Picture this: an auto manufacturer with no clue what parts are in its supply chain, where those parts come from and no ability to recall those parts if vulnerabilities are discovered.

That’s not a reality consumers would accept. So why do organizations (and manufacturers!) tolerate it when it comes to software?

On this week’s episode of Dev Interrupted, Brian Fox, co-founder & CTO, and Stephen Magill, VP of Product Innovation, join us to talk about Sonatype’s State of the Software Supply Chain Report.

Listen as Brian and Stephen explain the ins and outs of open source risk management, how companies that aren’t open source maintainers can do a better job protecting themselves and why cybercrime is like “VC funds for the bad guys.”

Show Notes8th Annual State of the Software Supply Chain Report

  • Learn how to increase your dev team's efficiency by up to 30% at our free Scaling Developer Efficiency workshop on February, 15th. Register: linearb.io/efficiency

Support the show:

  • Subscribe to our Substack
  • Follow us on YouTube
  • Review us on Apple Podcasts or Spotify
  • Follow us on Twitter or LinkedIn

Offers:

  • Learn about Continuous Merge with gitStream
  • Want to try LinearB? Book a Demo& use discount code "Dev Interrupted Podcast" ...