What's in the SOSS? An OpenSSF Podcast

OpenSSF

What's in the SOSS? features the sharpest minds in security as they dig into the challenges and opportunities that create a recipe for success in making software more secure. Get a taste of all the ingredients that make up secure open source software (SOSS) and explore the latest trends at the intersection of AI and security, vulnerability management, and threat assessments. Each episode of What's in the SOSS? is packed with valuable insight designed to foster collaboration and promote stronger security practices for the open source software community.About Christopher Robinson (aka CRob), hostCRob is a 43rd level Dungeon Master and a 26th level Securityologist. He is a leader within several Open Source Security Foundation (OpenSSF) efforts and is a frequent speaker on cyber, application, and open source security. He enjoys hats, herding cats, and moonlit walks on the beach.

  1. 6d ago

    Building the Agentic Future with Angie Jones

    In this episode of What’s in the SOSS?, host Sally Cooper interviews Angie Jones, VP of Developer Experience at the Agentic AI Foundation (AAIF). Angie shares her career journey from software engineering and holding 27 patents at IBM to leading open source protocol and developer relations initiatives. She details the mission of the Agentic AI Foundation as a neutral home for governing open source standards and technologies such as the Model Context Protocol (MCP), Goose, Agents.md, and Google's Agent-to-Agent (A2A) protocol. The conversation explores how cross-industry collaboration addresses the reliability and security of AI agents in production, key considerations for the shift toward agentic engineering, and what attendees can expect at the upcoming AgentCon and MCPCon North America. Chapters: 00:00 - Introduction00:28 - Welcome Angie Jones01:47 - Angie’s Career Journey: From IBM Patents to Open Source06:56 - Mission of the Agentic AI Foundation & Governing Open Standards11:47 - Preparing for the Era of Agentic Engineering13:20 - Preview of AgentCon and MCPCon North America17:32 - Rapid Fire Questions18:36 - Wrap-up & OpenSSF Resources Episode links: Angie Jones’ LinkedInAngie Jones’ BlogAgentic AI Foundation (AAIF)Model Context Protocol (MCP)goose: Open source AI agentAGENTS.mdAgent2Agent (A2A) ProtocolAAIF Working GroupsAAIF Agentic Commerce Working GroupOpenSSF AI/ML Security Working GroupSecure Agentic Framework (SAF)Register for AGNTCon + MCPCon North AmericaAGNTCon + MCPCon North America: Full ScheduleLet’s Play the Agentic AI Supply Chain Game! — Sarah Evans and Christopher Robinson (CRob) Workshop: Secure Agentic Framework (SAF) for Agentic AI — Sarah Evans, Jautau “Jay” White, Frederick Kautz, and Laura GuazzelliGitHub Octodex: Meet the OctocatsLinux Foundation ProjectsGet involved with the OpenSSFSubscribe to the OpenSSF newsletterFollow the OpenSSF on LinkedIn

    Building the Agentic Future with Angie Jones
  2. Sep 22

    Securing the Source: Navigating AI Velocity, CRA Compliance, and Dependency Debt with Abby Kearns

    In this episode of What’s in the SOSS, host Sally Cooper sits down with technology executive and ActiveState CEO Abby Kearns to break down the rapidly evolving open source security landscape. Together, they dissect why reactive post-build scanning fails to prevent dependency debt, how machine-speed AI ingestion is overwhelming human maintainers, and what the impending EU Cyber Resilience Act (CRA) mandates mean for enterprise software supply chains. Abby offers actionable insights into why building a "start secure, stay secure" paradigm is essential for modern software pipelines and why open source communities must unite to redefine repository economics in an AI-dominated world. Chapters: 00:00 - Introduction: Sally Cooper welcomes Active State CEO Abby Kearns to discuss AI, vulnerability management, and open source security.01:27 - The Limits of Reactive Scanning: Why controlling components at the build source beats post-build scanners.04:26 - AI Agents and Ingestion Risk: Managing governance and dependency debt when code moves at automated machine speed.07:27 - Regulatory Pressures & The CRA: Preparing for 24-hour vulnerability reporting deadlines and mandatory SBOM provenance.11:00 - Upstream Package Repository Economics: Addressing maintainer burnout and the influx of AI-generated PRs.14:02 - The True Cost of Exposure: Mitigating enterprise risk across foundational open source language libraries.16:27 - Rapid Fire Round: Tux the Penguin, favorite emojis, time travel, and key takeaways for the community. Episode links: Abby Kearns’ LinkedIn PageActive State WebsiteEU Cyber Resilience Act (CRA) OverviewLinux Foundation ProjectsGet involved with the OpenSSFSubscribe to the OpenSSF newsletterFollow the OpenSSF on LinkedIn

