Sign in

Josh Bressers

@josh.bressers.name
421 followers 476 following 201 posts

Mostly on Mastodon - Open Source Security opensourcesecurity.io - Hacker History hackerhistory.com - He/Him

PostsRepliesMedia
Josh Bressers @josh.bressers.name · 28/09/2026
This week on #OpenSourceSecurity I chat with @amandabrock.bsky.social from @openuk.bsky.social The open source world used to ignore topics like policy and government, but that's not really practical anymore. The world of open source, sovereignty, and politics is colliding
opensourcesecurity.io
Sovereignty, policy, and OpenUK with Amanda Brock
Josh welcomes Amanda Brock from OpenUK to chat about sovereignty, policy, open source, and a whole host of other topics. Amanda has front row seat into how sovereignty decisions can affect a county an...
000
Josh Bressers @josh.bressers.name · 14/09/2026
The first #CRA requirements started a few days ago. I chatted with Danial Thompson about what that means and what comes next Daniel has a ton of CRA knowledge, this first step isn't going to change a ton, but what's coming next will opensourcesecurity.io/2026/2026-09...
opensourcesecurity.io
CRA vulnerability reporting with Daniel Thompson
Josh welcomes back Daniel Thompson to explain what just happened regarding vulnerability reporting and the CRA on September 11. The very first CRA requirements kicked in, but what does it really mean?...
020
Josh Bressers @josh.bressers.name · 07/09/2026
I had a chat with Jaya Baloo from AISLE about why they seem to be finding vulnerabilities even when the new fancy tools aren't finding anything The answer is unsurprisingly "engineering" Jaya has a ton of interesting insight, including how to work with open source projects and what's coming next
opensourcesecurity.io
Finding difficult vulnerabilities with Jaya Baloo from AISLE
Josh chats with Jaya Baloo from AISLE about their vulnerability scanner. If you follow open source vulnerabilities AISLE is a name you’ve seen popping up recently. They have a vulnerability scanner th...
001
Josh Bressers @josh.bressers.name · 31/08/2026
I had a chat with Erik Möller from @sovereign.tech about what they're doing in the universe of funding open source Eric breaks down what they're doing, how it works, and how you can apply for funding. We even learn about some similar projects happening in the EU
opensourcesecurity.io
Sovereign Tech Agency with Erik Möller
Episode Links Erik’s LinkedIn Sovereign Tech Agency Meet the First Sovereign Tech Standards Cohort Incident Report: unsanctioned agent behaviour during cyber testing STA on Mastodon This episode is al...
022
Josh Bressers @josh.bressers.name · 24/08/2026
This week on #OpenSourceSecurity I had a chat with @paulasadoorian.bsky.social about a tool he wrote called Fettle and a report on CVEs he wrote We love making a huge deal about individual CVEs, but most of us have to deal with advisories that clump them together
opensourcesecurity.io
CVEs vs Advisories with Paul Asadoorian
Josh chats with Paul Asadoorian about a tool he wrote called fettle and a recent report Paul published on CVEs. Fettle is a tool to help update and manage Linux systems. The big sell on this one is ch...
000
Josh Bressers @josh.bressers.name · 17/08/2026
I had a chat with Erin Schnabel and Rob Nalen about a sustainability project between @commonhaus.org and HeroDevs The idea is to bring together the EOL business model from HeroDevs and use that to help further some of the Commonhaus software catalog
opensourcesecurity.io
Maintaining EOL Open Source with Commonhaus and HeroDevs
Josh chats with Erin Schnabel and Rob Nalen about a new effort from Commonhaus and HeroDevs for maintaining end of life open source. This project, the Open Source Sustainability Initiative is a clever...
032
Reposted by Josh Bressers
Andrew Nesbitt @andrewnez.bsky.social · 11/08/2026
Shared Code Between Package Managers nesbitt.io/2026/08/11/p...
nesbitt.io
Shared Code Between Package Managers
Which package-management libraries twenty package managers reuse from each other.
141
Reposted by Josh Bressers
James @43081j.com · 10/08/2026
had another good chat about @e18e.dev and what the community has been up to. check it out! 🎉 big thanks to @josh.bressers.name for having me along and for the good conversation 🙏
opensourcesecurity.io
Cleanup, Speedup, Levelup open source at e18e
Josh chats with James from e18e. This is a project that is working on improving Javascript packages by cleaning up, speeding up, and leveling up the dependencies. The way the e18e project handles this...
