

What's in the SOSS? An OpenSSF Podcast
OpenSSF
What's in the SOSS? features the sharpest minds in security as they dig into the challenges and opportunities that create a recipe for success in making software more secure. Get a taste of all the ingredients that make up secure open source software (SOSS) and explore the latest trends at the intersection of AI and security, vulnerability management, and threat assessments. Each episode of What's in the SOSS? is packed with valuable insight designed to foster collaboration and promote stronger security practices for the open source software community.About Christopher Robinson (aka CRob), hostCRob is a 43rd level Dungeon Master and a 26th level Securityologist. He is a leader within several Open Source Security Foundation (OpenSSF) efforts and is a frequent speaker on cyber, application, and open source security. He enjoys hats, herding cats, and moonlit walks on the beach.
Episodes
Mentioned books

Oct 16, 2025 • 39min
New Education Course: Secure AI/ML-Driven Software Development (LFEL1012) with David A. Wheeler
In this episode of “What’s In The SOSS,” Yesenia interviews David A. Wheeler, the Director of Open Source Supply Chain Security at the Linux Foundation. They discuss the importance of secure software development, particularly in the context of AI and machine learning. David shares insights from his extensive experience in the field, emphasizing the need for both education and tools to ensure security. The conversation also touches on common misconceptions about AI, the relevance of digital badges for developers, and the structure of a new course aimed at teaching secure AI practices. David highlights the evolving nature of software development and the necessity for continuous learning in this rapidly changing landscape.Chapters: 00:00 Introduction to Open Source and Security02:31 The Journey to Secure AI and ML Development08:28 Understanding AI's Impact on Software Development12:14 Myths and Misconceptions about AI in Security18:24 Connecting AI Security to Open Source and Closed Source20:29 The Importance of Digital Badges for Developers24:31 Course Structure and Learning Outcomes28:18 Final Thoughts on AI and Software SecurityEpisode links:David A. Wheeler’s LinkedIn pageSecure AI/ML-Driven Software Development (LFEL1012)OpenSSF EducationGet involved with the OpenSSFSubscribe to the OpenSSF newsletterFollow the OpenSSF on LinkedIn

Oct 7, 2025 • 23min
The Remediation Revolution: How AI Agents Are Transforming Open Source Security with John Amaral of Root.io
John Amaral, the founder of Root.io and an expert in open source container security, discusses the revolution in vulnerability management driven by AI technologies. He explains the shift from traditional scanning to a 'fix first' approach, enhancing developer efficiency and security. Amaral highlights how AI tools democratize coding, making it accessible while managing evolving threats in containerized environments. He advocates for 'shift out' practices, where agents take on maintenance burdens, allowing developers to focus on innovation.

10 snips
Sep 23, 2025 • 35min
From Manager to Open Source Security Pioneer: Kate Stewart's Journey Through SBOM, Safety, and the Zephyr Project
In this engaging discussion, Kate Stewart, a prominent figure at the Linux Foundation and expert in safety-critical open source, shares her unique journey from Motorola manager to open source advocate. She explains the evolution of Software Bill of Materials (SBOMs) and how they enhance security in software development. Kate also highlights the Zephyr project's dedication to security, detailing its achievement as a gold-level OpenSSF exemplar. Listeners will gain insights into regulatory challenges, contributing to open source, and navigating the complexities of licensing.

11 snips
Sep 9, 2025 • 30min
Racing Against Quantum: The Urgent Migration to Post-Quantum Cryptography with KeyFactor's Crypto Experts
Join David Hook, VP of Software Engineering at KeyFactor, and Tomas Gustavsson, Chief PKI Officer with 30 years of cryptography experience, as they tackle the urgent migration to post-quantum cryptography. They explain the quantum threat and why the financial sector is spearheading this transition. Practical tips for assessing current systems, enhancing crypto agility, and the vital need for high entropy in secure key generation are discussed. Plus, enjoy a fun rapid-fire Q&A showcasing their chemistry and insights!

Aug 26, 2025 • 15min
Securing AI: A Conversation with Sarah Evans on OpenSSF's AI/ML Initiatives
In this episode of "What's in the SOSS," we welcome back Sarah Evans, Distinguished Engineer at Dell Technologies and a key figure in the OpenSSF's AI/ML working group. Sarah discusses the critical work being done to extend secure software development practices to the rapidly evolving field of AI. She dives into the AI Model Signing project, the groundbreaking MLOps white paper developed in partnership with Ericsson, and the crucial work of identifying and addressing new personas in AI/ML operations. Tune in to learn how OpenSSF is shaping the future of AI security and what challenges and opportunities lie ahead.Episode Chapters:0:00 Welcome and Introduction to Sarah Evans0:48 Sarah Evans: Role at Dell Technologies and Involvement in OpenSSF1:38 The OpenSSF AI/ML Working Group: Genesis and Goals3:37 Deep Dive: The AI Model Signing Project with Sigstore4:28 AI Model Signing: Benefits for Developers5:20 Transition to the MLSeCOps White Paper5:49 The Mission of the MLSecOps White Paper: Addressing Industry Gaps7:00 Collaboration with Ericsson on the MLEC Ops White Paper8:15 Identifying and Addressing New Personas in AI/ML Ops10:04 The Power of Open Source in Extending Previous Work10:15 Future Directions for OpenSSF's AI/ML Strategy11:21 OpenSSF's Broader AI Security Focus12:08 Sneak Peek: New Companion Video Podcast on AI Security12:31 Sarah's Personal Focus: The Year of the Agents (2025)13:00 Security Concerns: Bringing Together Data Models and Code in AI Applications14:00 Conclusion and ThanksEpisode links:Sarah Evans LinkedIn pageOpenSSF AI/ML Security Working GroupOpenSSF Blog: Visualizing Secure MLOps (MLSecOps): A Practical Guide for Building Robust AI/ML Pipeline SecurityOpenSSF Whitepaper: Visualizing Secure MLOps (MLSecOps): A Practical Guide for Building Robust AI/ML Pipeline SecurityGet involved with the OpenSSFSubscribe to the OpenSSF newsletterFollow the OpenSSF on LinkedIn

