#4 AIが攻撃してくる時代、OSSの信頼はどう守る? episode artwork

EPISODE · May 26, 2026 · 42 MIN

#4 AIが攻撃してくる時代、OSSの信頼はどう守る?

from 八百万のOSS · host ミソラボ

「ソースを公開する方がリスクが高い」——そんな時代が本当に来てしまったのかもしれません。攻撃者がAIでOSSをスキャンして自動で弱点を突いてくる今、守る我々もAIで立ち向かうしかない。xz事件からHonoのAI Slop問題、TanStackのサプライチェーン攻撃、Takumi Guardのような新しい防御サービスまで、catatsuy が実体験を交えて語ります。なぜ今、狙われているのが「開発者本人」なのか。OSSに関わるすべてのエンジニアに聞いてほしい一本です。## xz* Everything I Know About the XZ Backdoor - https://boehs.org/node/everything-i-know-about-the-xz-backdoor* CVE-2024-3094 / Ubuntu security page - https://ubuntu.com/security/CVE-2024-3094## Hono - OSSにおけるAI Slop問題の何が問題なのか?* https://zenn.dev/yusukebe/articles/3fd5bc6ea341c9## TanStackのnpmサプライチェーン攻撃とGitHub Actionsの危険な権限設計* TanStack npm supply-chain compromise - https://tanstack.com/blog/npm-supply-chain-compromise-postmortem* npm staged publishing - https://docs.npmjs.com/staged-publishing/* pull_request_target の背景・リスクに関するGitHub Community discussion - https://github.com/orgs/community/discussions/179107## axios ソフトウェアサプライチェーン攻撃の概要と対応指針* https://blog.flatt.tech/entry/axios_compromise## tj-actions/changed-files CVE-2025-30066* https://www.cisa.gov/news-events/alerts/2025/03/18/supply-chain-compromise-third-party-tj-actionschanged-files-cve-2025-30066-and-reviewdogaction## Takumi Guard* https://flatt.tech/takumi/features/guard

Episode metadata supplied by the publisher feed · Published May 26, 2026

Embed this episode

NOW PLAYING

#4 AIが攻撃してくる時代、OSSの信頼はどう守る?

0:00 42:36

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of 八百万のOSS?

This episode is 42 minutes long.

When was this 八百万のOSS episode published?

This episode was published on May 26, 2026.

Can I download this 八百万のOSS episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!