Episode

Abandoned open source with Josh Marpet

Podcast
Open Source Security
Published
Jul 20, 2026
Duration seconds
2056
Processing state
not_requested
Canonical source
https://opensourcesecuritypodcast.libsyn.com/abandoned-open-source-with-josh-marpet
Audio
https://traffic.libsyn.com/secure/opensourcesecuritypodcast/2026-07-VCRI-josh-marpet.mp3?dest-id=542864
JSON
/v1/public/podcasts/open-source-security-518991/episodes/abandoned-open-source-with-josh-marpet
Markdown
/podcast/open-source-security-518991/abandoned-open-source-with-josh-marpet.md

Actions

  • POST https://stenobird.com/v1/public/podcasts/open-source-security-518991/episodes/abandoned-open-source-with-josh-marpet/transcription-requests
    Idempotently request low-priority transcript generation for this episode.
  • GET https://stenobird.com/podcast/open-source-security-518991/abandoned-open-source-with-josh-marpet.md
    Read the agent-friendly Markdown representation of this episode resource.

Summary

Josh welcomes Josh Marpet for a discussion about abandoned open source packages. Josh Marpet has a foundation called Value Chain Risk Institute that has a report discussion how to start measuring if an open source package might be abandoned. There's a lot of data, but not a lot of groups using that data to help make informed decisions about using open source. VCRI is one of those places that's starting to do this. The show notes and blog post for this episode can be found at https://opensourcesecurity.io/2026/2026-07-VCRI-josh-marpet