# Abandoned open source with Josh Marpet Page: https://stenobird.com/podcast/open-source-security-518991/abandoned-open-source-with-josh-marpet Text version: https://stenobird.com/podcast/open-source-security-518991/abandoned-open-source-with-josh-marpet.md Podcast: [Open Source Security](https://stenobird.com/podcast/open-source-security-518991) Published: 2026-07-20T00:00:00+00:00 Episode link: https://opensourcesecuritypodcast.libsyn.com/abandoned-open-source-with-josh-marpet Audio file: https://traffic.libsyn.com/secure/opensourcesecuritypodcast/2026-07-VCRI-josh-marpet.mp3?dest-id=542864 Processing state: not_requested JSON: https://stenobird.com/v1/public/podcasts/open-source-security-518991/episodes/abandoned-open-source-with-josh-marpet Duration seconds: 2056 ## Resource Josh welcomes Josh Marpet for a discussion about abandoned open source packages. Josh Marpet has a foundation called Value Chain Risk Institute that has a report discussion how to start measuring if an open source package might be abandoned. There's a lot of data, but not a lot of groups using that data to help make informed decisions about using open source. VCRI is one of those places that's starting to do this. The show notes and blog post for this episode can be found at https://opensourcesecurity.io/2026/2026-07-VCRI-josh-marpet ## Actions - request_transcript: `POST https://stenobird.com/v1/public/podcasts/open-source-security-518991/episodes/abandoned-open-source-with-josh-marpet/transcription-requests` — Idempotently request low-priority transcript generation for this episode. - read_markdown: `GET https://stenobird.com/podcast/open-source-security-518991/abandoned-open-source-with-josh-marpet.md` — Read the agent-friendly Markdown representation of this episode resource. A page view does not enqueue transcription. Agents should invoke `request_transcript` explicitly when they need this episode processed. ## Transcript Full transcripts are not published on public pages unless there is a clear rights basis.