Episode 24: Securing the FOSS Ecosystem with Gareth Rushgrove episode artwork

EPISODE · Feb 14, 2020 · 43 MIN

Episode 24: Securing the FOSS Ecosystem with Gareth Rushgrove

from Sustain · host SustainOSS

Sponsored By: Panelists Eric Berry | Justin Dorfman | Richard Littauer | Allen “Gunner” Gunn Guest Gareth Rushgrove Snyk Show Notes In this episode, we talk with Gareth Rushgrove, from Cambridge, UK, Director of Project Management at a security software startup called Snyk. He has spoken at a number of international technology conferences over the past few years, including FOSDEM, RAMP, BACON, QCon, PuppetConf, Monitorama, GOTO and Velocity. Security and Open Source don’t often go together, in this episode we explore the topic and more. 01:20 Gareth explains that Snyk provides tools for developers who use Open Source Software and help them stay secure. He also expands on vulnerability landscapes. 02:10 Justin asks Gareth at what point does he think the collective community decided that we need to start digging into security holes within our software and he answers the question. 04:00 One of the guys asks Gareth if security is a passion of his and if he joined the company because that’s what he loves or was it more for Open Source. 05:30 The guys talk about Guy Podjarney (a.k.a Guypod) and Steve Souders and how they started the web performance movement. 07:30 Richard states Snyk has 400,000 users on the website and three times more vulnerability than a public database. Gareth goes further in-depth about this and what his company does using Java, Ruby, or Python and how he does a bunch of propriety research and helps projects do profit disclosure. 11:10 Gareth discusses the Heartbleed attack & the Equifax data breach and its effect on the industry’s view on Open Source. Companies want Open Source ecosystem to be more secure, 17:50 Gunner chimes in with a question about if there is a list of things Gareth wishes Open Source projects would do to be better members of ecosystems visa the security and if there are checklists or places to go for best practices. Gareth expands on this. 23:49 Gareth talks about DevSecCon which is a conference that brings developers and security together in one place. There are eight conferences around the world this year. 24:33 One of the guys is curious about the effect of security and how people out there have packages that are used by millions of other users and how often they don’t know how many users are using it. Gareth explains. 26:44 Gunner asks about the role of threat modeling in the work Gareth does and what he recommends. 28:25 Gareth goes in-depth about the Helm Project and CNCF sponsoring. 37:31 Gareth gives advice on where people can go to find more information about security besides talking to Snyk. Spotlight 38:40 Justin’s spotlight this week is a blog post by Andrew Mason about [Ruby on Rails Development with VS Code](ttps://andrewm.codes/posts/ruby-on-rails-development-with-vs-code-p1i/) 39:07 Eric suggests getting off Google Chrome and using Firefox (Developer Edition). 40:15 Gunner’s pick is guix.gnu.org 40:46 Richard’s pick is crubadan.org 41:34 Finally, Gareth’s pick is openpolicyagent.org Links Snyk Gareth Rushgrove Twitter Puppet Heartbleed CNCF DevSecCon Helm HeavyBit Open Policy Agent GitHub Guy Podjarny Twitter Steve Souders Twitter Andrew Mason - Ruby On Rails Firefox Guix An Crúbadán Open PolicySpecial Guest: Gareth Rushgrove.

NOW PLAYING

Episode 24: Securing the FOSS Ecosystem with Gareth Rushgrove

0:00 43:44

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

Chewing the Fat with WorkForge WorkForge Bite-Sized Conversations for Building a Stronger Workforce Welcome to Chewing the Fat, a podcast delving deep into the world of food manufacturing. Dive into real conversations around critical topics like staffing, retention, onboarding, and career development in this essential industry. Subscribe now to gain insights from your peers, subject matter experts and more on the biggest issues facing food manufacturers today: -Hiring and retaining employees -Addressing the challenges of the Silver Tsunami -Improving time to productivity of new employees -Engaging employees from hire to retire And more... Tune in to Chewing the Fat, a WorkForge podcast, and join the conversation on how to build and sustain a resilient, high-performing workforce in food manufacturing. Evolve: Reinventing Leadership - Building Freedom Cultures Yvette Bethel Yvette Bethel invites leaders to explore, create, and sustain a freedom culture in their organization. Think and Grow Well® Lori L. Barr, M. D. You are more than just a body. The Think and Grow Well® Show introduces you to steps you can take right now to strengthen the four aspects of your human being. As you listen you'll be surprised how quickly you amplify your awareness, sustain your spirit, master your mind and buff your body before you face a health challenge. Your host, Dr. Lori Barr is an advocate for vibrant living. She introduces you to guests who have overcome obstacles that usually lead to disease and experts that have uncommon solutions to problems. Together we'll break down the steps taken to overcome the challenge and vitalize your life. Doctors and patients can live full out when we each take responsibility for our own health and well-being. That's freedom! Podsafe music licensed by Music Radio Creative. Leap Like Me Lisa Hoashi Sometimes life asks us to make a bigger change than we expected. Welcome to Leap Like Me, where we offer real stories, inspiration and practical advice on how to make purposeful, brave leaps in life – and sustain them even through challenging times. Life Coach Lisa Hoashi explores the strategies and mindset you need to make brave changes in your life and work. Featuring guest appearances from people who have stretched their sense of what's possible in their own lives, the show will help you to reimagine what's possible for you too.

Frequently Asked Questions

How long is this episode of Sustain?

This episode is 43 minutes long.

When was this Sustain episode published?

This episode was published on February 14, 2020.

What is this episode about?

Sponsored By: Panelists Eric Berry | Justin Dorfman | Richard Littauer | Allen “Gunner” Gunn Guest Gareth Rushgrove Snyk Show Notes In this episode, we talk with Gareth Rushgrove, from Cambridge, UK, Director of Project Management at a...

Can I download this Sustain episode?

Yes, you can download this episode by clicking the download button on the episode player, or subscribe to the podcast in your preferred podcast app for automatic downloads.
URL copied to clipboard!