Securing the open source supply chain (Changelog Interviews #482)

Published: March 1, 2022, 10 p.m.

b'This week we\\u2019re joined by the \\u201cmad scientist\\u201d himself, Feross Aboukhadijeh\\u2026and we\\u2019re talking about the launch of Socket \\u2014 the next big thing in the fight to secure and protect the open source supply chain. While working on the frontlines of open source, Feross and team have witnessed firsthand how supply chain attacks have swept across the software community and have damaged the trust in open source. Socket turns the problem of securing open source software on its head, and asks\\u2026\\u201cWhat if we assume all open source may be malicious?\\u201d So, they built a system that proactively detects indicators of compromised open source packages and brings awareness to teams in real-time. We cover the whys, the hows, and what\\u2019s next for this ambitious and very much needed project.'