Rephonic
Artwork for What's in the SOSS? An OpenSSF Podcast

What's in the SOSS? An OpenSSF Podcast

OpenSSF
Open Source
Cybersecurity
Vulnerability Management
Openssf
Google
Memory Safety
Open Source Security Foundation
Vulnerabilities
AI Cyber Challenge
Red Hat
Software Security
Open Source Security
Software Development
Open Source Software
Information Security
Apis
Common Weakness Enumeration
AI and Machine Learning
Open Source Software Security
Openai

What's in the SOSS? features the sharpest minds in security as they dig into the challenges and opportunities that create a recipe for success in making software more secure. Get a taste of all the ingredients that make up secure open source software (SOSS) and explore the latest trends at the intersection of AI and security, vulnerability management, and threat assessments. Each episode of What's... more

PublishesWeeklyEpisodes57Founded2 years ago
Number of ListenersCategory
Technology

Listen to this Podcast

Artwork for What's in the SOSS? An OpenSSF Podcast

Latest Episodes

In this episode of What’s in the SOSS? host Sally Cooper sits down with Yesenia Yser, co-lead of the OpenSSF Mentorship Program and the BEAR Working Group, and Kairo De Araujo, Open Source Software Engineer and mentor for rstuf. They dive into the su... more

Hannah Braswell and Jenn Power, security engineers from Red Hat and contributors to the OpenSSF, join host Sally Cooper to discuss the Gemara project. Gemara, an acronym for GRC Engineering Model for Automated Risk Assessment, is a seven-layer logica... more

In this final episode of our AI Cyber Challenge (AIxCC) series, CRob and Jeff Diecks wrap-up the journey from DARPA's groundbreaking two-year competition to the exciting collaborative phase happening now. Discover how winning teams are taking their A... more

In the final episode of our AI Cyber Challenge (AIxCC) series, CRob sits down with Michael Brown, Principal Security Engineer at Trail of Bits, to discuss their runner-up cybersecurity reasoning system, Buttercup. Michael shares how their team took a... more

In this 2nd episode in our series on DARPA's AI Cyber Challenge (AIxCC), CRob sits down with Professor Taesoo Kim from Georgia Tech to discuss Team Atlanta's journey to victory. Kim shares how his team - comprised of academics, world-class hackers, a... more

This episode of What’s in the SOSS features Andrew Carney from DARPA and ARPA-H, discussing the groundbreaking AI Cyber Challenge (AIxCC). The competition was designed to create autonomous systems capable of finding and patching vulnerabilities in op... more

Ever wondered what it takes to get your talk accepted at a major open source tech conference – or even land a keynote slot? Join What’s in the Sauce new co-host Sally Cooper, as she sits down with Stacey Potter and Adolfo “Puerco” García Veytia, fres... more

In this special episode, the What's in the SOSS podcast welcomes Sally Cooper as an official co-host. Sally, who leads OpenSSF's marketing efforts, shares her journey from hands-on technical roles in training and documentation to becoming a bridge be... more

Key Facts

Accepts Guests
Contact Information
Podcast Host
Number of Listeners
Find out how many people listen to this podcast per episode and each month.

Similar Podcasts

People also subscribe to these shows.

