Below the Surface (Audio) - The Supply Chain Security Podcast

The Hidden Risks of Open Source Components - BTS #49

May 6, 2025
Josh Bressers, a supply chain and open source security expert at Anchore, dives into the intricate world of open source components. He discusses the pervasive challenges of managing vulnerabilities in legacy systems and the critical role of Software Bill of Materials (SBOMs). They tackle regulatory pressures around software liability and the automation needed to tackle the increasing volume of CVEs. Josh also highlights innovative tools like SIFT and Gripe, emphasizing their importance in enhancing transparency and security in software development.
Ask episode
AI Snips
Chapters
Transcript
Episode notes
INSIGHT

Open Source Is Everywhere

  • Open source is now in virtually every product because it is easy, free, and fast to adopt.
  • That ubiquity creates systemic supply-chain exposure across all industries and device types.
ANECDOTE

Early Skepticism Turned Wrong

  • Josh remembered being dismissed for advocating open source early in his career but predicting its success.
  • He contrasted that skepticism with today's reality of open source everywhere.
INSIGHT

Embedded Devices Keep Aging Stacks

  • Embedded and BMC devices often run older Linux builds because vendors favor reuse and low margins.
  • Those aging stacks create long-lived attack surfaces that rarely get regular updates.
Get the Snipd Podcast app to discover more snips from this episode
Get the app