Find partners
What's in the SOSS? An OpenSSF Podcast

What's in the SOSS? An OpenSSF Podcast

Hosted by OpenSSF

TechnologyInterviews guests

Episodes

69

Latest episode

Aug 2026

Language

EN-US

About the show

What's in the SOSS? features the sharpest minds in security as they dig into the challenges and opportunities that create a recipe for success in making software more secure. Get a taste of all the ingredients that make up secure open source software (SOSS) and explore the latest trends at the intersection of AI and security, vulnerability management, and threat assessments. Each episode of What's in the SOSS? is packed with valuable insight designed to foster collaboration and promote stronger security practices for the open source software community. About Christopher Robinson (aka CRob), host CRob is a 43rd level Dungeon Master and a 26th level Securityologist. He is a leader within several Open Source Security Foundation (OpenSSF) efforts and is a frequent speaker on cyber, application, and open source security. He enjoys hats, herding cats, and moonlit walks on the beach.

Listen to episodes

60 recent
August 25, 2026Episode 2218 min

Private Forks, CRA Deadlines, and the True Cost of Open Source Compliance with Dave Russo

In this episode of What's in the SOSS, host Sally Cooper sits down with returning champion Dave Russo, Policy and Standards Lead at Red Hat’s Open Source and AI Program Office, to unpack the European Union’s Cyber Resilience Act (CRA). Together, they explore the stark realities of the 2026 CRA Awareness and Readiness Report, exposing why three-quarters of North American tech companies remain completely unaware of the strictest cybersecurity mandate in history. Dave breaks down the hidden $250,000-per-release financial toll of maintaining private forks, the crucial legal distinction between software manufacturers and open source stewards, and Red Hat's framework for "champion stewardship." Whether you are facing the upcoming September 2026 vulnerability reporting platform launch or preparing for full December 2027 enforcement, this conversation delivers clear, actionable guidance to get your organization compliant, collaborative, and secure. Chapters: 00:25 - Welcome & Introductions 01:28 - Meet Dave Russo 02:01 - The Global CRA Awareness Gap 04:46 - The Hidden Cost of Private Forks 07:32 - Manufacturer vs. Open Source Steward 09:09 - Red Hat's Light vs. Champion Stewardship 11:37 - Crucial CRA Deadlines Explained 13:51 - Actionable Compliance Steps Today 16:47 - Rapid Fire Fun Episode links: Dave Russo’s LinkedIn page Global Cyber Policy Working Group ( policy.openssf.org ) European Commission CRA Implementation Website European Commission CRA Guidance European Commission CRA FAQ Open Regulatory Compliance Working Group Open Resources for Baselines, Interoperability and Tooling (ORBIT) Working Group Open Source Project Security (OSPS) Baseline OpenSSF’s Global Cyber Policy Working Group European Union Cyber Resilience Act (CRA) Information, Resources & Guides Page LF Training Course: Understanding the EU Cyber Resilience Act (CRA) (LFEL1001) Global Cyber Policy GitHub Repository Add any other applicable links related to the episode OpenSSF Community Calendar Get involved with the OpenSSF Subscribe to the OpenSSF newsletter Follow the OpenSSF on LinkedIn

August 18, 2026Episode 2147 min

Watering the Community Garden: Navigating the EU CRA for Open Source with Roman Zhukov

