
0:00
35:48
Josh chats with Brian Fox from Sonatype about their 2026 State of the Software Supply Chain report. Most of the number continue to grow at alarming rates, but there's some new interesting findings in this one. We discuss end of life and open source which is tough to define. We touch on what using AI with open source dependencies looks like (and why it's broken), and we discuss the challenge of upgrading your open source dependencies in a way that doesn't break everything. It's a great report and great discussion.
The show notes and blog post for this episode can be found at
https://opensourcesecurity.io/2026/2026-03-SOTSSC-Brian-Fox/
Altri episodi di "Open Source Security"



Non perdere nemmeno un episodio di “Open Source Security”. Iscriviti all'app gratuita GetPodcast.








