{"podcast":{"title":"Sustain","slug":"sustain-796832","podcast_index_feed_id":796832,"rss_url":"https://feeds.fireside.fm/sustain/rss","website_url":"https://podcast.sustainoss.org","image_url":"https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/2/27729c65-f4a6-4496-8c86-820e7f13b285/cover.jpg?v=6","author":"SustainOSS","episode_count":292,"summary":"Sustain brings together practitioners, sustainers, funders, researchers and maintainers of the open source ecosystem. We have conversations about the health and sustainability of the open source community. We learn about the ins and outs of what ‘open source’ entails in the real world. Open source means so much more than a license; we're interested in talking about how to make sure that the culture of open source continues, grows, and ultimately, sustains itself. Newsletter","last_synced_at":"2026-07-25T02:20:58.603315+00:00","page_url":"https://stenobird.com/podcast/sustain-796832"},"episode":{"title":"Episode 290: Andrew Nesbitt on AI, Transitive Dependencies, and the New Open Source Security Crunch","slug":"episode-290-andrew-nesbitt-on-ai-transitive-dependencies-and-the-new-open-source-security-crunch","published_at":"2026-07-20T14:00:00+00:00","page_url":"https://stenobird.com/podcast/sustain-796832/episode-290-andrew-nesbitt-on-ai-transitive-dependencies-and-the-new-open-source-security-crunch","show_page_url":"https://stenobird.com/podcast/sustain-796832","url":"https://podcast.sustainoss.org/290","audio_url":"https://aphid.fireside.fm/d/1437767933/27729c65-f4a6-4496-8c86-820e7f13b285/f04d9efa-78ed-48c4-9886-7cede5913c4b.mp3","summary":"At UN Open Source Week in New York, Richard hosts a short, on-the-fly Sustain mini-episode from IBM’s offices with Andrew Nesbitt of Ecosyste.ms, a registry-of-registries built from dependency data across 300 million repositories. Nesbitt explains how that data is being used to prioritize security scanning with new AI models, revealing that many heavily used but dormant transitive dependencies—often unseen and unaudited—are high risk; in his testing of about 3,000 critical, abandoned projects across multiple ecosystems, roughly 50% had serious vulnerabilities, including logic flaws that can chain across dependency trees. He warns that LLMs accelerate both discovery and exploitation, shrinking traditional 90-day disclosure windows to effectively zero. They urge developers to prune and update dependencies and devices promptly, and to support maintainers respectfully—financially or with broader help—amid vulnerability floods and initiatives like the “Summer of Bliss.” 00:00 UN Open Source Week 00:58 Meet Andrew Nesbitt 01:45 AI Models Meet Dependency Data 04:05 The Hidden Transitive Risk 07:02 Abandoned Packages Crisis 08:34 Why It Matters Now 09:44 Responsible Disclosure Shrinks 11:48 What You Can Do Today 13:10 Support Maintainers Better 15:30 Wrap Up and Call to Action Special Guest: Andrew Nesbitt. Support Sustain","meta_description":"At UN Open Source Week in New York, Richard hosts a short, on-the-fly Sustain mini-episode from IBM’s offices with Andrew Nesbitt of Ecosyste.ms, a regist…","key_points":[],"chapters":[],"topics":[],"duration_seconds":970,"processing_state":"not_requested","actions":[{"name":"request_transcript","method":"POST","url":"https://stenobird.com/v1/public/podcasts/sustain-796832/episodes/episode-290-andrew-nesbitt-on-ai-transitive-dependencies-and-the-new-open-source-security-crunch/transcription-requests","description":"Idempotently request low-priority transcript generation for this episode."},{"name":"read_markdown","method":"GET","url":"https://stenobird.com/podcast/sustain-796832/episode-290-andrew-nesbitt-on-ai-transitive-dependencies-and-the-new-open-source-security-crunch.md","description":"Read the agent-friendly Markdown representation of this episode resource."}]}}