Open Source Security
Hosted by Josh Bressers
Half-hour conversations with the maintainers and foundations who keep open source secure.
- Level
- Practitioner, assumes you work in or study security
- Status
- Active, last episode
- Who's behind it
- Independent, Josh Bressers source
- Last verified
- Transcripts for some episodes
Listed underAppSec
Editorial take
The best show for understanding the software supply chain from the maintainer's side. Josh Bressers interviews one guest a week for about 35 minutes, and the guests are the people doing the work: Daniel Stenberg on AI slop bug reports against curl, the Debian packager who explains why the XZ backdoor was nearly undetectable, Python and Rust security leads, registry operators, and EU Cyber Resilience Act experts. It is unusually good on policy that will reach every developer, such as the CRA, CVE program changes, and SBOMs. The limitation is narrowness by design: almost everything is seen through open source, and there is little on incident response, cloud, or enterprise programs. The show has run since 2016, first as a two-host news show with Kurt Seifried, now as Josh's solo interview format.
Last hand-checked 2026-09-30.
Listen if you …
- own dependency risk, SBOMs, or vulnerability management for a software team
- want to understand the EU Cyber Resilience Act and CVE changes before they hit your backlog
- maintain open source and want to hear how other maintainers handle security
Skip if you …
- you want breach stories or threat actor news, this is about how software gets built and maintained
Start with these 3 episodes
- 01
Vulnerability disclosure with Casey Ellis
· 38 min · Beginner
A Bugcrowd founder explains why disclosure is hard. A clear entry point that needs no open source background.
- 02
Detecting XZ in Debian with Otto Kekäläinen
· 32 min · Practitioner
The show at its best: a working Debian packager on why the XZ backdoor was so hard to catch.
- 03
Curl vs AI with Daniel Stenberg
· 34 min · Practitioner
Curl's maintainer on AI-generated bogus bug reports and the policy he wrote to stop them.
About the show
Open Source Security is a weekly interview podcast hosted by Josh Bressers. Each episode is a single conversation with a maintainer, foundation leader, researcher, or policy expert about how security works in open source.
The show began in 2016 and has passed 540 episodes. Earlier years were a co-hosted news discussion with Kurt Seifried; the current format is a solo-hosted interview of about 30 to 40 minutes, with episode pages and recent transcripts on opensourcesecurity.io.
Notable guests
- Daniel Stenberg
- Casey Ellis
- Josh Corman
- Allan Friedman
- Brian Fox
- Seth Larson
- Alex Gaynor
- Paul Asadoorian
- Xe Iaso
- Amanda Brock
Pairs with
If Open Source Security works for you, these likely will too.
Absolute AppSec
Ken Johnson · Seth Law
Two working AppSec practitioners arguing about what actually helps developers ship safer code.
Listen if you run or work on an application security program and want peers' honest opinions.
panelweekly60m+Application Security Weekly
Mike Shema · John Kinsella · Kalyani Pawar
An hour a week on finding and fixing software flaws, from secure design to LLM-written code.
Listen if you build or secure software and want one reliable AppSec interview a week.
mixedweekly60m+Risky Business
PickPatrick Gray
Weekly news + analysis show for working security professionals.
Listen if you you work in security and need a weekly news synthesis.
panelweekly60m+