Podcast Episodes
Back to Search
Securing GitHub Actions with William Woodruff
William Woodruff discussed his project, Zizmor, a security linter designed to help developers identify and fix vulnerabilities within their GitHub Ac…
10 months ago
Embedded Security with Paul Asadoorian
Recently, I had the pleasure of chatting with Paul Asadoorian, Principal Security Researcher at Eclypsium and the host of the legendary Paul's Securi…
10 months, 1 week ago
tj-actions with Endor Lab's Dimitri Stiliadis
Dimitri Stiliadis, CTO from Endor Labs, discusses the recent tj-actions/changed-files supply chain attack, where a compromised GitHub Action exposed …
10 months, 2 weeks ago
Syft, Grype, and Grant with Alan Pope
I chat with Alan Pope about the open source security tools Syft, Grype, and Grant. These tools help create Software Bills of Materials (SBOMs) and sc…
10 months, 3 weeks ago
CVE for EOL with Aaron Frost
Aaron Frost explores the overly complex world of vulnerability identifiers for end of life software. We discuss how incomplete CVE reporting creates …
11 months ago
cargo-semver-checks with Predrag Gruevski
Cargo Semver Checks is a Rust tool by Predrag Gruevski that is tackling the problem of broken dependencies that cost developers time when trying to u…
11 months, 1 week ago
Distributed CI and Git with Lars Wirzenius
Lars Wirzenius discusses his innovative CI/CD system Ambient, which uses isolated virtual machines without network access to enhance security, and hi…
11 months, 2 weeks ago
FIDO authentication with William Brown
William Brown tells us all about how confusing and complicated the FIDO authentication universe is. He talks about WebAuthn implementation challenges…
11 months, 2 weeks ago
CRA with Luis Villa
In this episode, open source legal expert Luis Villa breaks down what the EU's Cyber Resilience Act means for developers and businesses, exploring ca…
11 months, 3 weeks ago
Open Source Malware with Brian Fox
Brian Fox discusses findings from a recent Sonatype report about the growing challenge of malicious packages in open source repositories. At the time…
1 year ago