The clock is ticking toward the European Union’s Cyber Resilience Act (CRA) deadlines, yet a staggering 66% of organizations remain completely unaware of what is coming. In this episode of What’s in the SOSS? host Sally sits down with Roman Zhukov, co-chair of the OpenSSF Global Cyber Policy Working Group and Security Communities Lead at Red Hat, to demystify this sweeping regulation. Using a brilliant "community garden" analogy, Roman breaks down the distinct roles of maintainers, stewards, and manufacturers under the law, illustrating why the traditional "consume and forget" model of open source is officially dead. They dive deep into the newly released 2026 CRA Awareness and Readiness Report, exposing the staggering $250,000+ engineering tax of maintaining private forks and detailing how active upstream collaboration is no longer just good citizenship—it’s a business and legal necessity. Tune in to discover actionable strategies, free educational resources, and how we can collectively bake "compliance as code" into the open source ecosystem. Chapters: 00:01 – Introduction: The CRA Countdown is On 02:04 – Tomatoes, Gardens, and Restaurants: Defining the CRA Personas 06:40 – Reality Check: Shocking Findings from the 2026 Readiness Report 10:12 – The Awareness Gap: Why Are We Ignoring the Warning Signs? 15:01 – The End of "Consume and Forget" 17:49 – The Private Fork Tax: A $250K Engineering Trap 23:34 – Red Hat’s Blueprint & Free Community Security Tools 28:44 – Taming the AI Vulnerability Tsunami 31:27 – Build Your Program Now: Action Steps for Manufacturers 36:12 – Supporting SMEs & Navigating Free Resources 40:30 – Carrying the Torch as an OpenSSF Ambassador 43:35 – Rapid Fire & How to Get Involved Episode links: Roman Zhukov’s LinkedIn page Cyber Resilience Act - Implementation Global Cyber Policy Working Group Linux Foundation 2026 CRA Awareness and Readiness Report Case Study: Defending the Open Source Supply Chain in a New Regulatory Era OpenSSF’s Global Cyber Policy Working Group European Union Cyber Resilience Act (CRA) Information, Resources & Guides Page Open Source Project Security Baseline (OSPS) SLSA Gemara GUAC OpenSSF Projects Understanding the EU Cyber Resilience Act (CRA) (LFEL1001) Global Cyber Policy GitHub Repository Get involved with the OpenSSF Subscribe to the OpenSSF newsletter Follow the OpenSSF on LinkedIn

August 11, 2026Episode 2016 min

CRA Readiness: Practical Strategies for Open Source Communities with Megan Knight

In this episode of What's in the SOSS, host Sally sits down with Megan Knight, Director of Software Communities at ARM, OpenSSF Board Member, and Chair of the Awareness SIG within the Global Cyber Policy Working Group. Together, they break down the upcoming European Union Cyber Resilience Act (CRA) and address the persistent gap in ecosystem awareness. Megan outlines concrete, practical strategies for maintainers and organizations, highlights the vital role of community collaboration across working groups like ORBIT and ORC, and shares key resources to help lower the barrier to compliance. Stick around for a fun rapid-fire round where favorite open source mascots steal the spotlight! Chapters: 00:24 - Introduction and Welcome 01:44 - The current CRA landscape and key findings from recent LF Research reports. 04:23 - Actionable compliance steps for maintainers and organizations 07:16 - The mission of the OpenSSF Global Cyber Policy Working Group 10:28 - How to get involved 13:25 - Rapid-fire 15:12 - Key takeaways and resources for a deeper dive into CRA readiness Episode links: Megan Knight’s LinkedIn page Cyber Resilience Act - Implementation Global Cyber Policy Working Group (policy.openssf.org) Linux Foundation 2025 CRA Awareness and Readiness Report Linux Foundation 2026 CRA Awareness and Readiness Report Open Regulatory Compliance Working Group Open Resources for Baselines, Interoperability and Tooling (ORBIT) Working Group Open Source Project Security (OSPS) Baseline OpenSSF’s Global Cyber Policy Working Group European Union Cyber Resilience Act (CRA) Information, Resources & Guides Page LF Training Course: Understanding the EU Cyber Resilience Act (CRA) (LFEL1001) Global Cyber Policy GitHub Repository Add any other applicable links related to the episode OpenSSF Community Calendar Get involved with the OpenSSF Subscribe to the OpenSSF newsletter Follow the OpenSSF on LinkedIn

August 4, 2026Episode 1938 min

Funding the Future: Community Collaboration and the Spirit of Open Source with Mila Zhou

