# It’s Not Open Source, It’s You. Where Open Source Risk Comes From w/ Sonatype | Dev Interrupted Powered by LinearB

> Brian Fox and Stephen Magill of Sonatype join us to discuss software supply chain security and open source risk management.

[Podcast](https://linearb.io/dev-interrupted/podcasts)

/

It’s Not Open Source, It’s You. Where Open Source Risk Comes From w/ Sonatype

# It’s Not Open Source, It’s You. Where Open Source Risk Comes From w/ Sonatype

By Brian Fox and Stephen Magill

|

December 13, 2022

![DOES_Sonatype_Podcast_Card_6e7e05dc76](https://assets.linearb.io/image/upload/c_limit,w_2560/f_auto/q_auto/v1/DOES_Sonatype_Podcast_Card_6e7e05dc76?_a=BAVMn6ID0)

Picture this: an auto manufacturer with no clue what parts are in its supply chain, where those parts come from and no ability to recall those parts if vulnerabilities are discovered.

That’s not a reality consumers would accept. So why do organizations (and manufacturers!) tolerate it when it comes to software? 

On this week’s episode of Dev Interrupted, Brian Fox, co-founder & CTO, and Stephen Magill, VP of Product Innovation, join us to talk about [Sonatype’s State of the Software Supply Chain Report](https://www.sonatype.com/state-of-the-software-supply-chain/introduction?utm%5Fterm=software%20supply%20chain&utm%5Fcampaign=NA+%7C+SSC+Report+%7C+Search&utm%5Fsource=google&utm%5Fmedium=cpc&hsa%5Ftgt=kwd-106357829&hsa%5Fgrp=142167159253&hsa%5Fsrc=g&hsa%5Fnet=adwords&hsa%5Fmt=p&hsa%5Fver=3&hsa%5Fad=628122468173&hsa%5Facc=2665806879&hsa%5Fkw=software%20supply%20chain&hsa%5Fcam=14683965568&gclid=CjwKCAiAv9ucBhBXEiwA6N8nYM2lvglnUbzVJtXAijjg2P8PrmsxlrzubItWZEig-kQKKHp04dDCWxoCMAwQAvD%5FBwE). 

Listen as Brian and Stephen explain the ins and outs of open source risk management, how companies that aren’t open source maintainers can do a better job protecting themselves and why cybercrime is like “VC funds for the bad guys.” 

### Episode Highlights:

* (1:48) Brian's and Stephen's background
* (5:21) [State of the Software Supply Chain Report](https://www.sonatype.com/state-of-the-software-supply-chain/introduction?utm%5Fterm=software%20supply%20chain&utm%5Fcampaign=NA+%7C+SSC+Report+%7C+Search&utm%5Fsource=google&utm%5Fmedium=cpc&hsa%5Ftgt=kwd-106357829&hsa%5Fgrp=142167159253&hsa%5Fsrc=g&hsa%5Fnet=adwords&hsa%5Fmt=p&hsa%5Fver=3&hsa%5Fad=628122468173&hsa%5Facc=2665806879&hsa%5Fkw=software%20supply%20chain&hsa%5Fcam=14683965568&gclid=CjwKCAiAv9ucBhBXEiwA6N8nYM2lvglnUbzVJtXAijjg2P8PrmsxlrzubItWZEig-kQKKHp04dDCWxoCMAwQAvD%5FBwE)
* (9:53) 4 practices of secure teams
* (12:43) What eng leaders need to know about their software supply chain
* (22:20) Cybercrime is like "VC funds invested into the bad guys"
* (28:38) Security issues gap between management and ICs

###### **Want to cut code-review time by up to 40%? Add estimated review time to pull requests automatically!**

gitStream is the free dev tool from LinearB that eliminates the No. 1 bottleneck in your team’s workflow: pull requests and code reviews. After reviewing the work of 2,000 dev teams, LinearB’s engineers and data scientists found that pickup times and code review were lasting 4 to 5 days longer than they should be. 

The good news is that they found these delays could be eliminated largely by adding estimated review time to pull requests!

Learn more about how gitStream is making coding better [HERE](https://linearb.io/dev/gitstream/?utm%5Fsource=Dev%20Interrupted&utm%5Fmedium=referral[…]gitStream%20-%20Referral%20-%20Dev%20Interrupted%20Show%20Notes).

[![Setup gitStream on your GitHub repo today](https://assets.linearb.io/uploads/gitstream-beta-cta-centered-2-1024x538.png)](https://linearb.io/dev/gitstream/?utm%5Fsource=Dev%20Interrupted&utm%5Fmedium=referral[…]gitStream%20-%20Referral%20-%20Dev%20Interrupted%20Show%20Notes)

## Real conversations with top engineering leaders

Find us on

[](https://www.linkedin.com/showcase/dev-interrupted/)
[](https://devinterrupted.substack.com/)

## Your next listen

[![Cover image for Rebuilding CLIs for agents, it’s time to get MCP-certified, and why human code review will never catch up](https://assets.linearb.io/image/upload/c_limit,w_2560/f_auto/q_auto/v1/agentic_cli_tools_mcp_certification_code_review_23be877e85?_a=BAVMn6ID0)](https://linearb.io/dev-interrupted/podcast/linux-foundation-mcp-certification-agentic-loops-pull-request-bottleneck)

Dev Interrupted

[Rebuilding CLIs for agents, it’s time to get MCP-certified, and why human code review will never catch up](https://linearb.io/dev-interrupted/podcast/linux-foundation-mcp-certification-agentic-loops-pull-request-bottleneck)

This week on the Friday Deploy, Ben and Andrew break down the Linux Foundation's new MCP certification and the fundamental mechanics of agentic loops. Discover...

[![Cover image for How to see in the dark factory | LaunchDarkly's Cameron Etezadi](https://assets.linearb.io/image/upload/c_limit,w_2560/f_auto/q_auto/v1/Blog_Comprehensive_DORA_Guide_2400x1256_66_6f6a37357d?_a=BAVMn6ID0)](https://linearb.io/dev-interrupted/podcast/launchdarkly-cameron-etezadi-dark-factory-agent-runtime-frameworks)

Dev Interrupted

[How to see in the dark factory | LaunchDarkly's Cameron Etezadi](https://linearb.io/dev-interrupted/podcast/launchdarkly-cameron-etezadi-dark-factory-agent-runtime-frameworks)

LaunchDarkly CTO Cameron Etezadi joins the show to discuss why the traditional "two-pizza" engineering team is dead. Discover how runtime agent frameworks and...

[![Cover image for How to cultivate expertise with local models, delegating to subagents, and we all really stopped reading, huh?](https://assets.linearb.io/image/upload/c_limit,w_2560/f_auto/q_auto/v1/local_ai_expertise_subagents_delegation_strategies_616640e057?_a=BAVMn6ID0)](https://linearb.io/dev-interrupted/podcast/open-source-glm-models-local-ai-coding-protecting-first-brain)

Dev Interrupted

[How to cultivate expertise with local models, delegating to subagents, and we all really stopped reading, huh?](https://linearb.io/dev-interrupted/podcast/open-source-glm-models-local-ai-coding-protecting-first-brain)

This week on the Friday Deploy, Ben and Andrew break down the rise of highly capable open-source models like GLM 5.2 and the reality of running local AI for...