02810
Reposted by Josh Bressers
Software Stewardship Lab @stewardshiplab.org · 07/08/2026
Today, we're launching a world-class research lab dedicated to Open Source sustainability with a team of some of the most experienced people in the world.
stewardshiplab.org
A Research Lab for Open Source ✸ Software Stewardship Lab
Today, we're launching a world-class research lab dedicated to Open Source sustainability with a team of some of the most experienced people in the world.
214043
Josh Bressers @josh.bressers.name · 03/08/2026
This week on #OpenSourceSecurity I chat with @patrickmgarrity.bsky.social from @vulncheck.bsky.social about a report they wrote that looked at the number of actually exploited vulnerabilities The increase of CVEs is out of control, but the number of things that get exploited is flat
opensourcesecurity.io
VulnCheck's State of Exploitation Report with Patrick Garrity
Josh chats with Patrick Garrity about the VulnCheck State of Exploitation 1H-2026 report. Patrick explains the current trends we are seeing around vulnerabilities right now. While the number of CVEs i...
001
Reposted by Josh Bressers
Damien Miller @damienmiller.bsky.social · 28/07/2026
I'm not an unbiased observer here, but the idea of paying a subscription for an SSH client seems uniquely absurd
3121
Josh Bressers @josh.bressers.name · 27/07/2026
I had a chat with @joshcorman.bsky.social about securing critical infrastructure on #OSSPodcast Josh is one of the best in the industry on this topic. He has a ton of interesting (and sometimes scary) things to say about this opensourcesecurity.io/2026/2026-07...
opensourcesecurity.io
Securing critical infrastructure with Josh Corman
Open Source Security welcomes Josh Corman to talk about the challenges around securing our critical infrastructure. Specifically the discussion centers around our water supplies. There are a lot of re...
131
Josh Bressers @josh.bressers.name · 20/07/2026
I chatted with Josh Marpet about a report his group, Value Chain Risk Institute, published showing the data behind open source dependencies It's not great, but having data that shows the problem is a big deal. There are a lot of opinions about open source and not a lot of data
opensourcesecurity.io
Abandoned open source with Josh Marpet
Josh welcomes Josh Marpet for a discussion about abandoned open source packages. Josh Marpet has a foundation called Value Chain Risk Institute that has a report discussion how to start measuring if a...
000
Josh Bressers @josh.bressers.name · 13/07/2026
I got to chat with @mairin.bsky.social about Red Hat's Project Lightwell on #OpenSourceSecurity It's going to be interesting to figure out how everyone will start interacting with open source projects. This is something Red Hat is pretty good at already opensourcesecurity.io/2026/2026-07...
opensourcesecurity.io
Red Hat's Project Lightwell with Mo Duffy
Josh welcomes Mo Duffy from Red Hat to chat about project Lightwell. The idea is to leverage the resources and understanding Red Hat has built up over the years to help deal with the deluge of vulnera...
010
Reposted by Josh Bressers
RustConf @rustconf.com · 08/07/2026
🎙️ Great convo on @josh.bressers.name's Open Source Security podcast with @lorilorusso.bsky.social & @nikomatsakis.com about the new Rust Foundation Maintainers Fund and funding the unglamorous, essential work of OSS maintenance. Check it out: youtube.com/watch?v=Z0s9... #rustlang #opensource
061
Josh Bressers @josh.bressers.name · 06/07/2026
I had a chat with Lori Lorusso and Niko Matsakis about the Rust Foundation Maintainers Fund Funding open source is a huge topic right now, the Rust Foundation has some great ideas. It will be exciting to watch this one grow and evolve #OpenSourceSecurity #rust #RustFoundation
opensourcesecurity.io
Rust Foundation Maintainers Fund with Lori and Niko
Josh chats with Lori Lorusso and Niko Matsakis about the Rust Foundation Maintainers Fund. This is a new project the Rust Foundation has create to help fund Rust maintainers. It’s a great discussion w...
173
Reposted by Josh Bressers
Allan @allanfriedman.bsky.social · 29/06/2026
This was a fun conversation! We unpacked the “omniBOM.”