Join host Yesenia as she sits down with Mila Zhou, Open Source Program Manager at AWS, to explore the fascinating intersection of finance, strategy, and security in the open source ecosystem. Mila shares her unique journey from forensic auditing to spearheading AWS funding initiatives, breaking down how strategic financial backing transforms vulnerable "long tail" projects and empowers dedicated security champions. Discover how full-time security engineers at foundations are securing critical repositories like PyPI, why community-driven forks like Valkey represent the true spirit of collaboration, and how the OpenSSF Ambassador Program is helping close the gap between developers and security experts. Chapters: 00:25 - Welcome & Introductions 01:03 - From Accounting to AWS OSPO 06:26 - A Day in the Life of an OSPO Program Manager 09:53 - Navigating Critical Funding & The Long Tail 13:25 - Valkey and Community-Driven Innovation 15:29 - The Invisible Power of Dedicated Security Engineers 28:46 - Marketing, Non-Code Contributions, and the Ambassador Program 36:25 - Rapid Fire Fun 37:05 - Final Thoughts & Closing Episode links: Miaolai (Mila) Zhou’s LinkedIn page Alpha-Omega Website Alpha-Omega Public Repository Valkey Mike Fiedler’s LinkedIn Seth Larson’s LinkedIn Yesenia’s Blog on Building a Team of Open Source Security Engineers in Residence The Hidden Heroes: How Non-Code Contributors Find Their Place in Open Source Communities - Miaolai Zhou & Lahari Chowtoori, AWS OpenSSF Ambassador Program Get involved with the OpenSSF Subscribe to the OpenSSF Newsletter Follow the OpenSSF on LinkedIn

July 28, 2026Episode 1833 min

Turning AI into the Ultimate Open Source Maintainer Power Tool with Michael Winser

In this episode of What’s in the SOSS? , host CRob welcomes back open source security champion Michael Winser to reflect on Alpha-Omega’s spectacular milestone of surpassing $20 million in security grants. Michael breaks down how their mission has evolved from simply chasing bugs to acting as a catalyst for sustainable, long-term security culture across critical projects. The two dive deep into the unsustainable economics of package repositories—the "app stores" of software development —and address how a massive partnership with frontier AI model providers is aiming to flip the script on AI. Instead of fueling endless, low-context vulnerability "slop," Alpha-Omega is working to put AI assists directly into the hands of maintainers as their ultimate defensive power tool. Chapters: 00:24 - Welcome Back, Michael Winser! 01:10 - The Origin Story of a $20 Million Milestone 04:54 - Evolving Beyond Audits to "Sustainable Security" 11:18 - The Messy Economics of Package Registries 20:28 - Turning AI into the Maintainer’s Power Tool 29:01 - Vision for 2026: The Security Trust Graph Episode links: Michael Winser’s LinkedIn page Alpha-Omega Website Alpha-Omega Public Repository Learn more about the Security Engineers in Residence (SEIR) Roles Andrew Nesbitt OpenSSF Securing Software Repositories Working Group Get involved with the OpenSSF Subscribe to the OpenSSF newsletter Follow the OpenSSF on LinkedIn

