
technologyMar 1, 20221:28:21pending
Securing the open source supply chain (Interview)
About this episode
This week we're joined by the "mad scientist" himself, Feross Aboukhadijeh...and we're talking about the launch of Socket — the next big thing in the fight to secure and protect the open source supply chain.
While working on the frontlines of open source, Feross and team have witnessed firsthand how supply chain attacks have swept across the software community and have damaged the trust in open source. Socket turns the problem of securing open source software on its head, and asks..."What if we assume all open source may be malicious?" So, they built a system that proactively detects indicators of compromised open source packages and brings awareness to teams in real-time. We cover the whys, the hows, and what's next for this ambitious and very much needed project.
Get every episode summarized
Each time The Changelog: Software Development, Open Source publishes, we email you a written briefing from the transcript — the topics, who appeared, and any specific claims, with the ad reads skipped.
Email me new episodesFree for 3 shows. No card needed.
No transcript yet
This episode has not been transcribed. Request it and it moves to the front of the queue.
More episodes
More from The Changelog: Software Development, Open Source

Forking Cal.com to closed source (Interview)
The Changelog: Software Development, Open Source
Sep 3, 20261:54:32pending

Postgres at PlanetScale (Interview)
The Changelog: Software Development, Open Source
Aug 25, 20261:42:17pending

Canary tokens and digital tripwires (Interview)
The Changelog: Software Development, Open Source
Jul 21, 20262:06:48pending

From open source hits to OpenAI (Interview)
The Changelog: Software Development, Open Source
Jun 5, 20261:46:28pending