011
Josh Bressers @josh.bressers.name · 29/06/2026
I had the pleasure to chat with @allanfriedman.bsky.social about Bill of Materials things on #OpenSourceSecurity We touched on SBOMs, HBOMs, AIBOMs, and even some other BOM types I can't remember now Allan is always fun to chat with, and he has encyclopedic knowledge about the BOM universe
opensourcesecurity.io
AIBOM, CBOM, and HBOM with Allan Friedman
Josh chats with Allan Friedman about all things Bill of Materials. Allan did a ton of work to help turn SBOM into what it is today. He has many thoughts and ideas around the new types of BOMs, a conce...
000
Josh Bressers @josh.bressers.name · 22/06/2026
I had a chat with Jordi Boggiano from Packagist about a heap of security features they recently added and adding in the future The security of the public package repositories is a hot topic right now, Packagist is doing some really interesting things to improve their security
opensourcesecurity.io
Packagist and Composer security with Jordi Boggiano
Josh welcomes Jordi Boggiano the lead maintainer of Composer and Packagist to explain the truckload of security features they’ve recently added. Packagist is the PHP package registry, Composer is the ...
046
Josh Bressers @josh.bressers.name · 15/06/2026
I had a chat on #OpenSourceSecurity with Mike Milinkovich and Thabang Mashologu from @eclipse.org about their new managed Open VSX registry The Eclipse Foundation has a plan that seems pretty sensible to keep the Open VSX registry around for a long time
opensourcesecurity.io
Sustaining Open VSX with Mike and Thabang
Josh welcomes Mike Milinkovich and Thabang Mashologu from the Eclipse Foundation to talk about their new managed Open VSX registry. This is the first open source package registry to create a commercia...
020
Reposted by Josh Bressers
Jason Scott @textfiles.com · 14/06/2026
Happy 40th, Maniacs
1607
Josh Bressers @josh.bressers.name · 08/06/2026
I had a chat with @francoisproulx.bsky.social about CI/CD security and a tool he built to red team your own pipelines. Holy cow this is a wild topic right now. I chatted with François a bit over a year ago before CI/CD lit on fire, his warnings were very apt opensourcesecurity.io/2026/2026-06...
opensourcesecurity.io
Hacking your CI/CD with François Proulx
Josh welcomes back François Proulx to talk about the absolute madness in the CI/CD universe right now. We also learn about François’ new project SmokedMeat which is a tool to help you hack your own CI...
010
Josh Bressers @josh.bressers.name · 11/05/2026
I had a chat on #OpenSourceSecurity with Kat Cosgrove about open source being critical infrastructure Kat has a ton of experience in the world of Kubernetes and had some really interesting things to tell us about both successful projects as well as having to shut down projects
opensourcesecurity.io
Open source is critical infrastructure with Kat Cosgrove
Josh talks to Kat Cosgrove about a how companies should be treating open source more like their critical infrastructure than free stuff. Kat has a ton of knowledge about how the interactions between c...
010
Reposted by Josh Bressers
Andrew Nesbitt @andrewnez.bsky.social · 08/05/2026
Weekend at Bernie's - Which of your dependencies are wearing sunglasses? nesbitt.io/2026/05/08/w...
nesbitt.io
Weekend at Bernie’s
Which of your dependencies are wearing sunglasses
093
Josh Bressers @josh.bressers.name · 04/05/2026
The the wrap up with David Bernstein around how to test a disaster recovery / emergency response plan I'm pretty excited to get these out, it feels like this topic is more relevant than it's ever been and David does a nice job explaining it all opensourcesecurity.io/2026/2026-05...
opensourcesecurity.io
How to actually test a disaster plan with David Bernstein
Josh and David finish up the disaster recovery and emergency planning trilogy. In this one David tells us how to test the plan he told us how to build in the last episode. There are some great ideas i...
000
Reposted by Josh Bressers
Miranda Heath @mirandaheath.website · 28/04/2026
Some incredible in-depth discussion between @vlad.website and @josh.bressers.name on the importance (and challenges) of paying OSS maintainers in this episode of Open Source Security! (PS thanks for the shout-out ☀️) opensourcesecurity.io/2026/2026-04...
opensourcesecurity.io
Open Source Pledge with Vlad-Stefan Harbuz
Josh has a discussion with Vlad-Stefan Harbuz about the Open Source Pledge as well as his recent FOSDEM talk. The Open Source Pledge is all about trying to build a sustainable universe for open source...
