# Open source is critical infrastructure with Kat Cosgrove Page: https://stenobird.com/podcast/open-source-security-518991/open-source-is-critical-infrastructure-with-kat-cosgrove Text version: https://stenobird.com/podcast/open-source-security-518991/open-source-is-critical-infrastructure-with-kat-cosgrove.md Podcast: [Open Source Security](https://stenobird.com/podcast/open-source-security-518991) Published: 2026-05-11T00:00:00+00:00 Episode link: https://opensourcesecuritypodcast.libsyn.com/open-source-is-critical-infrastructure-with-kat-cosgrove Audio file: https://traffic.libsyn.com/secure/opensourcesecuritypodcast/2026-05-open-source-infrastructure-kat.mp3?dest-id=542864 Processing state: not_requested JSON: https://stenobird.com/v1/public/podcasts/open-source-security-518991/episodes/open-source-is-critical-infrastructure-with-kat-cosgrove Duration seconds: 2281 ## Resource Josh talks to Kat Cosgrove about a how companies should be treating open source more like their critical infrastructure than free stuff. Kat has a ton of knowledge about how the interactions between companies and open source communities can work well, or not work at all. Kat's time on the Kubernetes Release Team. We touch on how a project like Kubernetes is super successful, while another, Ingress NGINX, was not. It's a super insightful discussion with a ton of lessons and advice for everyone. The show notes and blog post for this episode can be found at https://opensourcesecurity.io/2026/2026-05-open-source-infrastructure-kat/ ## Actions - request_transcript: `POST https://stenobird.com/v1/public/podcasts/open-source-security-518991/episodes/open-source-is-critical-infrastructure-with-kat-cosgrove/transcription-requests` — Idempotently request low-priority transcript generation for this episode. - read_markdown: `GET https://stenobird.com/podcast/open-source-security-518991/open-source-is-critical-infrastructure-with-kat-cosgrove.md` — Read the agent-friendly Markdown representation of this episode resource. A page view does not enqueue transcription. Agents should invoke `request_transcript` explicitly when they need this episode processed. ## Transcript Full transcripts are not published on public pages unless there is a clear rights basis.