{"podcast":{"title":"Open Source Security","slug":"open-source-security-518991","podcast_index_feed_id":518991,"rss_url":"https://opensourcesecuritypodcast.libsyn.com/rss","website_url":"https://opensourcesecurity.io/","image_url":"https://static.libsyn.com/p/assets/3/f/1/a/3f1a5cea3e17863e16c3140a3186d450/OSS-square-podcast-libsyn.png","author":"Open Source Security","episode_count":539,"summary":"Open Source Security is a media project to help showcase and educate on open source security. Our goal is to give the community a platform educate both developers and users on how open source security works. There's a lot of good work happening that doesn't get attention because there's no marketing department behind it, they don't have a developer relations team posting on LinkedIn every two hours. Let's focus on those people and teams then learn what they do and how they do it. The goal is to hear from the people doing the work, they know what's up, they have a lot to teach us. We just have to listen.","last_synced_at":"2026-07-27T06:18:01.636638+00:00","page_url":"https://stenobird.com/podcast/open-source-security-518991"},"episode":{"title":"2026 State of the Software Supply Chain with Brian Fox","slug":"2026-state-of-the-software-supply-chain-with-brian-fox","published_at":"2026-03-23T00:00:00+00:00","page_url":"https://stenobird.com/podcast/open-source-security-518991/2026-state-of-the-software-supply-chain-with-brian-fox","show_page_url":"https://stenobird.com/podcast/open-source-security-518991","url":"https://opensourcesecuritypodcast.libsyn.com/2026-state-of-the-software-supply-chain-with-brian-fox","audio_url":"https://traffic.libsyn.com/secure/opensourcesecuritypodcast/2026-03-SOTSSC-Brian-Fox.mp3?dest-id=542864","summary":"Josh chats with Brian Fox from Sonatype about their 2026 State of the Software Supply Chain report. Most of the number continue to grow at alarming rates, but there's some new interesting findings in this one. We discuss end of life and open source which is tough to define. We touch on what using AI with open source dependencies looks like (and why it's broken), and we discuss the challenge of upgrading your open source dependencies in a way that doesn't break everything. It's a great report and great discussion. The show notes and blog post for this episode can be found at https://opensourcesecurity.io/2026/2026-03-SOTSSC-Brian-Fox/","meta_description":"Josh chats with Brian Fox from Sonatype about their 2026 State of the Software Supply Chain report. Most of the number continue to grow at alarming rates,…","key_points":[],"chapters":[],"topics":[],"duration_seconds":2148,"processing_state":"not_requested","actions":[{"name":"request_transcript","method":"POST","url":"https://stenobird.com/v1/public/podcasts/open-source-security-518991/episodes/2026-state-of-the-software-supply-chain-with-brian-fox/transcription-requests","description":"Idempotently request low-priority transcript generation for this episode."},{"name":"read_markdown","method":"GET","url":"https://stenobird.com/podcast/open-source-security-518991/2026-state-of-the-software-supply-chain-with-brian-fox.md","description":"Read the agent-friendly Markdown representation of this episode resource."}]}}