Communications Very Erratic (CVE): Stabilizing Vuln Data for the Industry (OSFF NY Preview)

Communications Very Erratic (CVE): Stabilizing Vuln Data for the Industry (OSFF NY Preview)

Author: FINOS October 5, 2025 Duration: 34:14

🚨 What happens when the backbone of vulnerability reporting wobbles? In April 2025, funding shocks to CVE/CWE—and the downstream NVD—sparked panic before a short-term lifeline appeared. The uncertainty hasn’t gone away.In this clip:Christopher “CRob” Robinson, CTO & Chief Security Architect, OpenSSF (The Linux Foundation)CRob previews his OSFF NY session on why reliable, authoritative vulnerability metadata is critical for banks, regulated enterprises, and open source maintainers—and what upstream is doing about it. He walks through the recent CVE/NVD turbulence, why downstream teams (risk, OSPOs, product owners) struggle to meet regulatory obligations without stable data, and how the open source community is collaborating to deliver consistent, high-quality vulnerability information going forward. Expect clear context, practical takeaways, and a path from fragmented signals to trustworthy feeds.🎟️ See CRob’s full talk at OSFF New York (Oct 21–22, 2025).🌐 More about FINOS: https://www.finos.org/📧 Join our newsletter: https://www.finos.org/newsletter#FINOS #OSFFNY #OpenSourceSecurity #OpenSSF #CVE #CWE #NVD #VulnerabilityManagement #Risk #Compliance #SupplyChainSecurity


The FINOS Open Source in Finance Podcast, presented by FINOS, delves into the practical realities of applying open source principles within the financial sector. This isn't a theoretical discussion; it's a series of conversations with industry experts who share their direct experiences implementing specific technologies. Episodes explore the tangible benefits and challenges of projects focused on areas like desktop interoperability, which streamlines how complex applications work together, and low-code platforms that accelerate development. Listeners will hear detailed analysis on using synthetic data for testing and innovation, as well as approaches to effective data modeling. The dialogue extends into organizational strategy, covering best practices for establishing successful inner source programs and fostering collaborative development cultures inside large institutions. Each episode of this podcast focuses on a concrete use case or a pressing question at the intersection of finance and open collaboration, providing actionable insights rather than abstract concepts. It's a resource for professionals who want to understand how open source is actively shaping tools, processes, and competitive advantages in financial services today.
Author: Language: English Episodes: 100

FINOS Open Source in Finance Podcast
Podcast Episodes
Regulatory Challenges in Finance Insights from Leo Labeis, Regnosys [not-audio_url] [/not-audio_url]

Duration: 52:52
In this episode of the FINOS Open Source in Finance podcast, Head of Marketing Grizz Griswold interviews Leo Labeis, CEO of Regnosys. They explore regulatory challenges in finance, focusing on the Rune project and Common…
Colin Eberhardt - CTO, Scott Logic [not-audio_url] [/not-audio_url]

Duration: 32:27
In this episode of the podcast, Grizz sits down with Colin Eberhardt - CTO, Scott Logic. We talk about Colin's journey to CTO, ai, ai, ai, and ai. Colin Eberhardt: ⁠⁠⁠https://www.linkedin.com/in/colin-eberhardt-1464b4a/…
Andrew Aitken - Chief Open Source Officer, Hedera [not-audio_url] [/not-audio_url]

Duration: 43:34
In this episode of the podcast, Grizz sits down with Andrew Aitken - Chief Open Source Officer, Hedera. We talk about open source in finance, past, present, and future and how Web3 factors in. Andrew Aitken: ⁠⁠https://ww…
Lee Faus - Global Field CTO, GitLab [not-audio_url] [/not-audio_url]

Duration: 45:34
In this episode of the podcast, Grizz sits down with Lee Faus - Global Field CTO, GitLab. We talk about Lee's developer journey from high school teacher to GitLab, software development evolution and devops, intelligent d…
FINOS May 24 2024 Debrief - with Eddie Knight, Sonatype [not-audio_url] [/not-audio_url]

Duration: 1:02:50
In this episode of the podcast, Grizz and Eddie Knight of Sonatype return to our FINOS Debrief episodes that wrap up the past month or so in the FINOS Ecosystem - and look forward to the next month and beyond. Save 20% o…
Alex Scammon - Head of Open Source Development at G-Research [not-audio_url] [/not-audio_url]

Duration: 39:54
In this episode of the podcast, Grizz sits down with Alex Scammon - Head of Open Source Development at G-Research. We talk about Alex's building of an OSPO at G-Research, and how you need to be intrepid when you do somet…
Donald Fischer - CEO & CoFounder at Tidelift [not-audio_url] [/not-audio_url]

Duration: 45:25
In this episode of the podcast, Grizz sits down with Donald Fischer - CEO and CoFounder at Tidelift (a new Member of FINOS). We talk about Donald's journey through open source in the 90s to today, paying open source main…