July 14, 2026Episode 1721 min

Signing the Future: Securing AI and ML Artifacts with Mihai Maruseac

In this episode of What’s in the SOSS?, host Yesenia Yser sits down with Mihai Maruseac, the lead of the OpenSSF AI/ML Working Group and Security and Privacy expert at OpenAI, to dive deep into the unique security challenges facing artificial intelligence. Unlike traditional software packages, AI models cannot simply be inspected for malware by looking at their weights – malicious code only exposes itself upon execution. Mihai outlines how the community is answering this threat through the evolution of the OpenSSF Model Signing (OMS) specification. Discover how OMS creates an unshakeable chain of custody for models, data sets, and agent workflows, the structural shift toward implementation-agnostic toolchains, and what the future looks like for a fully realized, end-to-end secure AI supply chain. Chapters: 00:22 – Welcome: Yesenia introduces AI/ML Working Group lead Mihai Maruseac. 00:51 – From TensorFlow to OpenAI: Mihai’s journey navigating open source security and AI. 01:47 – Core Risks of Model Tampering: A look at hidden risks inside uninspectable model weights. 03:27 – Establishing Chain of Custody: How cryptographic signatures verify file integrity from training to deployment. 05:04 – Evolution of the OMS Spec: Why the community standardized on forward-compatible, framework-agnostic formats. 07:17 – Tracking Iteration (v1.1 & v1.2): An overview of newly introduced security keys and community features. 08:26 – Choosing Your PKI Tooling: Why the OMS specification remains highly flexible for users. 10:22 – Real-World Integration: Early success stories with Kaggle, NVIDIA, and the path to PyTorch. 12:42 – Looking Ahead to Version 2: Overcoming "attestation sprawl" by unifying multiple security claims. 15:29 – The Ideal AI Supply Chain: Using signed artifacts with GUAC to automatically map vulnerabilities. 17:09 – How to Get Involved: Immediate opportunities to contribute to signature format convergence. 18:11 – Rapid Fire Segment: Mihai shares his favorite retro games, hiking, and love for Vim. 19:37 – Final Words of Advice: Why contributors of all skill levels are welcome to join. Episode links: Mihai Maruseac’s LinkedIn Page OpenSSF Model Signing (OMS) OpenSSF Model Signing Spec GitHub Repo OpenSSF AI/ML Working Group OpenSSF Guide: Visualizing Secure MLOps (MLSecOps): A Practical Guide for Building Robust AI/ML Pipeline Security Graph for Understanding Artifact Composition (GUAC) Sigstore In-toto Ollama Get involved with the OpenSSF Subscribe to the OpenSSF newsletter Follow the OpenSSF on LinkedIn

June 30, 2026Episode 1634 min

The Heartbeat of the Kernel: Why Upstream is the Ultimate Security Strategy with Greg Kroah-Hartman

What does it feel like to wake up and realize your weekend passion project is now the critical infrastructure powering the planet? In this episode of What’s in the SOSS?, CRob sits down with Linux kernel maintainer and open source icon Greg Kroah-Hartman. Greg takes us on a journey from his early days writing firmware for printer and hospital ATMs to managing the relentless, everyday engineering task of maintaining the Linux kernel over decades. He breaks down the realities of modern kernel security, dismantles the myth that maintainers know every single vulnerability exploit , and details how looming global regulations like the EU's Cyber Resilience Act (CRA) are shifting the compliance burden onto vendors. If your organization uses Linux, Greg has a simple, urgent message for you: stop fearing change, build your testing infrastructure, and update your systems. Chapters: 00:03 - Welcome: Host CRob introduces Linux kernel legend Greg Kroah-Hartman. 01:04 - From Printers to Richard Stallman: Greg shares his origin story in embedded engineering and his introduction to free software. 02:00 - The Weekend Driver and the Dopamine Hit: How a quick weekend project turned Greg into a lifelong kernel contributor. 04:20 - Realizing Linux is Critical Infrastructure: The moment the telcos and banks moved in, signaling that Linux was everywhere. 05:28 - 2005: The Year the Kernel Grew Up: Implementing stable releases, the security team, and the rule to never break user space. 07:05 - What People Get Wrong About Kernel Security: Linus's mantra that "a bug is a bug," and the reality of handling 35 fixes a day. 09:32 - The Historic Fear of Updating: Why lagging behind for "stability" is actually incurring massive risk. 12:17 - Global Regulation and the Cyber Resilience Act (CRA): How upcoming laws are changing vendor responsibility and why the open source community is exempt. 13:51 - How OpenSSF is Reducing the Burden: Applauding the cross-ecosystem collaboration that protected maintainers from onerous drafts. 17:05 - Pay Your Employees to Contribute: Greg’s best piece of advice for downstream enterprises relying on open source. 18:39 - Inside the Kernel Security Alias: How the ad-hoc security team handles triage and assigns CVEs. 21:11 - The CVE Numbers Game: Why the kernel ranks #2 in CVE creation and the trouble with automated severity scores. 25:39 - We are Already There: AI Slop and Static Analysis: Greg addresses the recent surge of AI-generated bug reports and patches. 31:20 - Rapid Fire Round: Spicy food, coffee, Star Wars, and the ultimate call to action. Episode links: Greg Kroah-Hartman’s LinkedIn page The Linux Foundation CRA Stewards Playbook OpenSSF Global Cyber Policy Working Group The Linux Kernel Archive (Keep your systems current with the latest stable kernel releases) The Value of Open Source Software Additional Resources Get involved with the OpenSSF Subscribe to the OpenSSF newsletter Follow the OpenSSF on LinkedIn

