Securing the open source supply chain (Changelog Interviews #482) episode artwork

EPISODE · Mar 1, 2022 · 1H 28M

Securing the open source supply chain (Changelog Interviews #482)

from Changelog Master Feed

This week we're joined by the "mad scientist" himself, Feross Aboukhadijeh...and we're talking about the launch of Socket — the next big thing in the fight to secure and protect the open source supply chain. While working on the frontlines of open source, Feross and team have witnessed firsthand how supply chain attacks have swept across the software community and have damaged the trust in open source. Socket turns the problem of securing open source software on its head, and asks..."What if we assume all open source may be malicious?" So, they built a system that proactively detects indicators of compromised open source packages and brings awareness to teams in real-time. We cover the whys, the hows, and what's next for this ambitious and very much needed project.

Episode metadata supplied by the publisher feed · Published Mar 1, 2022

Embed this episode

NOW PLAYING

Securing the open source supply chain (Changelog Interviews #482)

0:00 1:28:21

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of Changelog Master Feed?

This episode is 1 hour and 28 minutes long.

When was this Changelog Master Feed episode published?

This episode was published on March 1, 2022.

Is there a transcript available for this episode?

Yes, a full transcript is available for this episode. You can read the complete transcript on the episode page.

Can I download this Changelog Master Feed episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!