Episode
2026 State of the Software Supply Chain with Brian Fox
- Podcast
- Open Source Security
- Published
- Mar 23, 2026
- Duration seconds
- 2148
- Processing state
not_requested
Actions
POST https://stenobird.com/v1/public/podcasts/open-source-security-518991/episodes/2026-state-of-the-software-supply-chain-with-brian-fox/transcription-requests
Idempotently request low-priority transcript generation for this episode.GET https://stenobird.com/podcast/open-source-security-518991/2026-state-of-the-software-supply-chain-with-brian-fox.md
Read the agent-friendly Markdown representation of this episode resource.
Summary
Josh chats with Brian Fox from Sonatype about their 2026 State of the Software Supply Chain report. Most of the number continue to grow at alarming rates, but there's some new interesting findings in this one. We discuss end of life and open source which is tough to define. We touch on what using AI with open source dependencies looks like (and why it's broken), and we discuss the challenge of upgrading your open source dependencies in a way that doesn't break everything. It's a great report and great discussion. The show notes and blog post for this episode can be found at https://opensourcesecurity.io/2026/2026-03-SOTSSC-Brian-Fox/