June 16, 2026Episode 1529 min

Consuming with Intent: Driving Enterprise Security and Career Growth Through Open Source with Jamie Thomas (IBM)

In this episode of Big Thoughts, Open Sources, host CRob sits down with Jamie Thomas, IBM Enterprise Security Executive and OpenSSF Governing Board Member (former Chair!), to tackle the vital shifting dynamics of enterprise open source engagement. From IBM's historical "billion-dollar bet" on Linux to modern supply chain wake-up calls like SolarWinds and Log4j, Jamie pulls back the curtain on what it truly means to move from accidental consumption to intentional stewardship. Tune in to discover how active participation in neutral foundations like the OpenSSF acts as a fast track for engineering career trajectories, why soft skills like "the art of influence" are critical for upstream collaboration, and how organizations can protect their crown jewels while implementing a powerful "give-back strategy." Chapters: 00:00 – Intro Music + Promo Clip 00:21 – Introduction & Welcoming Luminary Jamie Thomas 01:32 – Wearing the Enterprise Security Hat at IBM 02:10 – Supply Chain Wake-up Calls: From SolarWinds to Log4j 03:14 – Unlocking Open Ecosystems: IBM’s Early History with Java and Linux 05:21 – Mainframe Debates and Portability: The Evolution of Open Source Adoption 06:24 – The Red Hat Acquisition and Monetizing the Developer Ecosystem 08:20 – The Myth of "Free" Software: Securing Regulated Enterprise Deployment 10:15 – Why a Seat at the Table Matters: The Value of Neutral Foundations 11:29 – The Art of Influence: Upstream Contributions as a Career Catalyst 13:50 – Moving Innovation from Open Source Kernels to Commercial Value 16:12 – Storming, Norming, and Conversation: Lessons from the Kubernetes Era 17:38 – Pitching Upstream Time: Helping Developers Sell Open Source to Management 19:30 – Beyond Code: Bringing Domain Expertise and Soft Skills Upstream 21:40 – Conquering the Chasm: Automating CI/CD Pipelines and Testing at Scale 23:00 – Consuming with Intent: Active Stewardship and the OpenSSF Scorecard 25:21 – Rapid Fire Round: Mainframes, AI-Generated Code, and Star Trek nostalgia 27:53 – Call to Action: Crafting Your Organization's "Give-Back Strategy" Episode links: Jamie Thomas’ LinkedIn page Learn more about IBM’s Strong History and Commitment to Open Source Red Hat Eclipse Foundation CNCF Get involved with the OpenSSF Learn more about the OpenSSF Governing Board Subscribe to the OpenSSF Newsletter Follow the OpenSSF on LinkedIn

June 2, 2026Episode 1426 min

The Ghost in the Dependency Tree: Navigating Open Source End-of-Life with HeroDevs

