
Insights from recent episode analysis
Audience Interest
Podcast Focus
Publishing Consistency
Platform Reach
Insights are generated by CastFox AI using publicly available data, episode content, and proprietary models.
Most discussed topics
Brands & references
Total monthly reach
Estimated from 4 chart positions in 4 markets.
By chart position
- 🇯🇵JP · Technology#1761K to 10K
- 🇮🇱IL · Technology#4510K to 30K
- 🇵🇹PT · Technology#133500 to 3K
- 🇫🇮FI · Technology#190500 to 3K
- Per-Episode Audience
Est. listeners per new episode within ~30 days
3.6K to 14K🎙 Daily cadence·525 episodes·Last published 3d ago - Monthly Reach
Unique listeners across all episodes (30 days)
12K to 46K🇮🇱65%🇯🇵22%🇵🇹7%+1 more - Active Followers
Loyal subscribers who consistently listen
3.6K to 14K
Market Insights
Platform Distribution
Reach across major podcast platforms, updated hourly
Total Followers
—
Total Plays
—
Total Reviews
—
* Data sourced directly from platform APIs and aggregated hourly across all major podcast directories.
On the show
From 10 epsHost
Recent guests
Recent episodes
Sovereign Tech Agency with Erik Möller
Aug 31, 2026
Unknown duration
CVEs vs Advisories with Paul Asadoorian
Aug 24, 2026
Unknown duration
Maintaining EOL Open Source with Commonhaus and HeroDevs
Aug 17, 2026
Unknown duration
Cleanup, Speedup, Levelup open source at e18e
Aug 10, 2026
Unknown duration
VulnCheck's State of Exploitation Report with Patrick Garrity
Aug 3, 2026
Unknown duration
Social Links & Contact
Official channels & resources
Official Website
Login
RSS Feed
Login
| Date | Episode | Topics | Guests | Brands | Places | Keywords | Sponsor | Length | |
|---|---|---|---|---|---|---|---|---|---|
| 8/31/26 | Sovereign Tech Agency with Erik Möller | Josh chats with Erik Möller from the Sovereign Tech Agency about what they're doing. The Sovereign Tech Agency is doing some amazing work around funding open source maintainers and projects. Eric breaks down what they're doing, how it works, and how you can apply for funding. We even learn about some similar projects happening in the EU. Hopefully in the near future we will see the work Sovereign Tech Agency is doing happening in every country. The show notes and blog post for this episode can be found at https://opensourcesecurity.io/2026/2026-08-erik-sta | — | ||||||
| 8/24/26 | CVEs vs Advisories with Paul Asadoorian | Josh chats with Paul Asadoorian about a tool he wrote called fettle and a recent report Paul published on CVEs. Fettle is a tool to help update and manage Linux systems. The big sell on this one is checking if your firmware is out of date. We then talk about a report Paul created that doesn't obsess over CVEs, but rather the vendor updates. It makes more sense to worry about advisories as those are actionable, where CVEs often are not. It's a great chat and Paul is a legend in the industry. The show notes and blog post for this episode can be found at https://opensourcesecurity.io/2026/2026-08-paul-fettle-cve | — | ||||||
| 8/17/26 | Maintaining EOL Open Source with Commonhaus and HeroDevs | Josh chats with Erin Schnabel and Rob Nalen about a new effort from Commonhaus and HeroDevs for maintaining end of life open source. This project, the Open Source Sustainability Initiative is a clever way to bring corporations and projects together for maintenance of new and old versions of open source projects. This is pretty new territory for everyone, this project is worth keeping an eye on because it has a very small scope initially. Other similar ideas have gigantic scopes that are almost certainly too large. The show notes and blog post for this episode can be found at https://opensourcesecurity.io/2026/2026-08-commonhaus-herodevs | — | ||||||
| 8/10/26 | Cleanup, Speedup, Levelup open source at e18e | Josh chats with James from e18e. This is a project that is working on improving Javascript packages by cleaning up, speeding up, and leveling up the dependencies. The way the e18e project handles this work is very human open source. It's all about building up connections and trust with the package communities, which is no small effort. James fills us in on what they're doing as well as how we can get involved. It's a truly amazing effort The show notes and blog post for this episode can be found at https://opensourcesecurity.io/2026/2026-08-e18e-james | — | ||||||
| 8/3/26 | VulnCheck's State of Exploitation Report with Patrick Garrity | Josh chats with Patrick Garrity about the VulnCheck State of Exploitation 1H-2026 report. Patrick explains the current trends we are seeing around vulnerabilities right now. While the number of CVEs is way up, the number of actually exploited vulnerabilities isn't growing year over year. This tells us there is a lot of FUD and hype. We also ask where are all the vulnerabilities that project Glasswing found. They should be going public by now, but we're not seeing that play out in the data. The show notes and blog post for this episode can be found at https://opensourcesecurity.io/2026/2026-08-vulncheck-state-of-exploitation | — | ||||||
