Go offline with the Player FM app!
Bridging DevOps and Security: Tracy Reagan on the Future of Open Source
Manage episode 489258056 series 3564832
In this episode of What's in the SOSS, we sit down with longtime open source leader and DevOps champion Tracy Ragan. From her early days with the Eclipse Foundation to her current work with Ortelius, the Continuous Delivery Foundation, and the OpenSSF, Tracy shares her journey through the ever-evolving world of open source security.
We dig into the importance of configuration management, what DevSecOps really means, and how projects like the OpenSSF Scorecard and Ortelius help make our software supply chains more transparent and secure. Plus, we tackle the education gap between security pros and DevOps engineers—and how we can bridge it.
If you're curious about building more secure pipelines or just want to geek out about SBOMs and Scorecard, this episode is for you.
Chapters:
00:25 – Welcome + Tracy's Open Source Origin Story
02:00 – Early Days at the Eclipse Foundation
03:10 – DevOps + DevSecOps: Why It Matters
04:20 – Explaining the DevOps “Factory Floor”
06:00 – DevOps Pipelines as Security Data Engines
07:50 – What Is the OpenSSF Scorecard?
09:30 – Ortelius: Aggregating DevOps + Security Insights
11:20 – The DevOps Budget Problem + Exposing Insecure Packages
13:00 – Why DevRel Is Critical for DevOps Security Education
15:40 – Crossing the Divide Between DevOps and Security Teams
16:10 – 🎉 Rapid Fire: Editors, Mascots & Spicy Food
17:30 – Final Call to Action + How to Get Involved
Episode links:
Chapters
1. Bridging DevOps and Security: Tracy Reagan on the Future of Open Source (00:00:00)
2. Welcome + Tracy's Open Source Origina Story (00:00:25)
3. Early Days at the Eclipse Foundation (00:02:00)
4. DevOps + DevSecOps: Why it Matters (00:03:10)
5. Explaining the DevOps "Factory Floor" (00:04:20)
6. DevOps Pipelines as Security Data Engines (00:06:00)
7. What Is the OpenSSF Scorecard? (00:07:50)
8. Ortelius: Aggregating DevOps + Security Insights (00:09:30)
9. The DevOps Budget Problem + Exposing Insecure Packages (00:11:20)
10. Why DevRel Is Critical for DevOps Security Education (00:13:00)
11. Crossing the Divide Between DevOps and Security Teams (00:15:40)
12. Rapid Fire: Editors, Mascots & Spicy Food (00:16:10)
13. Final Call to Action + How to Get Involved (00:17:30)
34 episodes
Manage episode 489258056 series 3564832
In this episode of What's in the SOSS, we sit down with longtime open source leader and DevOps champion Tracy Ragan. From her early days with the Eclipse Foundation to her current work with Ortelius, the Continuous Delivery Foundation, and the OpenSSF, Tracy shares her journey through the ever-evolving world of open source security.
We dig into the importance of configuration management, what DevSecOps really means, and how projects like the OpenSSF Scorecard and Ortelius help make our software supply chains more transparent and secure. Plus, we tackle the education gap between security pros and DevOps engineers—and how we can bridge it.
If you're curious about building more secure pipelines or just want to geek out about SBOMs and Scorecard, this episode is for you.
Chapters:
00:25 – Welcome + Tracy's Open Source Origin Story
02:00 – Early Days at the Eclipse Foundation
03:10 – DevOps + DevSecOps: Why It Matters
04:20 – Explaining the DevOps “Factory Floor”
06:00 – DevOps Pipelines as Security Data Engines
07:50 – What Is the OpenSSF Scorecard?
09:30 – Ortelius: Aggregating DevOps + Security Insights
11:20 – The DevOps Budget Problem + Exposing Insecure Packages
13:00 – Why DevRel Is Critical for DevOps Security Education
15:40 – Crossing the Divide Between DevOps and Security Teams
16:10 – 🎉 Rapid Fire: Editors, Mascots & Spicy Food
17:30 – Final Call to Action + How to Get Involved
Episode links:
Chapters
1. Bridging DevOps and Security: Tracy Reagan on the Future of Open Source (00:00:00)
2. Welcome + Tracy's Open Source Origina Story (00:00:25)
3. Early Days at the Eclipse Foundation (00:02:00)
4. DevOps + DevSecOps: Why it Matters (00:03:10)
5. Explaining the DevOps "Factory Floor" (00:04:20)
6. DevOps Pipelines as Security Data Engines (00:06:00)
7. What Is the OpenSSF Scorecard? (00:07:50)
8. Ortelius: Aggregating DevOps + Security Insights (00:09:30)
9. The DevOps Budget Problem + Exposing Insecure Packages (00:11:20)
10. Why DevRel Is Critical for DevOps Security Education (00:13:00)
11. Crossing the Divide Between DevOps and Security Teams (00:15:40)
12. Rapid Fire: Editors, Mascots & Spicy Food (00:16:10)
13. Final Call to Action + How to Get Involved (00:17:30)
34 episodes
All episodes
×Welcome to Player FM!
Player FM is scanning the web for high-quality podcasts for you to enjoy right now. It's the best podcast app and works on Android, iPhone, and the web. Signup to sync subscriptions across devices.