Artwork

Content provided by OpenSSF. All podcast content including episodes, graphics, and podcast descriptions are uploaded and provided directly by OpenSSF or their podcast platform partner. If you believe someone is using your copyrighted work without your permission, you can follow the process outlined here https://ppacc.player.fm/legal.
Player FM - Podcast App
Go offline with the Player FM app!

Bridging DevOps and Security: Tracy Reagan on the Future of Open Source

20:04
 
Share
 

Manage episode 489258056 series 3564832
Content provided by OpenSSF. All podcast content including episodes, graphics, and podcast descriptions are uploaded and provided directly by OpenSSF or their podcast platform partner. If you believe someone is using your copyrighted work without your permission, you can follow the process outlined here https://ppacc.player.fm/legal.

In this episode of What's in the SOSS, we sit down with longtime open source leader and DevOps champion Tracy Ragan. From her early days with the Eclipse Foundation to her current work with Ortelius, the Continuous Delivery Foundation, and the OpenSSF, Tracy shares her journey through the ever-evolving world of open source security.

We dig into the importance of configuration management, what DevSecOps really means, and how projects like the OpenSSF Scorecard and Ortelius help make our software supply chains more transparent and secure. Plus, we tackle the education gap between security pros and DevOps engineers—and how we can bridge it.

If you're curious about building more secure pipelines or just want to geek out about SBOMs and Scorecard, this episode is for you.

Chapters:
00:25 – Welcome + Tracy's Open Source Origin Story
02:00 – Early Days at the Eclipse Foundation
03:10 – DevOps + DevSecOps: Why It Matters
04:20 – Explaining the DevOps “Factory Floor”
06:00 – DevOps Pipelines as Security Data Engines
07:50 – What Is the OpenSSF Scorecard?
09:30 – Ortelius: Aggregating DevOps + Security Insights
11:20 – The DevOps Budget Problem + Exposing Insecure Packages
13:00 – Why DevRel Is Critical for DevOps Security Education
15:40 – Crossing the Divide Between DevOps and Security Teams
16:10 – 🎉 Rapid Fire: Editors, Mascots & Spicy Food
17:30 – Final Call to Action + How to Get Involved

Episode links:

  continue reading

Chapters

1. Bridging DevOps and Security: Tracy Reagan on the Future of Open Source (00:00:00)

2. Welcome + Tracy's Open Source Origina Story (00:00:25)

3. Early Days at the Eclipse Foundation (00:02:00)

4. DevOps + DevSecOps: Why it Matters (00:03:10)

5. Explaining the DevOps "Factory Floor" (00:04:20)

6. DevOps Pipelines as Security Data Engines (00:06:00)

7. What Is the OpenSSF Scorecard? (00:07:50)

8. Ortelius: Aggregating DevOps + Security Insights (00:09:30)

9. The DevOps Budget Problem + Exposing Insecure Packages (00:11:20)

10. Why DevRel Is Critical for DevOps Security Education (00:13:00)

11. Crossing the Divide Between DevOps and Security Teams (00:15:40)

12. Rapid Fire: Editors, Mascots & Spicy Food (00:16:10)

13. Final Call to Action + How to Get Involved (00:17:30)

34 episodes

Artwork
iconShare
 
Manage episode 489258056 series 3564832
Content provided by OpenSSF. All podcast content including episodes, graphics, and podcast descriptions are uploaded and provided directly by OpenSSF or their podcast platform partner. If you believe someone is using your copyrighted work without your permission, you can follow the process outlined here https://ppacc.player.fm/legal.

In this episode of What's in the SOSS, we sit down with longtime open source leader and DevOps champion Tracy Ragan. From her early days with the Eclipse Foundation to her current work with Ortelius, the Continuous Delivery Foundation, and the OpenSSF, Tracy shares her journey through the ever-evolving world of open source security.

We dig into the importance of configuration management, what DevSecOps really means, and how projects like the OpenSSF Scorecard and Ortelius help make our software supply chains more transparent and secure. Plus, we tackle the education gap between security pros and DevOps engineers—and how we can bridge it.

If you're curious about building more secure pipelines or just want to geek out about SBOMs and Scorecard, this episode is for you.

Chapters:
00:25 – Welcome + Tracy's Open Source Origin Story
02:00 – Early Days at the Eclipse Foundation
03:10 – DevOps + DevSecOps: Why It Matters
04:20 – Explaining the DevOps “Factory Floor”
06:00 – DevOps Pipelines as Security Data Engines
07:50 – What Is the OpenSSF Scorecard?
09:30 – Ortelius: Aggregating DevOps + Security Insights
11:20 – The DevOps Budget Problem + Exposing Insecure Packages
13:00 – Why DevRel Is Critical for DevOps Security Education
15:40 – Crossing the Divide Between DevOps and Security Teams
16:10 – 🎉 Rapid Fire: Editors, Mascots & Spicy Food
17:30 – Final Call to Action + How to Get Involved

Episode links:

  continue reading

Chapters

1. Bridging DevOps and Security: Tracy Reagan on the Future of Open Source (00:00:00)

2. Welcome + Tracy's Open Source Origina Story (00:00:25)

3. Early Days at the Eclipse Foundation (00:02:00)

4. DevOps + DevSecOps: Why it Matters (00:03:10)

5. Explaining the DevOps "Factory Floor" (00:04:20)

6. DevOps Pipelines as Security Data Engines (00:06:00)

7. What Is the OpenSSF Scorecard? (00:07:50)

8. Ortelius: Aggregating DevOps + Security Insights (00:09:30)

9. The DevOps Budget Problem + Exposing Insecure Packages (00:11:20)

10. Why DevRel Is Critical for DevOps Security Education (00:13:00)

11. Crossing the Divide Between DevOps and Security Teams (00:15:40)

12. Rapid Fire: Editors, Mascots & Spicy Food (00:16:10)

13. Final Call to Action + How to Get Involved (00:17:30)

34 episodes

All episodes

×
 
Loading …

Welcome to Player FM!

Player FM is scanning the web for high-quality podcasts for you to enjoy right now. It's the best podcast app and works on Android, iPhone, and the web. Signup to sync subscriptions across devices.

 

Quick Reference Guide

Copyright 2025 | Privacy Policy | Terms of Service | | Copyright
Listen to this show while you explore
Play