{"podcast":{"title":"Open Source Security","slug":"open-source-security-518991","podcast_index_feed_id":518991,"rss_url":"https://opensourcesecuritypodcast.libsyn.com/rss","website_url":"https://opensourcesecurity.io/","image_url":"https://static.libsyn.com/p/assets/3/f/1/a/3f1a5cea3e17863e16c3140a3186d450/OSS-square-podcast-libsyn.png","author":"Open Source Security","episode_count":539,"summary":"Open Source Security is a media project to help showcase and educate on open source security. Our goal is to give the community a platform educate both developers and users on how open source security works. There's a lot of good work happening that doesn't get attention because there's no marketing department behind it, they don't have a developer relations team posting on LinkedIn every two hours. Let's focus on those people and teams then learn what they do and how they do it. The goal is to hear from the people doing the work, they know what's up, they have a lot to teach us. We just have to listen.","last_synced_at":"2026-07-27T06:18:01.636638+00:00","page_url":"https://stenobird.com/podcast/open-source-security-518991"},"episode":{"title":"Abandoned open source with Josh Marpet","slug":"abandoned-open-source-with-josh-marpet","published_at":"2026-07-20T00:00:00+00:00","page_url":"https://stenobird.com/podcast/open-source-security-518991/abandoned-open-source-with-josh-marpet","show_page_url":"https://stenobird.com/podcast/open-source-security-518991","url":"https://opensourcesecuritypodcast.libsyn.com/abandoned-open-source-with-josh-marpet","audio_url":"https://traffic.libsyn.com/secure/opensourcesecuritypodcast/2026-07-VCRI-josh-marpet.mp3?dest-id=542864","summary":"Josh welcomes Josh Marpet for a discussion about abandoned open source packages. Josh Marpet has a foundation called Value Chain Risk Institute that has a report discussion how to start measuring if an open source package might be abandoned. There's a lot of data, but not a lot of groups using that data to help make informed decisions about using open source. VCRI is one of those places that's starting to do this. The show notes and blog post for this episode can be found at https://opensourcesecurity.io/2026/2026-07-VCRI-josh-marpet","meta_description":"Josh welcomes Josh Marpet for a discussion about abandoned open source packages. Josh Marpet has a foundation called Value Chain Risk Institute that has a…","key_points":[],"chapters":[],"topics":[],"duration_seconds":2056,"processing_state":"not_requested","actions":[{"name":"request_transcript","method":"POST","url":"https://stenobird.com/v1/public/podcasts/open-source-security-518991/episodes/abandoned-open-source-with-josh-marpet/transcription-requests","description":"Idempotently request low-priority transcript generation for this episode."},{"name":"read_markdown","method":"GET","url":"https://stenobird.com/podcast/open-source-security-518991/abandoned-open-source-with-josh-marpet.md","description":"Read the agent-friendly Markdown representation of this episode resource."}]}}