163
Reposted by Josh Bressers
Vlad-Stefan Harbuz 🌸 @vlad.website · 27/04/2026
I really enjoyed talking to @josh.bressers.name about the @opensourcepledge.com, and about why and how we should support Open Source maintainers 😊
193
Josh Bressers @josh.bressers.name · 27/04/2026
I had a chat with @vlad.website about the @opensourcepledge.com Vlad has a ton of insight into how hard it is to just figure out what you're running plus the challenges maintainers have Vlad has a ton of great ideas how to start tackling some of these incredibly difficult problems
opensourcesecurity.io
Open Source Pledge with Vlad-Stefan Harbuz
Josh has a discussion with Vlad-Stefan Harbuz about the Open Source Pledge as well as his recent FOSDEM talk. The Open Source Pledge is all about trying to build a sustainable universe for open source...
041
Josh Bressers @josh.bressers.name · 20/04/2026
I had chat with David Bernstein about creating a disaster recovery plan on #OpenSourceSecurity With all the events unfolding almost every day lately, there's never been a better time to put a plan like this together. In a few weeks David will tell us how to test such a plan once we create it
opensourcesecurity.io
Building a plan for disaster with David Bernstein
Josh welcomes back David Bernstein to talk about creating a disaster recover plan. It’s a very timely topic given all the current events. There are more supply chain attacks and compromises than ever ...
000
Josh Bressers @josh.bressers.name · 16/04/2026
A new #HackerHistory is out! This time we hear the story of Pyr0 Pyr0 tells us about a new upcoming conference all about hacker history, NaClCON Then we hear about a lot of awesome hacker history It's a great story! hackerhistory.com/podcast/the-...
hackerhistory.com
The history of Pyr0 - Hacker History Podcast
Hacker History sits down with Luke McOmie, AKA Pyr0, to talk about a new conference about hacker history, as well as his history. Pyr0 tells us all about NaClCON. It's a conference dedicated to the st...
000
Josh Bressers @josh.bressers.name · 13/04/2026
I had a chat with Paul McCarty about his project @opensourcemalware.bsky.social Paul has a ton of great insight into what's happening with the massive influx of malware into our open source ecosystems opensourcesecurity.io/2026/2026-04...
opensourcesecurity.io
Open Source Malware with Paul McCarty
Josh talks to Paul McCarty of Open Source Malware about … open source malware. Paul explains why there aren’t many good open source malware datasets. We discuss why the existing data is lacking for ma...
000
Josh Bressers @josh.bressers.name · 06/04/2026
I had a chat with @andrewnez.bsky.social about why creating a new package repository is so hard. There are a ton of little details like support from SBOM and vulnerability scanners nobody even thinks about. There are so many little details Andrew does a great job explaining all this and more
opensourcesecurity.io
Package management challenges with Andrew Nesbitt
Josh welcomes back Andrew Nesbitt to discuss some recent blog posts he wrote about the challenges of new ecosystems as well as challenges of no ecosystems like C. There aren’t very many people who loo...
051
Josh Bressers @josh.bressers.name · 30/03/2026
This week I had a chat with Michael Winser about securing open source at scale We recorded prior to the events of the last few weeks, everything Michael talks about with securing our infrastructure is spot on
opensourcesecurity.io
Open Source Security at scale with Michael Winser
Josh talks to Michael Winser about a talk he gave at FOSDEM as well as his work on Alpha Omega at the Linux Foudnation. Michael is approaching open source security in a way that nobody has ever tried ...
000
Reposted by Josh Bressers
nolabs, Inc @nolabs.ai · 24/03/2026
@josh.bressers.name put it well: MCP is moving faster than anyone can keep up with. @lukehinds.bsky.social joined #OpenSourceSecurity to dig into why agent security is structurally hard and what kernel-level sandboxing nono.sh actually solves. Episode: opensourcesecurity.io/2026/2026-03...
opensourcesecurity.io
MCP and Agent security with Luke Hinds
Josh talks to Luke Hinds, CEO of Always Further, about MCP and agent security. We start out talking about Luke’s new tool, nono which is a sandboxing tool that has AI agents in mind as a use case. We ...
