interview format.

Last hand-checked 2026-09-30.

Listen if you …

  • own dependency risk, SBOMs, or vulnerability management for a software team
  • want to understand the EU Cyber Resilience Act and CVE changes before they hit your backlog
  • maintain open source and want to hear how other maintainers handle security

Skip if you …

  • you want breach stories or threat actor news, this is about how software gets built and maintained

Start with these 3 episodes

  1. 01

    Vulnerability disclosure with Casey Ellis

    · 38 min · Beginner

    A Bugcrowd founder explains why disclosure is hard. A clear entry point that needs no open source background.

  2. 02

    Detecting XZ in Debian with Otto Kekäläinen

    · 32 min · Practitioner

    The show at its best: a working Debian packager on why the XZ backdoor was so hard to catch.

  3. 03

    Curl vs AI with Daniel Stenberg

    · 34 min · Practitioner

    Curl's maintainer on AI-generated bogus bug reports and the policy he wrote to stop them.

About the show

Open Source Security is a weekly interview podcast hosted by Josh Bressers. Each episode is a single conversation with a maintainer, foundation leader, researcher, or policy expert about how security works in open source.

The show began in 2016 and has passed 540 episodes. Earlier years were a co-hosted news discussion with Kurt Seifried; the current format is a solo-hosted interview of about 30 to 40 minutes, with episode pages and recent transcripts on opensourcesecurity.io.

Notable guests

  • Daniel Stenberg
  • Casey Ellis
  • Josh Corman
  • Allan Friedman
  • Brian Fox
  • Seth Larson
  • Alex Gaynor
  • Paul Asadoorian
  • Xe Iaso
  • Amanda Brock

If Open Source Security works for you, these likely will too.