logo
episode-header-image
Mar 2022
1h 28m

Securing the open source supply chain (C...

CHANGELOG MEDIA
About this episode
This week we're joined by the "mad scientist" himself, Feross Aboukhadijeh...and we're talking about the launch of Socket — the next big thing in the fight to secure and protect the open source supply chain. While working on the frontlines of open source, Feross and team have witnessed firsthand how supply chain attacks have swept across the software comm ... Show More
Up next
Sep 3
Forking Cal.com to closed source (Changelog Interviews #685)
This week I'm joined by Peer Richelsen, co-founder of Cal.com. What if the majority of open source repositories are already compromised and we just don't know it yet? That's the theory Peer brings to the table this week. We dig into how AI has flattened the knowledge graph to the ... Show More
1h 54m
Aug 25
Postgres at PlanetScale (Changelog Interviews #684)
Sam Lambert is back after 4 years and he does not hold back! We cover $5 PlanetScale Postgres, the Neki "do-over" of Vitess, agents shipping schema changes through deploy requests, rolling back a 500TB table in seconds, and the very real question of whether to open source any of ... Show More
1h 42m
Jul 21
Canary tokens and digital tripwires (Changelog Interviews #683)
Haroon Meer is back! Haroon is the Founder of Thinkst, the ~50-person bootstrapped company behind Canary and Canarytokens — honeypots and tripwires you sprinkle inside your network and forget about until an attacker touches one. We talk about the AWS API key token attackers just ... Show More
2h 6m
Recommended Episodes
Jan 2022
What's in your package.json?
Tobie Langel, Open source strategist and Principal at UnlockOpen, joins Chris, Feross, and Amal to discuss recent widespread incidents affecting the JavaScript community (and breaking CI builds) around the globe. Two widely used npm libraries were self-sabotaged by their single m ... Show More
1h 9m
Nov 2024
ANTHOLOGY — Packages, pledges & protocols (Interview)
The hallway track at All Things Open 2024 — features Carl George, Principal Software Engineer at Red Hat for a discussion on the state of open source enterprise linux and RHEL (Red Hat Enterprise Linux), Max Howell, creator of Homebrew and tea.xyz which offers rewards and recogni ... Show More
1h 45m
Jun 2024
Yet another open source rug pull (News)
A popular open source iOS authenticator app goes rogue under new ownership, Andreas Kling steps back from SerenityOS & forks Ladybird, Vhyrro takes a thought-provoking try at a "static effect system", Matt Bessey is over GraphQL & Marc-Andre Giroux still likes GraphQL sometimes ( ... Show More
9m 47s
Apr 2017
First-time contributors and maintainer balance (Interview)
Kent C. Dodds joined the show to talk about guiding and supporting first time contributors to open source. We talked about the many ways to be first-timer friendly, how to contribute to open source, the burden and balance of a maintainer, and a few of the projects Kent maintains, ... Show More
1h 13m
Nov 2016
Mad science, WebTorrent, WebRTC (Interview)
Feross Aboukhadijeh joined the show this week to talk with us about his backstory, passive income, WebTorrent, WebRTC, Electron and the ins and outs of packaging apps for all platforms. 
1h 21m
Apr 2025
894: Open Source Matters w/ Chad Whitacre
Wes and Scott talk with Chad Whitacre, the newest member of the Syntax team, about all things open source—licenses, controversies, economics, and ethics. Chad breaks down what most people misunderstand, and how companies can support sustainable software development the right way. ... Show More
1h 1m
Nov 2021
Open Source Software and Digital Transformation
tail spinning
21m 21s
Oct 2017
Franklin talks about open-source vulnerabilities, DevSecOps & how cyber talent can become rockstars
Franklin Mosley is a known speaker on security talent and application security. He joins the podcast to talk about open-source vulnerabilities, DevSecOps, and what it takes to be a Rockstar security professional. We grill him in Overrated/Underrated with topics like hiring malici ... Show More
25m 9s