022
Reposted by Josh Bressers
Luke Hinds @lukehinds.bsky.social · 16/03/2026
great chat, with a great chap (Josh, not me).
022
Josh Bressers @josh.bressers.name · 16/03/2026
I had a chat on #OpenSourceSecurity with @lukehinds.bsky.social about his project nono as well as MCP security nono is a sandbox for containing all these tools which is an incredibly difficult problem to solve. The things we see skills and MCP doing are moving forward faster than anyone can keep up
opensourcesecurity.io
MCP and Agent security with Luke Hinds
Josh talks to Luke Hinds, CEO of Always Further, about MCP and agent security. We start out talking about Luke’s new tool, nono which is a sandboxing tool that has AI agents in mind as a use case. We ...
051
Josh Bressers @josh.bressers.name · 09/03/2026
This week on #OpenSourceSecurity I had a chat with Paul Kehrer and Alex Gaynor about the statement they published discussing the challenges posed by modern OpenSSL for the python cryptography module
opensourcesecurity.io
The State of OpenSSL for pyca/cryptography with Alex Gaynor and Paul Kehrer
Josh talks to Paul Kehrer and Alex Gaynor, from the Python Cryptographic Authority. Alex and Paul recently published a statement discuss the challenges posed by modern OpenSSL. We discuss the statemen...
012
Josh Bressers @josh.bressers.name · 02/03/2026
I had a chat on #OpenSourceSecurity with @sylvestreledru.bsky.social about his Rust coreutils work Replacing coreutils with Rust is one of those things that I love as a way to improve security but also keep a project fresh in the modern age I learned a ton from this disucssion
opensourcesecurity.io
Rust coreutils with Sylvestre Ledru
Josh talks to Sylvestre Ledru about the Rust coreutils project. We’ve been using GNU coreutils for decades now, and the goal of Rust coreutils is to rewrite these utilities in Rust. The primary reason...
021
Josh Bressers @josh.bressers.name · 23/02/2026
This week on #OpenSourceSecurity I chat with Brad Axen about Goose and the Agentic AI Foundation I'm often skeptical about AI claims, but I do approve the foundation model and seeing Goose donated to it
opensourcesecurity.io
Goose and the Agentic AI Foundation with Brad Axen
Josh chats with Brad Axen from Block about his creation Goose as well as the Agentic AI Foundation (AAIF). I am quite skeptical of many AI claims, but Brad has a very pragmatic view about where things...
000
Reposted by Josh Bressers
Nextcloud @nextcloud.bsky.social · 17/02/2026
How does open source business model work, why is user empowerment so important, and when is the right time for digital sovereignty? Find out in the new episode of the @josh.bressers.name podcast as he is joined by our founder @karlitschek.bsky.social
opensourcesecurity.io
Digital Sovereignty and Nextcloud with Frank Karlitschek
Episode Links Frank Nextcloud Nextcloud getting started Digital Sovereignty Index This episode is also available as a podcast, search for “Open Source Security” on your favorite podcast player.…
052
Josh Bressers @josh.bressers.name · 16/02/2026
I had a chat with @oej.edvina.net about The Global Vulnerability Intelligence Platform Olle is working to build a community around the future of vulnerability identifiers Don't just give it a listen, but also come help Olle. It's a pretty important problem that nobody can solve alone
opensourcesecurity.io
The Global Vulnerability Intelligence Platform with Olle E. Johansson
Josh chats with Olle E. Johansson about the Global Vulnerability Intelligence Platform (GVIP). It’s no secret the current vulnerability systems are reaching a breaking point. Olle is one of the few pe...
011
Josh Bressers @josh.bressers.name · 09/02/2026
I had a chat with Frank Karlitschek from @nextcloud.bsky.social about digital sovereignty There's a lot of attention lately around digital sovereignty and often that conversation also includes Nextcloud
opensourcesecurity.io
Digital Sovereignty and Nextcloud with Frank Karlitschek
Episode Links Frank Nextcloud Nextcloud getting started Digital Sovereignty Index This episode is also available as a podcast, search for “Open Source Security” on your favorite podcast player. Episod...