    Securing the Source: Navigating AI Velocity, CRA Compliance, and Dependency Debt with Abby Kearns
  3. Sep 8

    Balancing AI's Double-Edged Sword: Software Engineering, Unlearning, and Ecosystem Sustainability with Mark Russinovich

    In this episode of What's in the SOSS?, host CRob sits down with Mark Russinovich – CTO and Deputy CISO of Azure, as well as Board Chair for the Open Source Security Foundation (OpenSSF) – for a wide-ranging conversation on the changing landscape of software security. Mark shares insights from his journey from Sysinternals to Azure leadership, exploring how generative AI is delivering dramatic productivity boosts while creating new talent pipeline challenges for early-in-career engineers. The discussion dives into the shift toward hardware-backed "what, not who" supply chain identity, the urgent rolling Y2K effort to fix AI-discovered vulnerabilities via initiatives like Accretis, and the reality of persistent AI hallucinations. Finally, Mark details OpenSSF's strategic priorities for package registry sustainability and gives a sneak peek into his personal vibe-coded side projects like Polypost.  Chapters: 00:00 – Sysinternals & Career Journey: Mark reflects on his transition from Sysinternals to Microsoft Azure leadership.  02:08 – OpenSSF Board Leadership: Mark outlines his vision and key priorities as the new OpenSSF Board Chair. 03:32 – Corporate & Community Alignment: How Microsoft balances its enterprise goals with open source community needs.  05:40 – AI's Impact on Software Engineering: Why AI coding shifts developer roles toward architecture, review, and preceptorships.  12:35 – Finding vs. Fixing Vulnerabilities: Managing the rapid race against AI-assisted threats across modern systems.  16:07 – LLM Code Quality & Edge Cases: Exploring prompt specification limits and unexpected model behaviors.  22:07 – Navigating AI Hallucinations: Why model hallucinations persist despite web grounding and how experts mitigate them.  26:34 – Supply Chain: Shifting "Who" to "What": Establishing identity using hardware attestation and confidential computing.  30:44 – Machine Unlearning & Model Safety: Mark details his research on targeted unlearning and model alignment experiments.  34:06 – Rapid Response & Accretis: Standing up coordinated responses to patch critical open source vulnerabilities.  39:39 – Package Registry Sustainability: Securing package repositories and building sustainable funding models.  45:44 – Personal Projects & Vibe-Coding: Mark discusses his current AI coding stack, Polypost, and gaming.  53:44 – Rapid Fire Round: Quick takes on Emacs, Star Wars, and favorite dystopian robots. Episode links: Mark Russinovich’s LinkedIn pageMicrosoft AzureOpenSSF Guide: Principles for Package Repository SecurityWho's Harry Potter? Approximate Unlearning in LLMs PaperHALU Bench: Hallucination Benchmark ResearchSCITT (Supply Chain Integrity, Transparency, and Trust - IETF)Microsoft Signing TransparencyPolypost GitHubPolypost WebAppGet involved with the OpenSSFLearn more about the OpenSSF Governing BoardSubscribe to the OpenSSF NewsletterFollow the OpenSSF on LinkedIn

