OpenSSF’s What’s in the SOSS? podcast talks with Red Hat vice president of product security Vincent Danen about the changing state of open source vulnerability disclosure, covering the CVE program’s history, the rise of alternative advisory systems, the flood of AI-assisted vulnerability reports and the burden it puts on upstream maintainers, why SBOMs and VEX still lack a usable experience for downstream consumers, and how the EU Cyber Resilience Act is shifting global software supply-chain expectations.
What’s in the SOSS? Podcast #75 – S3E27 From Upstream to Downstream: Managing Open Source Risk in a Changing Regulatory Era with Vincent Danen
OpenSSF's What's in the SOSS? podcast talks with Red Hat vice president of product security Vincent Danen about the changing state of open source vulnerability disclosure, covering the CVE program's history, the rise of alternative advisory systems, the flood of AI-assisted vulnerability reports and the burden it puts on upstream maintainers, why SBOMs and VEX still lack a usable experience for downstream consumers, and how the EU Cyber Resilience Act is shifting global software supply-chain expectations.
Source: OpenSSF