Josh Bressers

@josh.bressers.name

Mostly on Mastodon - VP of Security at Anchore - Open Source Security https://opensourcesecurity.io - Hacker History http://hackerhistory.com - He/Him

I chatted with Josh Marpet about a report his group, Value Chain Risk Institute, published showing the data behind open source dependencies It's not great, but having data that shows the problem is a big deal. There are a lot of opinions about open source and not a lot of data

Abandoned open source with Josh Marpet

Josh welcomes Josh Marpet for a discussion about abandoned open source packages. Josh Marpet has a foundation called Value Chain Risk Institute that has a report discussion how to start measuring if a...

opensourcesecurity.io

I had a chat with Lori Lorusso and Niko Matsakis about the Rust Foundation Maintainers Fund Funding open source is a huge topic right now, the Rust Foundation has some great ideas. It will be exciting to watch this one grow and evolve #OpenSourceSecurity #rust #RustFoundation

Rust Foundation Maintainers Fund with Lori and Niko

Josh chats with Lori Lorusso and Niko Matsakis about the Rust Foundation Maintainers Fund. This is a new project the Rust Foundation has create to help fund Rust maintainers. It’s a great discussion w...

opensourcesecurity.io

I had the pleasure to chat with @allanfriedman.bsky.social about Bill of Materials things on #OpenSourceSecurity We touched on SBOMs, HBOMs, AIBOMs, and even some other BOM types I can't remember now Allan is always fun to chat with, and he has encyclopedic knowledge about the BOM universe

AIBOM, CBOM, and HBOM with Allan Friedman

Josh chats with Allan Friedman about all things Bill of Materials. Allan did a ton of work to help turn SBOM into what it is today. He has many thoughts and ideas around the new types of BOMs, a conce...

opensourcesecurity.io

I had a chat with Jordi Boggiano from Packagist about a heap of security features they recently added and adding in the future The security of the public package repositories is a hot topic right now, Packagist is doing some really interesting things to improve their security

Packagist and Composer security with Jordi Boggiano

Josh welcomes Jordi Boggiano the lead maintainer of Composer and Packagist to explain the truckload of security features they’ve recently added. Packagist is the PHP package registry, Composer is the ...

opensourcesecurity.io

I had a chat on #OpenSourceSecurity with Mike Milinkovich and Thabang Mashologu from @eclipse.org about their new managed Open VSX registry The Eclipse Foundation has a plan that seems pretty sensible to keep the Open VSX registry around for a long time

Sustaining Open VSX with Mike and Thabang

Josh welcomes Mike Milinkovich and Thabang Mashologu from the Eclipse Foundation to talk about their new managed Open VSX registry. This is the first open source package registry to create a commercia...

opensourcesecurity.io

I had a chat on #OpenSourceSecurity with Kat Cosgrove about open source being critical infrastructure Kat has a ton of experience in the world of Kubernetes and had some really interesting things to tell us about both successful projects as well as having to shut down projects

Open source is critical infrastructure with Kat Cosgrove

Josh talks to Kat Cosgrove about a how companies should be treating open source more like their critical infrastructure than free stuff. Kat has a ton of knowledge about how the interactions between c...

opensourcesecurity.io

The the wrap up with David Bernstein around how to test a disaster recovery / emergency response plan I'm pretty excited to get these out, it feels like this topic is more relevant than it's ever been and David does a nice job explaining it all opensourcesecurity.io/2026/2026-05...

How to actually test a disaster plan with David Bernstein

Josh and David finish up the disaster recovery and emergency planning trilogy. In this one David tells us how to test the plan he told us how to build in the last episode. There are some great ideas i...

opensourcesecurity.io

I really enjoyed talking to @josh.bressers.name about the @opensourcepledge.com, and about why and how we should support Open Source maintainers 😊

Josh Bressers@josh.bressers.name · 3mo ago

I had a chat with @vlad.website about the @opensourcepledge.com Vlad has a ton of insight into how hard it is to just figure out what you're running plus the challenges maintainers have Vlad has a ton of great ideas how to start tackling some of these incredibly difficult problems

I had a chat with @vlad.website about the @opensourcepledge.com Vlad has a ton of insight into how hard it is to just figure out what you're running plus the challenges maintainers have Vlad has a ton of great ideas how to start tackling some of these incredibly difficult problems

Open Source Pledge with Vlad-Stefan Harbuz

Josh has a discussion with Vlad-Stefan Harbuz about the Open Source Pledge as well as his recent FOSDEM talk. The Open Source Pledge is all about trying to build a sustainable universe for open source...

opensourcesecurity.io

I had chat with David Bernstein about creating a disaster recovery plan on #OpenSourceSecurity With all the events unfolding almost every day lately, there's never been a better time to put a plan like this together. In a few weeks David will tell us how to test such a plan once we create it

Building a plan for disaster with David Bernstein

Josh welcomes back David Bernstein to talk about creating a disaster recover plan. It’s a very timely topic given all the current events. There are more supply chain attacks and compromises than ever ...

opensourcesecurity.io

I had a chat with @andrewnez.bsky.social about why creating a new package repository is so hard. There are a ton of little details like support from SBOM and vulnerability scanners nobody even thinks about. There are so many little details Andrew does a great job explaining all this and more

Package management challenges with Andrew Nesbitt

Josh welcomes back Andrew Nesbitt to discuss some recent blog posts he wrote about the challenges of new ecosystems as well as challenges of no ecosystems like C. There aren’t very many people who loo...

opensourcesecurity.io

This week I had a chat with Michael Winser about securing open source at scale We recorded prior to the events of the last few weeks, everything Michael talks about with securing our infrastructure is spot on

Open Source Security at scale with Michael Winser

Josh talks to Michael Winser about a talk he gave at FOSDEM as well as his work on Alpha Omega at the Linux Foudnation. Michael is approaching open source security in a way that nobody has ever tried ...

opensourcesecurity.io

I had a chat on #OpenSourceSecurity with @lukehinds.bsky.social about his project nono as well as MCP security nono is a sandbox for containing all these tools which is an incredibly difficult problem to solve. The things we see skills and MCP doing are moving forward faster than anyone can keep up

MCP and Agent security with Luke Hinds

Josh talks to Luke Hinds, CEO of Always Further, about MCP and agent security. We start out talking about Luke’s new tool, nono which is a sandboxing tool that has AI agents in mind as a use case. We ...

opensourcesecurity.io

I had a chat on #OpenSourceSecurity with @sylvestreledru.bsky.social about his Rust coreutils work Replacing coreutils with Rust is one of those things that I love as a way to improve security but also keep a project fresh in the modern age I learned a ton from this disucssion

Rust coreutils with Sylvestre Ledru

Josh talks to Sylvestre Ledru about the Rust coreutils project. We’ve been using GNU coreutils for decades now, and the goal of Rust coreutils is to rewrite these utilities in Rust. The primary reason...

opensourcesecurity.io