Aug 12, 2025 • 26min
Open Source Security: OSTIF's 10-Year Journey of Collaborative Audits
In this episode of "What's in the SOSS," Derek Zimmer and Amir Montezari from the Open Source Technology Improvement Fund (OSTIF) discuss their decade-long mission of providing security resources to open source projects. They focus on collaborative, maintainer-centric security audits that help projects improve their security posture through expert third-party reviews, without creating fear or overwhelming developers.Episode Chapters:00:00 Introduction00:22 Podcast Welcome01:04 OSTIF Founders Introduction02:31 OSTIF's Mission and Approach05:28 Relationship Management and Expertise08:01 Evolution of Security Engagement Methods12:15 Making Security Audits Less Intimidating18:00 Rapid Fire Questions20:45 Closing, Call to ActionEpisode links:Derek Zimmer LinkedIn pageAmir Montezary LinkedIn pageOSTIF (Open Source Technology Improvement Fund)Get involved with the OpenSSFSubscribe to the OpenSSF newsletterFollow the OpenSSF on LinkedInJoin us at OpenSSF Community Day Europe Aug 28, 2025

7 snips
Jul 29, 2025 • 32min
From Compliance to Community: Meeting CRA Requirements Together
Michael Winser from Alpha Omega highlights the importance of community connections in open-source security. Ulf Riehm, Product Owner at Herrmann Ultraschall, discusses the integration of security into automation using a specialized tech stack. Jonatan Männchen, CISO at the Erlang Ecosystem Foundation, emphasizes compliance with the CRA and fostering a collaborative security culture. Together, they explore how proactive community engagement and transparency can enhance security practices across ecosystems.

5 snips
Jul 15, 2025 • 19min
Building India's Open Source Security Community: From Developer Nation to Security Champions
Ram Iyengar, OpenSSF's India community representative and former computer science professor, shares his transformative journey into the world of open source security. He discusses the challenges of engaging developers in security practices and the launch of LF India for community building. Ram emphasizes the importance of education and local partnerships in fostering a strong open-source culture. With a mix of technical insights and fun banter, he sheds light on upcoming events and the vibrant, passionate community driving these initiatives.

9 snips
Jul 1, 2025 • 30min
From Lockpicking to Leadership: Tabatha DiDomenico on Security, Open Source, and Building Community
Tabatha DiDomenico, an open source security engineer and community leader, shares her inspiring journey from a curious techie to a leader at G-Research and BSides Orlando. She discusses the pivotal role of DevRel in fostering vibrant open source ecosystems and the importance of local communities in cybersecurity. Tabatha emphasizes the value of volunteering for networking and shares insights on creating internal open source cultures. This captivating conversation offers practical advice for anyone looking to thrive in the open source world.

Jun 17, 2025 • 20min
Bridging DevOps and Security: Tracy Reagan on the Future of Open Source
In this episode of What's in the SOSS, we sit down with longtime open source leader and DevOps champion Tracy Ragan. From her early days with the Eclipse Foundation to her current work with Ortelius, the Continuous Delivery Foundation, and the OpenSSF, Tracy shares her journey through the ever-evolving world of open source security.We dig into the importance of configuration management, what DevSecOps really means, and how projects like the OpenSSF Scorecard and Ortelius help make our software supply chains more transparent and secure. Plus, we tackle the education gap between security pros and DevOps engineers—and how we can bridge it.If you're curious about building more secure pipelines or just want to geek out about SBOMs and Scorecard, this episode is for you.Chapters:00:25 – Welcome + Tracy's Open Source Origin Story02:00 – Early Days at the Eclipse Foundation03:10 – DevOps + DevSecOps: Why It Matters04:20 – Explaining the DevOps “Factory Floor”06:00 – DevOps Pipelines as Security Data Engines07:50 – What Is the OpenSSF Scorecard?09:30 – Ortelius: Aggregating DevOps + Security Insights11:20 – The DevOps Budget Problem + Exposing Insecure Packages13:00 – Why DevRel Is Critical for DevOps Security Education15:40 – Crossing the Divide Between DevOps and Security Teams16:10 – 🎉 Rapid Fire: Editors, Mascots & Spicy Food17:30 – Final Call to Action + How to Get InvolvedEpisode links:Tracy Ragan’s LinkedIn pageOrtelius ProjectScorecard ProjectEclipse FoundationCD FoundationGet involved with the OpenSSFSubscribe to the OpenSSF newsletterFollow the OpenSSF on LinkedIn