| 7/27/26 | Securing critical infrastructure with Josh Corman | Open Source Security welcomes Josh Corman to talk about the challenges around securing our critical infrastructure. Specifically the discussion centers around our water supplies. There are a lot of really wild things happening right now with attacks like Volt Typhoon and Salt Typhoon. Josh has an amazing ability to make these sort of discussions easy to understand without spreading FUD. Josh also has suggestions for actions that need to be taken to help deal with these problems. It's not all technical solutions, there are non technical things we can do to help reduce the risk posed by our technical systems failing. The show notes and blog post for this episode can be found at https://opensourcesecurity.io/2026/2026-07-critical-infrastructure-josh-corman | — | ||||||
| 7/20/26 | open sourceabandoned packages+3 | Josh Marpet | Value Chain Risk Institute | — | open sourceabandoned packages+3 | — | 34m 16s | ||
| 7/13/26 | open sourcevulnerability management+4 | Mo Duffy | Project LightwellRed Hat | — | open sourcevulnerability reports+4 | — | 32m 32s | ||
| 7/6/26 | Rust Foundationopen source funding+3 | Lori LorussoNiko Matsakis | Rust Foundation | — | Rust Foundationmaintainers fund+3 | — | 32m 46s | ||
| 6/29/26 | Bill of MaterialsSBOM+3 | Allan Friedman | SBOMOmniBOM | — | Bill of MaterialsSBOM+3 | — | 34m 38s | ||
Want analysis for the episodes below?Free for Pro Submit a request, we'll have your selected episodes analyzed within an hour. Free, at no cost to you, for Pro users. | |||||||||
| 6/22/26 | security featuresPHP package registry+4 | Jordi Boggiano | ComposerPackagist+1 | — | securityComposer+4 | — | 34m 48s | ||
| 6/15/26 | Open SourceEclipse Foundation+3 | Mike MilinkovichThabang Mashologu | Eclipse FoundationOpen VSX | — | Open VSXEclipse Foundation+3 | — | 36m 53s | ||
| 6/8/26 | CI/CDsecurity+3 | François Proulx | SmokedMeatBoost Security | — | CI/CDsecurity+5 | — | 35m 37s | ||
| 6/1/26 | open sourcesecurity+4 | Sal Kimmich | Open Source Security | — | open sourcesecurity bugs+4 | — | 31m 54s | ||
| 5/25/26 | vulnerability disclosuresecurity+3 | Casey Ellis | Bugcrowddisclose.io | — | vulnerabilitydisclosure+5 | — | 37m 49s | ||
| 5/18/26 | open app repositoriesF-Droid+4 | Hans-Christoph Steiner | F-DroidAndroid+2 | — | F-Droidopen source+5 | — | 36m 47s | ||
| 5/11/26 | Open source is critical infrastructure with Kat Cosgrove | Josh talks to Kat Cosgrove about a how companies should be treating open source more like their critical infrastructure than free stuff. Kat has a ton of knowledge about how the interactions between companies and open source communities can work well, or not work at all. Kat's time on the Kubernetes Release Team. We touch on how a project like Kubernetes is super successful, while another, Ingress NGINX, was not. It's a super insightful discussion with a ton of lessons and advice for everyone. The show notes and blog post for this episode can be found at https://opensourcesecurity.io/2026/2026-05-open-source-infrastructure-kat/ | — | ||||||
| 5/4/26 | How to actually test a disaster plan with David Bernstein | Josh and David finish up the disaster recovery and emergency planning trilogy. In this one David tells us how to test the plan he told us how to build in the last episode. There are some great ideas in this one about how to test the process not the people. How to construct the plan, and even some tips to go from a plan to some actual real world testing. It's another episode filled with great and practical advice. The show notes and blog post for this episode can be found at https://opensourcesecurity.io/2026/2026-05-testing-the-plan-david-bernstein/ | — | ||||||
| 4/27/26 | Open Source Pledge with Vlad-Stefan Harbuz | Josh has a discussion with Vlad-Stefan Harbuz about the Open Source Pledge as well as his recent FOSDEM talk. The Open Source Pledge is all about trying to build a sustainable universe for open source maintainers. This ties into Vlad's FOSDEM talk which was all about the challenge of just knowing what open source you are using. The importance of trying to make open source sustainable is a really important topic, but it's also a really hard topic. Vlad helps explain all of this as well as some ideas for the solving this in the future. The show notes and blog post for this episode can be found at https://opensourcesecurity.io/2026/2026-04-open-source-pledge-vlad/ | — | ||||||