011
Josh Bressers @josh.bressers.name · 02/02/2026
This episode of #OpenSourceSecurity I have a chat with David Bernstein about crisis response I love this topic because responding to a crisis is pretty common in security work, but doesn't have to be a gong show This is one of those topics that can go deep. David did a nice job covering basics
opensourcesecurity.io
The Art of Crisis Management with David Bernstein
Josh talks to David Bernstein about the world of crisis management and business continuity. David is a certified emergency manager and tell us about preparing for both digital and physical disruptions...
010
Reposted by Josh Bressers
Suricata IDS @suricata.io · 29/01/2026
In a recent episode of Open Source Security, @josh.bressers.name sits down with Victor Julien, founder and lead developer of the #Suricata project. Tune in now! opensourcesecurity.io/2026/2026-01...
021
Josh Bressers @josh.bressers.name · 19/01/2026
This episode of #OpenSourceSecurity I discuss @suricata.io with Victor Julian Victor tells us all about the past, present, and future of #Suricata I learned a ton opensourcesecurity.io/2026/2026-01...
opensourcesecurity.io
All about Suricata with Victor Julien
Josh discusses Suricata with Victor Julien, the founder and lead developer of the Suricata project. Victor explains the history of Suricata, its impact on cybersecurity, and the community that keeps i...
011
Josh Bressers @josh.bressers.name · 12/01/2026
This week on #OpenSourceSecurity I have a chat with Gergely Nagy about Iocaine Iocaine creates a maze of garbage to trap scraping bots. I love this idea, it has amazing chaotic good energy! I learn all about how Iocaine works, and even got to see some dashboards showing off the size of the problem
opensourcesecurity.io
Iocaine poisons bots with Gergely Nagy
Josh talks to Gergely Nagy (algernon) about his tool Iocaine. Iocaine creates a maze to trap scraping bots in a world a fake pages they cannot escape. algernon tells us how Iocaine effectively traps b...
021
Josh Bressers @josh.bressers.name · 05/01/2026
This week on #OpenSourceSecurity I have a chat with Xe Iaso about #Anubis, the tool that stops web AI scrapers The scale of web scraping is way worse than I expected, and blocking things is also a lot harder than I expected This is one of those conversations where I learned how little I know
opensourcesecurity.io
Anubis with Xe Iaso
Josh chats with Xe Iaso, the creator of Anubis the web AI firewall. We discuss how Anubis is tackling bots and scrapers. The discussion around the scrapers is fascinating and challenging, these things...
020
Josh Bressers @josh.bressers.name · 29/12/2025
This week on #OpenSourceSecurity I chat with Dirkjan Ochtman and Joe Birr-Pixton about #Rustls. A lot has happened with Rustls in the last few years (and there's a lot more to come). Writing a TLS implementation is incredibly complicated, even when you don't have to worry about memory safety
opensourcesecurity.io
Rustls with Dirkjan and Joe
Josh talk to Dirkjan and Joe about Rustls (pronounced rustles), a Rust-based TLS library. Dirkjan and Joe are developers on Rustls. We talk about the history that got us to this point. The many many c...
053
Josh Bressers @josh.bressers.name · 22/12/2025
On a very special Christmas episode of #OpenSourceSecurity I asked Daniel Thompson-Yvetot how the #CRA will impact Santa Claus I meant the episode to be silly, just in time for Christmas, but I think I learned more from Daniel in those 50 minutes than I have in the last 3 years reading about CRA
opensourcesecurity.io
Daniel Thompson answers: Does the CRA apply to Santa?
Josh welcomes back Daniel Thompson explore the rather silly question of whether Santa Claus needs to be compliant with the Cyber Resilience Act (CRA). This episode was intended to be silly, but it end...
100
Josh Bressers @josh.bressers.name · 15/12/2025
This #OpenSourceSecurity episode I chat with Gabriele Columbro from @linuxfoundationeu.bsky.social We of course chat about the #CRA and how he helped with shaping what we see today We also cover open source sustainability, vertical foundations, and all the attention open source is receiving
opensourcesecurity.io
Linux Foundation Europe with Gabriele Columbro
Josh has a chat with Gabriele Columbro, Executive Director of the Fintech Open Source Foundation and General Manager of Linux Foundation Europe. We of course discuss the Cyber Resilience Act (CRA), th...
011