Hard Fork
Hard ForkThe New York Times

Recent Guests

Justin Cappos
Professor at New York University, focused on software supply chain security
New York University
Episode: Teaching the Next Generation: Software Supply Chain Security in Academia with Justin Cappos
Eddie Knight
Specialist in security compliance and community member at Sonatype and the Linux Foundation
Sonatype
Episode: A Deep Dive into the Open Source Project Security (OSPS) Baseline
Ben Cotton
Open source community lead at Kusari and leader of the OSPS Baseline SIG
Kusari
Episode: A Deep Dive into the Open Source Project Security (OSPS) Baseline
David A. Wheeler
Director of Open Source Supply Chain Security at Linux Foundation's OpenSSF
Linux Foundation
Episode: New Education Course: Secure AI/ML-Driven Software Development (LFEL1012) with David A. Wheeler
John Amaral
Expert in open source security and software supply chain security, and co-founder of Root.io
Root.io
Episode: The Remediation Revolution: How AI Agents Are Transforming Open Source Security with John Amaral of Root.io
Amir Montezari
Managing Director of the Open Source Technology Improvement Fund (OSTIF)
OSTIF
Episode: Open Source Security: OSTIF's 10-Year Journey of Collaborative Audits
Derek Zimmer
Founder of the Open Source Technology Improvement Fund (OSTIF)
OSTIF
Episode: Open Source Security: OSTIF's 10-Year Journey of Collaborative Audits
Tabatha DiDomenico
Open source security engineer at G-Research
G-Research
Episode: From Lockpicking to Leadership: Tabatha DiDomenico on Security, Open Source, and Building Community
Zach Steindler
Works at GitHub on supply chain security, TAC Chair at OpenSSF.
GitHub
Episode: OpenSSF 2025 MVVSR Overview

Hosts

Christopher Robinson
Host with OpenSSF involvement, frequently guides discussions on cyber, application, and Open Source security.
Yesenia Sen
Co-host contributing domain expertise in security and OSS community participation.

Top Technology Podcasts

Acquired
AcquiredBen Gilbert and David Rosenthal
Tomorrow, Today
Tomorrow, TodayShekhar Natarajan
Technology Now
Technology NowHewlett Packard Enterprise
Hard Fork
Hard ForkThe New York Times
Building AI Boston
Building AI BostonBuilding AI Boston
Dwarkesh Podcast
Dwarkesh PodcastDwarkesh Patel

Talking Points

Recent interactions between the hosts and their guests.

AIxCC Part 2 - From Skeptics to Believers: How Team Atlanta Won AIxCC by Combining Traditional Security with LLMs
Q: What plans does the team have now that the competition is over?
We have commercialization efforts focusing on vulnerabilities in smart contracts and plans to provide an open-source version of our CRS for broader usage.
AIxCC Part 2 - From Skeptics to Believers: How Team Atlanta Won AIxCC by Combining Traditional Security with LLMs
Q: Was there anything that surprised you in the team and kind of changed your thinking about the capabilities of these tools?
We started off skeptical about the effectiveness of AI tools but were surprised by how much LLMs improved our capabilities, especially after the semifinal stage.
AIxCC Part 2 - From Skeptics to Believers: How Team Atlanta Won AIxCC by Combining Traditional Security with LLMs
Q: What was your team's approach? What was your strategy as you were kind of approaching the competition?
We utilized multiple backgrounds, combining academia, world-class hackers, and engineers from Samsung, focusing on both traditional techniques and innovative approaches to enhance our performance.
Demystifying the CFP Process with KubeCon North America Keynote Speakers
Q: Why are CFPs important to open source communities?
CFPs help diversify voices and shape narratives in communities, giving new speakers a chance to share fresh perspectives and ideas.
Demystifying the CFP Process with KubeCon North America Keynote Speakers
Q: What would you say to someone who feels like they are not expert enough to submit a CFP?
Imposter syndrome is a natural feeling; it shows that you are reflective about your work. You are already a step above others for being willing to research and propose your ideas.

Audience Metrics

Listeners, social reach, demographics and more for this podcast.

Listeners per Episode
Gender Skew
Location
Interests
Professions
Age Range
Household Income
Social Media Reach

Frequently Asked Questions About What's in the SOSS? An OpenSSF Podcast

What is What's in the SOSS? An OpenSSF Podcast about and what kind of topics does it cover?

