Home / Companies / Socket / Blog / Post Details
Content Deep Dive

Software Engineering Daily Podcast: Feross on AI, Open Source, and Supply Chain Risk

Blog post from Socket

Post Details
Company
Date Published
Author
Sarah Gooding
Word Count
10,160
Company Posts That Month
20
Language
English
Hacker News Points
-
Post removed?
No
Summary

Feross Aboukhadijeh, founder and CEO of Socket, discusses with Josh Goldberg on Software Engineering Daily the critical issue of open-source supply chain attacks in the software industry and how Socket aims to mitigate these risks. Feross shares insights from his journey through building popular open-source projects and the challenges of maintaining them, emphasizing the necessity of treating open-source dependencies as integral parts of one's codebase. He highlights the importance of practical security habits, such as utilizing lock files and vetting new dependencies, to prevent malicious code from infiltrating systems. The conversation also explores the emerging threats posed by AI-driven risks, where attackers exploit hallucinated package names generated by language models. Feross underscores the need for vigilance and proactive measures, like those offered by Socket, to protect against the evolving landscape of software vulnerabilities while reflecting on his personal experiences with open source, including the burnout associated with maintaining popular projects.

Trends Found in this Post
Trend Post Mentions Total Month Mentions Posts Companies MoM
LLM 9 3,775 638 202 -32%
MCP 3 4,899 392 145 +47%
Developer Experience 1 454 241 96 -6%
Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.