
How Open Source Projects Coordinate Security Vulnerability Disclosures
When a critical vulnerability is discovered in open source software, the path from discovery to patch is a delicate dance of secrecy, coordination, and trust. This episode uses the 2024 xz backdoor and the Heartbleed bug as case studies to explore how maintainers, security researchers, and downstream distributors handle embargoes, disclosure timelines, and the tension between transparency and safety. Lucas and Luna examine the role of foundations like the Open Source Security Foundation (OpenSSF), the CVE system, and the often-overlooked burden on volunteer maintainers. They also discuss what listeners can do to stay secure and support the infrastructure projects that power the internet.
#SecurityVulnerabilityDisclosure #OpenSourceSecurity #xzBackdoor #Heartbleed #OpenSSF #CVE #CoordinatedDisclosure #MaintainerBurnout #SupplyChainSecurity #Linux #LucasAndLuna #FexingoBusiness #BusinessPodcast #Technology #OpenSourceGovernance #SecurityResearcher #EmbargoPolicy #DownstreamCoordination
Keep every episode free: buymeacoffee.com/fexingo
Information
- Show
- FrequencyUpdated Daily
- PublishedJuly 26, 2026 at 8:39 AM UTC
- Length7 min
- Season3
- Episode132
- RatingClean