<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"><channel><description>Mostly on Mastodon - VP of Security at Anchore - Open Source Security https://opensourcesecurity.io - Hacker History http://hackerhistory.com - He/Him</description><link>https://bsky.app/profile/josh.bressers.name</link><title>@josh.bressers.name - Josh Bressers</title><item><link>https://bsky.app/profile/josh.bressers.name/post/3mvie4gqca22b</link><description>The first #CRA requirements started a few days ago. I chatted with Danial Thompson about what that means and what comes next&#xA;&#xA;Daniel has a ton of CRA knowledge, this first step isn&#39;t going to change a ton, but what&#39;s coming next will&#xA;&#xA;https://opensourcesecurity.io/2026/2026-09-daniel-cra/</description><pubDate>14 Sep 2026 14:47 +0000</pubDate><guid isPermaLink="false">at://did:plc:rogdgdlystxgcyh3pg6uswtr/app.bsky.feed.post/3mvie4gqca22b</guid></item><item><link>https://bsky.app/profile/josh.bressers.name/post/3muwpbjrjx22h</link><description>I had a chat with Jaya Baloo from AISLE about why they seem to be finding vulnerabilities even when the new fancy tools aren&#39;t finding anything&#xA;&#xA;The answer is unsurprisingly &#34;engineering&#34;&#xA;&#xA;Jaya has a ton of interesting insight, including how to work with open source projects and what&#39;s coming next&#xA;https://opensourcesecurity.io/2026/2026-09-jaya-aisle/</description><pubDate>07 Sep 2026 14:19 +0000</pubDate><guid isPermaLink="false">at://did:plc:rogdgdlystxgcyh3pg6uswtr/app.bsky.feed.post/3muwpbjrjx22h</guid></item><item><link>https://bsky.app/profile/josh.bressers.name/post/3muezth6lbc2s</link><description>I had a chat with Erik Möller from @sovereign.tech about what they&#39;re doing in the universe of funding open source&#xA;&#xA;Eric breaks down what they&#39;re doing, how it works, and how you can apply for funding. We even learn about some similar projects happening in the EU&#xA;https://opensourcesecurity.io/2026/2026-08-erik-sta/</description><pubDate>31 Aug 2026 13:40 +0000</pubDate><guid isPermaLink="false">at://did:plc:rogdgdlystxgcyh3pg6uswtr/app.bsky.feed.post/3muezth6lbc2s</guid></item><item><link>https://bsky.app/profile/josh.bressers.name/post/3mttenkauwc2d</link><description>This week on #OpenSourceSecurity I had a chat with @paulasadoorian.bsky.social about a tool he wrote called Fettle and a report on CVEs he wrote&#xA;&#xA;We love making a huge deal about individual CVEs, but most of us have to deal with advisories that clump them together&#xA;https://opensourcesecurity.io/2026/2026-08-paul-fettle-cve/</description><pubDate>24 Aug 2026 13:06 +0000</pubDate><guid isPermaLink="false">at://did:plc:rogdgdlystxgcyh3pg6uswtr/app.bsky.feed.post/3mttenkauwc2d</guid></item><item><link>https://bsky.app/profile/josh.bressers.name/post/3mtbvd5a3x22u</link><description>I had a chat with Erin Schnabel and Rob Nalen about a sustainability project between @commonhaus.org and HeroDevs&#xA;&#xA;The idea is to bring together the EOL business model from HeroDevs and use that to help further some of the Commonhaus software catalog&#xA;https://opensourcesecurity.io/2026/2026-08-commonhaus-herodevs/</description><pubDate>17 Aug 2026 14:16 +0000</pubDate><guid isPermaLink="false">at://did:plc:rogdgdlystxgcyh3pg6uswtr/app.bsky.feed.post/3mtbvd5a3x22u</guid></item><item><link>https://bsky.app/profile/josh.bressers.name/post/3ms6qhveyn22l</link><description>This week on #OpenSourceSecurity I chat with @patrickmgarrity.bsky.social from @vulncheck.bsky.social about a report they wrote that looked at the number of actually exploited vulnerabilities&#xA;&#xA;The increase of CVEs is out of control, but the number of things that get exploited is flat&#xA;https://opensourcesecurity.io/2026/2026-08-vulncheck-state-of-exploitation/</description><pubDate>03 Aug 2026 14:46 +0000</pubDate><guid isPermaLink="false">at://did:plc:rogdgdlystxgcyh3pg6uswtr/app.bsky.feed.post/3ms6qhveyn22l</guid></item><item><link>https://bsky.app/profile/josh.bressers.name/post/3mrn5cfle222u</link><description>I had a chat with @joshcorman.bsky.social about securing critical infrastructure on #OSSPodcast &#xA;&#xA;Josh is one of the best in the industry on this topic. He has a ton of interesting (and sometimes scary) things to say about this&#xA;&#xA;https://opensourcesecurity.io/2026/2026-07-critical-infrastructure-josh-corman/</description><pubDate>27 Jul 2026 14:48 +0000</pubDate><guid isPermaLink="false">at://did:plc:rogdgdlystxgcyh3pg6uswtr/app.bsky.feed.post/3mrn5cfle222u</guid></item><item><link>https://bsky.app/profile/josh.bressers.name/post/3mr3hzgetvs2f</link><description>I chatted with Josh Marpet about a report his group, Value Chain Risk Institute, published showing the data behind open source dependencies&#xA;&#xA;It&#39;s not great, but having data that shows the problem is a big deal. There are a lot of opinions about open source and not a lot of data&#xA;https://opensourcesecurity.io/2026/2026-07-VCRI-josh-marpet/</description><pubDate>20 Jul 2026 14:12 +0000</pubDate><guid isPermaLink="false">at://did:plc:rogdgdlystxgcyh3pg6uswtr/app.bsky.feed.post/3mr3hzgetvs2f</guid></item><item><link>https://bsky.app/profile/josh.bressers.name/post/3mqjvkqdplk2o</link><description>I got to chat with @mairin.bsky.social about Red Hat&#39;s Project Lightwell on #OpenSourceSecurity &#xA;&#xA;It&#39;s going to be interesting to figure out how everyone will start interacting with open source projects. This is something Red Hat is pretty good at already&#xA;&#xA;https://opensourcesecurity.io/2026/2026-07-lightwell-mo-duffy/</description><pubDate>13 Jul 2026 14:26 +0000</pubDate><guid isPermaLink="false">at://did:plc:rogdgdlystxgcyh3pg6uswtr/app.bsky.feed.post/3mqjvkqdplk2o</guid></item><item><link>https://bsky.app/profile/josh.bressers.name/post/3mpycscxums25</link><description>I had a chat with Lori Lorusso and Niko Matsakis about the Rust Foundation Maintainers Fund&#xA;&#xA;Funding open source is a huge topic right now, the Rust Foundation has some great ideas. It will be exciting to watch this one grow and evolve&#xA;&#xA;#OpenSourceSecurity #rust #RustFoundation&#xA;https://opensourcesecurity.io/2026/2026-07-rfmf-lori-niko/</description><pubDate>06 Jul 2026 14:35 +0000</pubDate><guid isPermaLink="false">at://did:plc:rogdgdlystxgcyh3pg6uswtr/app.bsky.feed.post/3mpycscxums25</guid></item><item><link>https://bsky.app/profile/josh.bressers.name/post/3mpgsm32hbs2v</link><description>I had the pleasure to chat with @allanfriedman.bsky.social about Bill of Materials things on #OpenSourceSecurity &#xA;&#xA;We touched on SBOMs, HBOMs, AIBOMs, and even some other BOM types I can&#39;t remember now&#xA;&#xA;Allan is always fun to chat with, and he has encyclopedic knowledge about the BOM universe&#xA;https://opensourcesecurity.io/2026/2026-06-allan-omnibom/</description><pubDate>29 Jun 2026 15:30 +0000</pubDate><guid isPermaLink="false">at://did:plc:rogdgdlystxgcyh3pg6uswtr/app.bsky.feed.post/3mpgsm32hbs2v</guid></item><item><link>https://bsky.app/profile/josh.bressers.name/post/3mov34lms4226</link><description>I had a chat with Jordi Boggiano from Packagist about a heap of security features they recently added and adding in the future&#xA;&#xA;The security of the public package repositories is a hot topic right now, Packagist is doing some really interesting things to improve their security&#xA;https://opensourcesecurity.io/2026/2026-06-packagist-security-jordi/</description><pubDate>22 Jun 2026 14:15 +0000</pubDate><guid isPermaLink="false">at://did:plc:rogdgdlystxgcyh3pg6uswtr/app.bsky.feed.post/3mov34lms4226</guid></item><item><link>https://bsky.app/profile/josh.bressers.name/post/3modjt77jec26</link><description>I had a chat on #OpenSourceSecurity with Mike Milinkovich and Thabang Mashologu from @eclipse.org about their new managed Open VSX registry&#xA;&#xA;The Eclipse Foundation has a plan that seems pretty sensible to keep the Open VSX registry around for a long time&#xA;https://opensourcesecurity.io/2026/2026-06-openvsx-mike-thabang/</description><pubDate>15 Jun 2026 14:50 +0000</pubDate><guid isPermaLink="false">at://did:plc:rogdgdlystxgcyh3pg6uswtr/app.bsky.feed.post/3modjt77jec26</guid></item><item><link>https://bsky.app/profile/josh.bressers.name/post/3mnru3k2fus2m</link><description>I