Communications Very Erratic (CVE): Stabilizing Vuln Data for the Industry (OSFF NY Preview)

Communications Very Erratic (CVE): Stabilizing Vuln Data for the Industry (OSFF NY Preview)

Author: FINOS October 5, 2025 Duration: 34:14

🚨 What happens when the backbone of vulnerability reporting wobbles? In April 2025, funding shocks to CVE/CWE—and the downstream NVD—sparked panic before a short-term lifeline appeared. The uncertainty hasn’t gone away.In this clip:Christopher “CRob” Robinson, CTO & Chief Security Architect, OpenSSF (The Linux Foundation)CRob previews his OSFF NY session on why reliable, authoritative vulnerability metadata is critical for banks, regulated enterprises, and open source maintainers—and what upstream is doing about it. He walks through the recent CVE/NVD turbulence, why downstream teams (risk, OSPOs, product owners) struggle to meet regulatory obligations without stable data, and how the open source community is collaborating to deliver consistent, high-quality vulnerability information going forward. Expect clear context, practical takeaways, and a path from fragmented signals to trustworthy feeds.🎟️ See CRob’s full talk at OSFF New York (Oct 21–22, 2025).🌐 More about FINOS: https://www.finos.org/📧 Join our newsletter: https://www.finos.org/newsletter#FINOS #OSFFNY #OpenSourceSecurity #OpenSSF #CVE #CWE #NVD #VulnerabilityManagement #Risk #Compliance #SupplyChainSecurity


The FINOS Open Source in Finance Podcast, presented by FINOS, delves into the practical realities of applying open source principles within the financial sector. This isn't a theoretical discussion; it's a series of conversations with industry experts who share their direct experiences implementing specific technologies. Episodes explore the tangible benefits and challenges of projects focused on areas like desktop interoperability, which streamlines how complex applications work together, and low-code platforms that accelerate development. Listeners will hear detailed analysis on using synthetic data for testing and innovation, as well as approaches to effective data modeling. The dialogue extends into organizational strategy, covering best practices for establishing successful inner source programs and fostering collaborative development cultures inside large institutions. Each episode of this podcast focuses on a concrete use case or a pressing question at the intersection of finance and open collaboration, providing actionable insights rather than abstract concepts. It's a resource for professionals who want to understand how open source is actively shaping tools, processes, and competitive advantages in financial services today.
Author: Language: English Episodes: 100

FINOS Open Source in Finance Podcast
Podcast Episodes
FINOS October 27 2022 Debrief + Q4 All Community Call [not-audio_url] [/not-audio_url]

Duration: 1:12:31
In this episode of the podcast, we return to our FINOS Debrief episodes (now monthly) that wrap up the past month in the FINOS Ecosystem - and look forward to the next month and beyond. We've also added the FINOS Q4 All…
FINOS September 28 2022 Debrief [not-audio_url] [/not-audio_url]

Duration: 21:27
In this episode of the podcast, we return to our FINOS Debrief episodes (now monthly) that wrap up the past month in the FINOS Ecosystem - and look forward to the next month and beyond. Links will be added here shortly:…