# 2026 State of the Software Supply Chain with Brian Fox Page: https://stenobird.com/podcast/open-source-security-518991/2026-state-of-the-software-supply-chain-with-brian-fox Text version: https://stenobird.com/podcast/open-source-security-518991/2026-state-of-the-software-supply-chain-with-brian-fox.md Podcast: [Open Source Security](https://stenobird.com/podcast/open-source-security-518991) Published: 2026-03-23T00:00:00+00:00 Episode link: https://opensourcesecuritypodcast.libsyn.com/2026-state-of-the-software-supply-chain-with-brian-fox Audio file: https://traffic.libsyn.com/secure/opensourcesecuritypodcast/2026-03-SOTSSC-Brian-Fox.mp3?dest-id=542864 Processing state: not_requested JSON: https://stenobird.com/v1/public/podcasts/open-source-security-518991/episodes/2026-state-of-the-software-supply-chain-with-brian-fox Duration seconds: 2148 ## Resource Josh chats with Brian Fox from Sonatype about their 2026 State of the Software Supply Chain report. Most of the number continue to grow at alarming rates, but there's some new interesting findings in this one. We discuss end of life and open source which is tough to define. We touch on what using AI with open source dependencies looks like (and why it's broken), and we discuss the challenge of upgrading your open source dependencies in a way that doesn't break everything. It's a great report and great discussion. The show notes and blog post for this episode can be found at https://opensourcesecurity.io/2026/2026-03-SOTSSC-Brian-Fox/ ## Actions - request_transcript: `POST https://stenobird.com/v1/public/podcasts/open-source-security-518991/episodes/2026-state-of-the-software-supply-chain-with-brian-fox/transcription-requests` — Idempotently request low-priority transcript generation for this episode. - read_markdown: `GET https://stenobird.com/podcast/open-source-security-518991/2026-state-of-the-software-supply-chain-with-brian-fox.md` — Read the agent-friendly Markdown representation of this episode resource. A page view does not enqueue transcription. Agents should invoke `request_transcript` explicitly when they need this episode processed. ## Transcript Full transcripts are not published on public pages unless there is a clear rights basis.