  4. Sep 1

    Navigating the New Era: The EU Cyber Resilience Act Explained with Madalin Neag

    In this episode of What’s in the SOSS, host Sally Cooper is joined by Madalin Neag, EU Policy Advisor at the OpenSSF, to demystify the European Union’s Cyber Resilience Act (CRA). As the tech industry shifts from treating open source as a free buffet to navigating a new era of regulatory liability, Madalin explains how the CRA establishes a horizontal cybersecurity baseline for digital products. The conversation explores the innovative concept of "open source software stewards," the importance of moving beyond passive consumption to active upstream contribution, and why compliance should be viewed as an outcome of good engineering rather than a separate checkbox exercise. Whether you are a manufacturer of smart devices or a volunteer maintainer, this episode provides essential insights into how the CRA will reshape the global software supply chain, encouraging a secure-by-design mindset that strengthens the entire digital ecosystem. Chapters: 00:23 - Introductions and Madalin’s role at OpenSSF 03:42 - What is the Cyber Resilience Act (CRA)? 05:27 - The CRA in the global regulatory landscape 09:05 - Relevance to open source and the "Software Steward" concept 13:02 - Moving from passive consumption to upstream contribution 16:20 - Practical steps for organizational readiness 20:26 - Should open source maintainers be worried? 24:12 - Insights from the Linux Foundation CRA Readiness Report 31:32 - What to watch for in the coming year 34:07 - Rapid fire round and concluding thoughts Episode links: Madalin Neag’s LinkedIn pageCyber Resilience Act - ImplementationGlobal Cyber Policy Working GroupLinux Foundation 2026 CRA Awareness and Readiness ReportCase Study: Defending the Open Source Supply Chain in a New Regulatory EraOpenSSF’s Global Cyber Policy Working Group European Union Cyber Resilience Act (CRA) Information, Resources & Guides PageOpen Source Project Security Baseline (OSPS)SLSAGemaraGUACOpenSSF ProjectsUnderstanding the EU Cyber Resilience Act (CRA) (LFEL1001)Global Cyber Policy GitHub RepositoryJoin us at Open Source Summit and OpenSSF Community Day in Prague Get involved with the OpenSSFSubscribe to the OpenSSF newsletterFollow the OpenSSF on LinkedIn

    Navigating the New Era: The EU Cyber Resilience Act Explained with Madalin Neag
  5. Aug 25

    Private Forks, CRA Deadlines, and the True Cost of Open Source Compliance with Dave Russo

    In this episode of What's in the SOSS, host Sally Cooper sits down with returning champion Dave Russo, Policy and Standards Lead at Red Hat’s Open Source and AI Program Office, to unpack the European Union’s Cyber Resilience Act (CRA). Together, they explore the stark realities of the 2026 CRA Awareness and Readiness Report, exposing why three-quarters of North American tech companies remain completely unaware of the strictest cybersecurity mandate in history. Dave breaks down the hidden $250,000-per-release financial toll of maintaining private forks, the crucial legal distinction between software manufacturers and open source stewards, and Red Hat's framework for "champion stewardship." Whether you are facing the upcoming September 2026 vulnerability reporting platform launch or preparing for full December 2027 enforcement, this conversation delivers clear, actionable guidance to get your organization compliant, collaborative, and secure.  Chapters: 00:25 - Welcome & Introductions01:28 - Meet Dave Russo02:01 - The Global CRA Awareness Gap04:46 - The Hidden Cost of Private Forks07:32 - Manufacturer vs. Open Source Steward09:09 - Red Hat's Light vs. Champion Stewardship11:37 - Crucial CRA Deadlines Explained13:51 - Actionable Compliance Steps Today16:47 - Rapid Fire FunEpisode links: Dave Russo’s LinkedIn pageGlobal Cyber Policy Working Group (policy.openssf.org)European Commission CRA Implementation WebsiteEuropean Commission CRA GuidanceEuropean Commission CRA FAQOpen Regulatory Compliance Working GroupOpen Resources for Baselines, Interoperability and Tooling (ORBIT) Working GroupOpen Source Project Security (OSPS) BaselineOpenSSF’s Global Cyber Policy Working Group European Union Cyber Resilience Act (CRA) Information, Resources & Guides PageLF Training Course: Understanding the EU Cyber Resilience Act (CRA) (LFEL1001)Global Cyber Policy GitHub RepositoryAdd any other applicable links related to the episodeOpenSSF Community CalendarGet involved with the OpenSSFSubscribe to the OpenSSF newsletterFollow the OpenSSF on LinkedIn