had a chat with @francoisproulx.bsky.social about CI/CD security and a tool he built to red team your own pipelines. Holy cow this is a wild topic right now. I chatted with François a bit over a year ago before CI/CD lit on fire, his warnings were very apt&#xA;&#xA;https://opensourcesecurity.io/2026/2026-06-fran%C3%A7ois-smoked-meat/</description><pubDate>08 Jun 2026 14:06 +0000</pubDate><guid isPermaLink="false">at://did:plc:rogdgdlystxgcyh3pg6uswtr/app.bsky.feed.post/3mnru3k2fus2m</guid></item><item><link>https://bsky.app/profile/josh.bressers.name/post/3mlldvfj2zs2e</link><description>I had a chat on #OpenSourceSecurity with Kat Cosgrove about open source being critical infrastructure&#xA;&#xA;Kat has a ton of experience in the world of Kubernetes and had some really interesting things to tell us about both successful projects as well as having to shut down projects&#xA;https://opensourcesecurity.io/2026/2026-05-open-source-infrastructure-kat/</description><pubDate>11 May 2026 13:09 +0000</pubDate><guid isPermaLink="false">at://did:plc:rogdgdlystxgcyh3pg6uswtr/app.bsky.feed.post/3mlldvfj2zs2e</guid></item><item><link>https://bsky.app/profile/josh.bressers.name/post/3mkzxxeld5s2k</link><description>The the wrap up with David Bernstein around how to test a disaster recovery / emergency response plan&#xA;&#xA;I&#39;m pretty excited to get these out, it feels like this topic is more relevant than it&#39;s ever been and David does a nice job explaining it all&#xA;&#xA;https://opensourcesecurity.io/2026/2026-05-testing-the-plan-david-bernstein/</description><pubDate>04 May 2026 15:21 +0000</pubDate><guid isPermaLink="false">at://did:plc:rogdgdlystxgcyh3pg6uswtr/app.bsky.feed.post/3mkzxxeld5s2k</guid></item><item><link>https://bsky.app/profile/josh.bressers.name/post/3mkic4dbua22s</link><description>I had a chat with @vlad.website about the @opensourcepledge.com &#xA;&#xA;Vlad has a ton of insight into how hard it is to just figure out what you&#39;re running plus the challenges maintainers have&#xA;&#xA;Vlad has a ton of great ideas how to start tackling some of these incredibly difficult problems&#xA;https://opensourcesecurity.io/2026/2026-04-open-source-pledge-vlad/</description><pubDate>27 Apr 2026 14:34 +0000</pubDate><guid isPermaLink="false">at://did:plc:rogdgdlystxgcyh3pg6uswtr/app.bsky.feed.post/3mkic4dbua22s</guid></item><item><link>https://bsky.app/profile/josh.bressers.name/post/3mjws2kzzwk2w</link><description>I had chat with David Bernstein about creating a disaster recovery plan on #OpenSourceSecurity &#xA;&#xA;With all the events unfolding almost every day lately, there&#39;s never been a better time to put a plan like this together. In a few weeks David will tell us how to test such a plan once we create it&#xA;https://opensourcesecurity.io/2026/2026-04-disaster-planning-david-bernstein/</description><pubDate>20 Apr 2026 15:32 +0000</pubDate><guid isPermaLink="false">at://did:plc:rogdgdlystxgcyh3pg6uswtr/app.bsky.feed.post/3mjws2kzzwk2w</guid></item><item><link>https://bsky.app/profile/josh.bressers.name/post/3mjmproyi222d</link><description>A new #HackerHistory is out!&#xA;&#xA;This time we hear the story of Pyr0&#xA;&#xA;Pyr0 tells us about a new upcoming conference all about hacker history, NaClCON&#xA;&#xA;Then we hear about a lot of awesome hacker history&#xA;&#xA;It&#39;s a great story!&#xA;&#xA;https://hackerhistory.com/podcast/the-history-of-pyr0/</description><pubDate>16 Apr 2026 15:24 +0000</pubDate><guid isPermaLink="false">at://did:plc:rogdgdlystxgcyh3pg6uswtr/app.bsky.feed.post/3mjmproyi222d</guid></item><item><link>https://bsky.app/profile/josh.bressers.name/post/3mjezw62pns22</link><description>I had a chat with Paul McCarty about his project @opensourcemalware.bsky.social&#xA;&#xA;Paul has a ton of great insight into what&#39;s happening with the massive influx of malware into our open source ecosystems&#xA;&#xA;https://opensourcesecurity.io/2026/2026-04-open-source-malware-paul-mccarty/</description><pubDate>13 Apr 2026 14:05 +0000</pubDate><guid isPermaLink="false">at://did:plc:rogdgdlystxgcyh3pg6uswtr/app.bsky.feed.post/3mjezw62pns22</guid></item></channel></rss>