The program consistently centers on open-source software security, governance, and the evolving role of AI in securing code, supply chains, and developer tooling. Episodes frequently explore practical security hygiene for open-source projects, OSINT-style vulnerability management, and the education and community-building efforts around OpenSSF initiatives. A recurring strength is translating complex security concepts into actionable guidance for maintainers, contributors, and organisations adopting open-source technologies. Notable twists include deep-dives into OSPS Baseline adoption, SBOM-related challenges, and the intersection of academia, industry collaboration, and open-source security practices, often anchored by practitioners active... more

Where can I find podcast stats for What's in the SOSS? An OpenSSF Podcast?

Rephonic provides a wide range of podcast stats for What's in the SOSS? An OpenSSF Podcast. We scanned the web and collated all of the information that we could find in our comprehensive podcast database. See how many people listen to What's in the SOSS? An OpenSSF Podcast and access YouTube viewership numbers, download stats, audience demographics, chart rankings, ratings, reviews and more.

How many listeners does What's in the SOSS? An OpenSSF Podcast get?

Rephonic provides a full set of podcast information for three million podcasts, including the number of listeners. View further listenership figures for What's in the SOSS? An OpenSSF Podcast, including podcast download numbers and subscriber numbers, so you can make better decisions about which podcasts to sponsor or be a guest on. You will need to upgrade your account to access this premium data.

What are the audience demographics for What's in the SOSS? An OpenSSF Podcast?

Rephonic provides comprehensive predictive audience data for What's in the SOSS? An OpenSSF Podcast, including gender skew, age, country, political leaning, income, professions, education level, and interests. You can access these listener demographics by upgrading your account.

How many subscribers and views does What's in the SOSS? An OpenSSF Podcast have?

To see how many followers or subscribers What's in the SOSS? An OpenSSF Podcast has on Spotify and other platforms such as Castbox and Podcast Addict, simply upgrade your account. You'll also find viewership figures for their YouTube channel if they have one.

Which podcasts are similar to What's in the SOSS? An OpenSSF Podcast?

These podcasts share a similar audience with What's in the SOSS? An OpenSSF Podcast:

1. Hard Fork

How many episodes of What's in the SOSS? An OpenSSF Podcast are there?

What's in the SOSS? An OpenSSF Podcast launched 2 years ago and published 57 episodes to date. You can find more information about this podcast including rankings, audience demographics and engagement in our podcast database.

How do I contact What's in the SOSS? An OpenSSF Podcast?

Our systems regularly scour the web to find email addresses and social media links for this podcast. We scanned the web and collated all of the contact information that we could find in our podcast database. But in the unlikely event that you can't find what you're looking for, our concierge service lets you request our research team to source better contacts for you.

Where can I see ratings and reviews for What's in the SOSS? An OpenSSF Podcast?

Rephonic pulls ratings and reviews for What's in the SOSS? An OpenSSF Podcast from multiple sources, including Spotify, Apple Podcasts, Castbox, and Podcast Addict.

View all the reviews in one place instead of visiting each platform individually and use this information to decide if a show is worth pitching or not.

How do I access podcast episode transcripts for What's in the SOSS? An OpenSSF Podcast?

Rephonic provides full transcripts for episodes of What's in the SOSS? An OpenSSF Podcast. Search within each transcript for your keywords, whether they be topics, brands or people, and figure out if it's worth pitching as a guest or sponsor. You can even set-up alerts to get notified when your keywords are mentioned.

What guests have appeared on What's in the SOSS? An OpenSSF Podcast?

Recent guests on What's in the SOSS? An OpenSSF Podcast include:

1. Justin Cappos
2. Eddie Knight
3. Ben Cotton
4. David A. Wheeler
5. John Amaral
6. Amir Montezari
7. Derek Zimmer
8. Tabatha DiDomenico

To view more recent guests and their details, simply upgrade your Rephonic account. You'll also get access to a typical guest profile to help you decide if the show is worth pitching.

Find and pitch the right podcasts

We help savvy brands, marketers and PR professionals to find the right podcasts for any topic or niche. Get the data and contacts you need to pitch podcasts at scale and turn listeners into customers.
Try it free for 7 days