    Private Forks, CRA Deadlines, and the True Cost of Open Source Compliance with Dave Russo
  6. Aug 18

    Watering the Community Garden: Navigating the EU CRA for Open Source with Roman Zhukov

    The clock is ticking toward the European Union’s Cyber Resilience Act (CRA) deadlines, yet a staggering 66% of organizations remain completely unaware of what is coming. In this episode of What’s in the SOSS? host Sally sits down with Roman Zhukov, co-chair of the OpenSSF Global Cyber Policy Working Group and Security Communities Lead at Red Hat, to demystify this sweeping regulation. Using a brilliant "community garden" analogy, Roman breaks down the distinct roles of maintainers, stewards, and manufacturers under the law, illustrating why the traditional "consume and forget" model of open source is officially dead. They dive deep into the newly released 2026 CRA Awareness and Readiness Report, exposing the staggering $250,000+ engineering tax of maintaining private forks and detailing how active upstream collaboration is no longer just good citizenship—it’s a business and legal necessity. Tune in to discover actionable strategies, free educational resources, and how we can collectively bake "compliance as code" into the open source ecosystem.  Chapters: 00:01 – Introduction: The CRA Countdown is On02:04 – Tomatoes, Gardens, and Restaurants: Defining the CRA Personas06:40 – Reality Check: Shocking Findings from the 2026 Readiness Report10:12 – The Awareness Gap: Why Are We Ignoring the Warning Signs?15:01 – The End of "Consume and Forget"17:49 – The Private Fork Tax: A $250K Engineering Trap23:34 – Red Hat’s Blueprint & Free Community Security Tools28:44 – Taming the AI Vulnerability Tsunami31:27 – Build Your Program Now: Action Steps for Manufacturers36:12 – Supporting SMEs & Navigating Free Resources40:30 – Carrying the Torch as an OpenSSF Ambassador43:35 – Rapid Fire & How to Get InvolvedEpisode links: Roman Zhukov’s LinkedIn pageCyber Resilience Act - ImplementationGlobal Cyber Policy Working GroupLinux Foundation 2026 CRA Awareness and Readiness ReportCase Study: Defending the Open Source Supply Chain in a New Regulatory EraOpenSSF’s Global Cyber Policy Working Group European Union Cyber Resilience Act (CRA) Information, Resources & Guides PageOpen Source Project Security Baseline (OSPS)SLSAGemaraGUACOpenSSF ProjectsUnderstanding the EU Cyber Resilience Act (CRA) (LFEL1001)Global Cyber Policy GitHub RepositoryGet involved with the OpenSSFSubscribe to the OpenSSF newsletterFollow the OpenSSF on LinkedIn

    Watering the Community Garden: Navigating the EU CRA for Open Source with Roman Zhukov
  7. Aug 11

    CRA Readiness: Practical Strategies for Open Source Communities with Megan Knight