| 4/20/26 | Building a plan for disaster with David Bernstein | Josh welcomes back David Bernstein to talk about creating a disaster recover plan. It's a very timely topic given all the current events. There are more supply chain attacks and compromises than ever before. There are some great resources for this planning, but as David tells us, it's really not that hard to put some plans together. It's easy to over-plan, David gives some great tips on getting started with our planning for an eventual incident. The show notes and blog post for this episode can be found at https://opensourcesecurity.io/2026/2026-04-disaster-planning-david-bernstein/ | — | ||||||
| 4/13/26 | Open Source Malware with Paul McCarty | Josh talks to Paul McCarty of Open Source Malware about ... open source malware. Paul explains why there aren't many good open source malware datasets. We discuss why the existing data is lacking for many use cases. We of course touch on AI and the malware in skills problems and challenges. It's a fun discussion with a lot of new and interesting problems we all have to deal with. The show notes and blog post for this episode can be found at https://opensourcesecurity.io/2026/2026-04-open-source-malware-paul-mccarty/ | — | ||||||
| 4/6/26 | Package management challenges with Andrew Nesbitt | Josh welcomes back Andrew Nesbitt to discuss some recent blog posts he wrote about the challenges of new ecosystems as well as challenges of no ecosystems like C. There aren't very many people who look at multiple ecosystems in the way Andrew does. He has thoughts on why it's so hard to create a new ecosystem as well as some of the reasons we don't see a C language ecosystem. Andrew has a ton of interesting ideas and insight for us about both existing, new, and nonexistent ecosystems. The show notes and blog post for this episode can be found at https://opensourcesecurity.io/2026/2026-04-ecosystems-andrew/ | — | ||||||
| 3/30/26 | Open Source Security at scale with Michael Winser | Josh talks to Michael Winser about a talk he gave at FOSDEM as well as his work on Alpha Omega at the Linux Foundation. Michael is approaching open source security in a way that nobody has ever tried before. What if we could fund some really big, really hard projects? It's not cheap or easy, but he's getting it done. We spend a lot of the time discussing package registries, which are a huge topic. Michael is doing some amazing work helping package registries which is the first step in a very long journey. The show notes and blog post for this episode can be found at https://opensourcesecurity.io/2026/2026-03-michael-winser/ | — | ||||||
| 3/23/26 | 2026 State of the Software Supply Chain with Brian Fox | Josh chats with Brian Fox from Sonatype about their 2026 State of the Software Supply Chain report. Most of the number continue to grow at alarming rates, but there's some new interesting findings in this one. We discuss end of life and open source which is tough to define. We touch on what using AI with open source dependencies looks like (and why it's broken), and we discuss the challenge of upgrading your open source dependencies in a way that doesn't break everything. It's a great report and great discussion. The show notes and blog post for this episode can be found at https://opensourcesecurity.io/2026/2026-03-SOTSSC-Brian-Fox/ | — | ||||||
| 3/16/26 | MCP and Agent security with Luke Hinds | Josh talks to Luke Hinds, CEO of Always Further, about MCP and agent security. We start out talking about Luke's new tool, nono which is a sandboxing tool that has AI agents in mind as a use case. We explain what MCP and agents are doing as well as why it's so hard to secure them. It's not impossible, but it's not simple either. We end the show by discussing some of the more human aspects to security and how history may be repeating itself with security folks laughing at new users who don't know any better. The show notes and blog post for this episode can be found at https://opensourcesecurity.io/2026/2026-03-mcp-agent-luke/ | — | ||||||
Showing 25 of 544
Pitch Fit is a Pro feature
See how bookable this show is for guests, which brands already advertise, the per-episode ad value, and the best-fit guest and sponsor profile. The numbers are blurred on the free plan.
How readily this show books outside guests like you.
How proven this show is for host-read sponsorships.
For Guests
ProFor Advertisers
ProUpgrade to Pro to unlock guest cadence, sponsor categories, fit scores, and per-episode ad value for this show.
Chart history for Open Source Security
Peaked at #45 in IL, currently #45 in IL.
| Market | Genre | Peak | Current | Trend |
|---|---|---|---|---|
| IL | — | #45 | #45 | — |
| PT | — | #133 | #133 | — |
| Japan | — | #176 | #176 | — |
| Finland | — | #190 | #190 | — |
Chart Positions
4 placements across 4 markets.
Chart Positions
4 placements across 4 markets.