Artwork

Content provided by Omkhar Arasaratnam, OpenSSF and Omkhar Arasaratnam. All podcast content including episodes, graphics, and podcast descriptions are uploaded and provided directly by Omkhar Arasaratnam, OpenSSF and Omkhar Arasaratnam or their podcast platform partner. If you believe someone is using your copyrighted work without your permission, you can follow the process outlined here https://player.fm/legal.
Player FM - Podcast App
Go offline with the Player FM app!

Google’s Andrew Pollock and Addressing Open Source Vulnerabilities

12:16
 
Share
 

Manage episode 433932135 series 3564832
Content provided by Omkhar Arasaratnam, OpenSSF and Omkhar Arasaratnam. All podcast content including episodes, graphics, and podcast descriptions are uploaded and provided directly by Omkhar Arasaratnam, OpenSSF and Omkhar Arasaratnam or their podcast platform partner. If you believe someone is using your copyrighted work without your permission, you can follow the process outlined here https://player.fm/legal.

Episode description: Andrew Pollock is a Senior Software Engineer at Google, currently working on https://osv.dev. With a background as an Enterprise Security Engineer, he has extensive experience in large-scale Linux Systems Administration and GCP Security. Andrew is passionate about the human factors in security, focusing on scalable solutions, great user experiences and self-service opportunities. He has primarily worked in Linux/Unix environments as a Site Reliability Engineer or Security Engineer, with a strong interest in process improvement and automation.

  • 00:52 - Andrew shares his background as a “mid-90s data nerd”
  • 02:31 - Managing vulnerabilities in the open source ecosystem
  • 03:57 - How to navigate inconsistent metadata
  • 06:26 - The challenge of source attribution
  • 07:54 - The rapid-fire round
  • 09:15 - Andrew’s advice to open source developers
  • 10:22 - Andrew’s call to action to developers

Episode links:

  continue reading

12 episodes

Artwork
iconShare
 
Manage episode 433932135 series 3564832
Content provided by Omkhar Arasaratnam, OpenSSF and Omkhar Arasaratnam. All podcast content including episodes, graphics, and podcast descriptions are uploaded and provided directly by Omkhar Arasaratnam, OpenSSF and Omkhar Arasaratnam or their podcast platform partner. If you believe someone is using your copyrighted work without your permission, you can follow the process outlined here https://player.fm/legal.

Episode description: Andrew Pollock is a Senior Software Engineer at Google, currently working on https://osv.dev. With a background as an Enterprise Security Engineer, he has extensive experience in large-scale Linux Systems Administration and GCP Security. Andrew is passionate about the human factors in security, focusing on scalable solutions, great user experiences and self-service opportunities. He has primarily worked in Linux/Unix environments as a Site Reliability Engineer or Security Engineer, with a strong interest in process improvement and automation.

  • 00:52 - Andrew shares his background as a “mid-90s data nerd”
  • 02:31 - Managing vulnerabilities in the open source ecosystem
  • 03:57 - How to navigate inconsistent metadata
  • 06:26 - The challenge of source attribution
  • 07:54 - The rapid-fire round
  • 09:15 - Andrew’s advice to open source developers
  • 10:22 - Andrew’s call to action to developers

Episode links:

  continue reading

12 episodes

All episodes

×
 
Loading …

Welcome to Player FM!

Player FM is scanning the web for high-quality podcasts for you to enjoy right now. It's the best podcast app and works on Android, iPhone, and the web. Signup to sync subscriptions across devices.

 

Quick Reference Guide