    In this episode of What's in the SOSS, host Sally sits down with Megan Knight, Director of Software Communities at ARM, OpenSSF Board Member, and Chair of the Awareness SIG within the Global Cyber Policy Working Group. Together, they break down the upcoming European Union Cyber Resilience Act (CRA) and address the persistent gap in ecosystem awareness. Megan outlines concrete, practical strategies for maintainers and organizations, highlights the vital role of community collaboration across working groups like ORBIT and ORC, and shares key resources to help lower the barrier to compliance. Stick around for a fun rapid-fire round where favorite open source mascots steal the spotlight!  Chapters: 00:24 - Introduction and Welcome 01:44 - The current CRA landscape and key findings from recent LF Research reports.  04:23 - Actionable compliance steps for maintainers and organizations  07:16 - The mission of the OpenSSF Global Cyber Policy Working Group  10:28 - How to get involved  13:25 - Rapid-fire 15:12 - Key takeaways and resources for a deeper dive into CRA readiness Episode links: Megan Knight’s LinkedIn pageCyber Resilience Act - ImplementationGlobal Cyber Policy Working Group (policy.openssf.org)Linux Foundation 2025 CRA Awareness and Readiness ReportLinux Foundation 2026 CRA Awareness and Readiness ReportOpen Regulatory Compliance Working GroupOpen Resources for Baselines, Interoperability and Tooling (ORBIT) Working GroupOpen Source Project Security (OSPS) BaselineOpenSSF’s Global Cyber Policy Working Group European Union Cyber Resilience Act (CRA) Information, Resources & Guides PageLF Training Course: Understanding the EU Cyber Resilience Act (CRA) (LFEL1001)Global Cyber Policy GitHub RepositoryAdd any other applicable links related to the episodeOpenSSF Community CalendarGet involved with the OpenSSFSubscribe to the OpenSSF newsletterFollow the OpenSSF on LinkedIn

    CRA Readiness: Practical Strategies for Open Source Communities with Megan Knight
  8. Aug 4

    Funding the Future: Community Collaboration and the Spirit of Open Source with Mila Zhou

    Join host Yesenia as she sits down with Mila Zhou, Open Source Program Manager at AWS, to explore the fascinating intersection of finance, strategy, and security in the open source ecosystem. Mila shares her unique journey from forensic auditing to spearheading AWS funding initiatives, breaking down how strategic financial backing transforms vulnerable "long tail" projects and empowers dedicated security champions. Discover how full-time security engineers at foundations are securing critical repositories like PyPI, why community-driven forks like Valkey represent the true spirit of collaboration, and how the OpenSSF Ambassador Program is helping close the gap between developers and security experts.  Chapters: 00:25 - Welcome & Introductions01:03 - From Accounting to AWS OSPO06:26 - A Day in the Life of an OSPO Program Manager09:53 - Navigating Critical Funding & The Long Tail13:25 - Valkey and Community-Driven Innovation15:29 - The Invisible Power of Dedicated Security Engineers28:46 - Marketing, Non-Code Contributions, and the Ambassador Program36:25 - Rapid Fire Fun37:05 - Final Thoughts & Closing Episode links: Miaolai (Mila) Zhou’s LinkedIn pageAlpha-Omega WebsiteAlpha-Omega Public RepositoryValkeyMike Fiedler’s LinkedInSeth Larson’s LinkedInYesenia’s Blog on Building a Team of Open Source Security Engineers in ResidenceThe Hidden Heroes: How Non-Code Contributors Find Their Place in Open Source Communities - Miaolai Zhou & Lahari Chowtoori, AWSOpenSSF Ambassador ProgramGet involved with the OpenSSFSubscribe to the OpenSSF NewsletterFollow the OpenSSF on LinkedIn

    Funding the Future: Community Collaboration and the Spirit of Open Source with Mila Zhou

Ratings & Reviews

5
out of 5
2 Ratings

About

What's in the SOSS? features the sharpest minds in security as they dig into the challenges and opportunities that create a recipe for success in making software more secure. Get a taste of all the ingredients that make up secure open source software (SOSS) and explore the latest trends at the intersection of AI and security, vulnerability management, and threat assessments. Each episode of What's in the SOSS? is packed with valuable insight designed to foster collaboration and promote stronger security practices for the open source software community.About Christopher Robinson (aka CRob), hostCRob is a 43rd level Dungeon Master and a 26th level Securityologist. He is a leader within several Open Source Security Foundation (OpenSSF) efforts and is a frequent speaker on cyber, application, and open source security. He enjoys hats, herding cats, and moonlit walks on the beach.

You Might Also Like