Open Source Security

By Josh Bressers

Stop trying to fix the open source software supply chain

🔊 Play episode (32 min)

Direct episode link

đź’¬ Share episode

Published October 02, 2022 7:00pm

Josh and Kurt talk about a blog post that explains there isn't really an open source software supply chain. The whole idea of open source being one thing is incorrect, open source is really a lot of little things put together. A lot of companies and organizations get this wrong. Show Notes Iliana's Twitter There is no “software supply chain” Google supply chain blog GitHub ansi_term advisory PyPI 2FA Dashboard tarfile issue rediscovered in 2022

Return to podcast