In this episode of What’s in the SOSS?, host CRob welcomes back open source security champion Michael Winser to reflect on Alpha-Omega’s spectacular milestone of surpassing $20 million in security grants. Michael breaks down how their mission has evolved from simply chasing bugs to acting as a catalyst for sustainable, long-term security culture across critical projects. The two dive deep into the unsustainable economics of package repositories—the "app stores" of software development —and address how a massive partnership with frontier AI model providers is aiming to flip the script on AI. Instead of fueling endless, low-context vulnerability "slop," Alpha-Omega is working to put AI assists directly into the hands of maintainers as their ultimate defensive power tool.
Chapters:
- 00:24 - Welcome Back, Michael Winser!
- 01:10 - The Origin Story of a $20 Million Milestone
- 04:54 - Evolving Beyond Audits to "Sustainable Security"
- 11:18 - The Messy Economics of Package Registries
- 20:28 - Turning AI into the Maintainer’s Power Tool
- 29:01 - Vision for 2026: The Security Trust Graph
Episode links:
- Michael Winser’s LinkedIn page
- Alpha-Omega Website
- Alpha-Omega Public Repository
- Learn more about the Security Engineers in Residence (SEIR) Roles
- Andrew Nesbitt
- OpenSSF Securing Software Repositories Working Group
- Get involved with the OpenSSF
- Subscribe to the OpenSSF newsletter
- Follow the OpenSSF on LinkedIn
Fler avsnitt av What's in the SOSS? An OpenSSF Podcast
Visa alla avsnitt av What's in the SOSS? An OpenSSF PodcastWhat's in the SOSS? An OpenSSF Podcast med OpenSSF finns tillgänglig på flera plattformar. Informationen på denna sida kommer från offentliga podd-flöden.
