Get the app
Ben Cotton
Open source community lead at Kusari and lead of the Open Source Project Security (OSPS) Baseline SIG, focused on creating practical security control catalogs for projects.
Best podcasts with Ben Cotton
Ranked by the Snipd community
9 snips
Nov 4, 2025
• 33min
A Deep Dive into the Open Source Project Security (OSPS) Baseline
chevron_right
Ben Cotton, Open Source Community Lead at Kusari, and Eddie Knight, Security Compliance Specialist at Sonatype, dive into the Open Source Project Security Baseline. They discuss how this baseline provides a framework for enhancing software security and simplifying requirements for maintainers. The GUAC case study showcases its real-world application, while the importance of documentation in securing software deployment is emphasized. Future directions focus on improving tooling and community engagement, allowing for continued refinement and increased confidence in open source projects.
The AI-powered Podcast Player
Save insights by tapping your headphones, chat with episodes, discover the best highlights - and more!
Get the app