Communications Very Erratic (CVE): Stabilizing Vuln Data for the Industry (OSFF NY Preview)

Communications Very Erratic (CVE): Stabilizing Vuln Data for the Industry (OSFF NY Preview)

Author: FINOS October 5, 2025 Duration: 34:14

🚨 What happens when the backbone of vulnerability reporting wobbles? In April 2025, funding shocks to CVE/CWE—and the downstream NVD—sparked panic before a short-term lifeline appeared. The uncertainty hasn’t gone away.In this clip:Christopher “CRob” Robinson, CTO & Chief Security Architect, OpenSSF (The Linux Foundation)CRob previews his OSFF NY session on why reliable, authoritative vulnerability metadata is critical for banks, regulated enterprises, and open source maintainers—and what upstream is doing about it. He walks through the recent CVE/NVD turbulence, why downstream teams (risk, OSPOs, product owners) struggle to meet regulatory obligations without stable data, and how the open source community is collaborating to deliver consistent, high-quality vulnerability information going forward. Expect clear context, practical takeaways, and a path from fragmented signals to trustworthy feeds.🎟️ See CRob’s full talk at OSFF New York (Oct 21–22, 2025).🌐 More about FINOS: https://www.finos.org/📧 Join our newsletter: https://www.finos.org/newsletter#FINOS #OSFFNY #OpenSourceSecurity #OpenSSF #CVE #CWE #NVD #VulnerabilityManagement #Risk #Compliance #SupplyChainSecurity


The FINOS Open Source in Finance Podcast, presented by FINOS, delves into the practical realities of applying open source principles within the financial sector. This isn't a theoretical discussion; it's a series of conversations with industry experts who share their direct experiences implementing specific technologies. Episodes explore the tangible benefits and challenges of projects focused on areas like desktop interoperability, which streamlines how complex applications work together, and low-code platforms that accelerate development. Listeners will hear detailed analysis on using synthetic data for testing and innovation, as well as approaches to effective data modeling. The dialogue extends into organizational strategy, covering best practices for establishing successful inner source programs and fostering collaborative development cultures inside large institutions. Each episode of this podcast focuses on a concrete use case or a pressing question at the intersection of finance and open collaboration, providing actionable insights rather than abstract concepts. It's a resource for professionals who want to understand how open source is actively shaping tools, processes, and competitive advantages in financial services today.
Author: Language: English Episodes: 100

FINOS Open Source in Finance Podcast
Podcast Episodes
FINOS (and OSSF London) Debrief 14 October 21 [not-audio_url] [/not-audio_url]

Duration: 29:25
In this episode of the podcast we're excited talk about connections coming from our first in-person conference in two years, the FINOS Member Meeting and Open Source Strategy Forum in London last week. We talk about conn…
FINOS Debrief 17 September 21 [not-audio_url] [/not-audio_url]

Duration: 19:05
In this episode of the podcast we're excited to welcome a new FINOS team member, announce the OSSF NYC agenda, boast about our podcast, and as always, look for ways for you to get involved with the FINOS Community. New F…
FDC3 Fast and Easy - Kris West [not-audio_url] [/not-audio_url]

Duration: 16:31
In this episode of the podcast, Grizz "sits down" with Kris West, Principal Engineer at Cosaic, about his upcoming talk at the Open Source Strategy Forum in London October 5th. They discuss Kris's background and position…
Debunking Common Fears About Open Source | Danese Cooper [not-audio_url] [/not-audio_url]

Duration: 34:28
In this episode of the podcast Danese Cooper, Founder & Chair of InnerSource Commons, and long time open source veteran discusses Debunking Common Fears about Open Source (a great segway into our Open Source Strategy For…

«1...678910