In this episode of What’s in the SOSS, host CRob sits down with Isaac Wuest, Product Line Leader at HeroDevs, to explore the critical and often overlooked "gray area" of the software supply chain: End-of-Life (EOL) software. While the industry heavily relies on CVEs to track vulnerabilities, Isaac explains how maintainer abandonment creates a vacuum where risks are present but remain undiscovered and unreported. From the origins of HeroDevs supporting AngularJS to the nuances of the EU Cyber Resilience Act (CRA), this conversation provides a practical framework for distinguishing between inherent hazards and actual risk in your dependency tree. Chapters: 00:04 - CRob welcomes Isaac Wuest from HeroDevs 00:45 - The HeroDevs origin story: How Google sunsetting AngularJS created a need for secure drop-in replacements. 02:44 - Isaac’s path to open source: Transitioning from product management to supporting maintainers. 04:06 - Exploring the "Gap" in CVEs: Why dictionary-based vulnerability tracking misses EOL and malicious packages. 07:03 - The challenge of "Maintainer Attestation": Why most open source projects lack a formal EOL calendar. 09:52 - Compliance and Risks: How EOL dependencies create blank spots for security professionals and auditors. 11:27 - The Shark in the Tank: Using a food regulation analogy to differentiate between hazard and risk. 13:22 - Navigating the EU Cyber Resilience Act: Preparing for increased manufacturer accountability in software. 14:08 - Maintainer Abandonment: Identifying the moment a project stops receiving patches without formal notice. 16:14 - Scanning for Gaps: Why standard industry tools currently struggle to provide a complete EOL picture. 18:49 - Practical Remediation: Recommendations for researching upgrade paths using tools like endoflife.date. 20:49 - Analyzing SBOMs: How engineers can leverage free datasets to identify and fix deep dependency risks. 23:00 - Rapid Fire: Coffee, Star Wars, spicy food, and the favorite apocalyptic robot. 25:01 - Final Thoughts: A call to action for educating yourself on your application's EOL exposure. Episode links: Isaac Wuest’s LinkedIn page HeroDevs Free Tool: End of Life Data Set Community Resource: endoflife.date Get involved with the OpenSSF Subscribe to the OpenSSF newsletter Follow the OpenSSF on LinkedIn

May 19, 2026Episode 1325 min

Beginner to Builder: Shaping the Conversation in Open Source Security

In this episode of What's in the SOSS, Yesenia Yser interviews cybersecurity analyst Ejiro Oghenekome about her journey from UI/UX design to becoming a key contributor to the OpenSSF. Ejiro shares the inspiration behind her public "100 Days of Cybersecurity" challenge, which has helped her maintain discipline and consistency while making the field less intimidating for beginners. She discusses how connecting with the OpenSSF community led her to the BEAR Working Group, where her authorship of the "Beginner to Builder" blog series has allowed her to move from consuming content to actively shaping the open source security conversation. Ejiro also offers advice to the next generation, emphasizing that open source contribution is not just about coding but is a welcoming space for anyone to learn and grow, regardless of their current expertise. Episode links: Ejiro (Sonia) Oghenekome LinkedIn page Ejiro’s GitHub page BEAR Working Group Ejiro’s OpenSSF Beginner to Builder Blog Series: Blog #1: From Beginner to Builder: Understanding OpenSSF Community and Working Groups Blog #2: From Beginner to Builder: Your First Code Contribution Blog #3: From Beginner to Builder: Free OpenSSF and Linux Foundation Education Courses Get involved with the OpenSSF Subscribe to the OpenSSF newsletter Follow the OpenSSF on LinkedIn Chapters: 00:00 - Music, Promo clip, & Welcome 01:11 - Ejiro details her transition from UI/UX design to cybersecurity and connecting with OpenSSF. 03:39 - Ejiro explains her motivation for starting the 100-day challenge, including receiving advice to learn publicly and a previous rejection from an internship. 06:49 - Ejiro shares that she is currently on day 44 and expects to complete the challenge around April. 07:50 - Ejiro discusses her biggest personal lesson: understanding consistency and discipline, and learning from the community. 10:45 - Ejiro describes her authorship of the "Beginner to Builder" blog series, which shifted her from consuming content to shaping the open source conversation. 15:47 - Ejiro shares the impact of her work, noting that it has made cybersecurity feel less intimidating for beginners and helped her grow in confidence. 18:22 - Rapid Fire Questions: Ejiro shares her preferences on books, cooking, social media, and more. 21:13 - Ejiro offers advice to the next generation, emphasizing that open source is welcoming, not just about coding, and provides great opportunities for learning and growth. 24:46 - Yesenia concludes the interview, thanking Ejiro for her time and contributions

Is this your show?

Claim this listing to keep it up to date, reach guests who want to pitch you, and manage bookings with Guestify.

Claim this listing

More Technology podcasts