Communications Very Erratic (CVE): Stabilizing Vuln Data for the Industry (OSFF NY Preview)

Communications Very Erratic (CVE): Stabilizing Vuln Data for the Industry (OSFF NY Preview)

Author: FINOS October 5, 2025 Duration: 34:14

🚹 What happens when the backbone of vulnerability reporting wobbles? In April 2025, funding shocks to CVE/CWE—and the downstream NVD—sparked panic before a short-term lifeline appeared. The uncertainty hasn’t gone away.In this clip:Christopher “CRob” Robinson, CTO & Chief Security Architect, OpenSSF (The Linux Foundation)CRob previews his OSFF NY session on why reliable, authoritative vulnerability metadata is critical for banks, regulated enterprises, and open source maintainers—and what upstream is doing about it. He walks through the recent CVE/NVD turbulence, why downstream teams (risk, OSPOs, product owners) struggle to meet regulatory obligations without stable data, and how the open source community is collaborating to deliver consistent, high-quality vulnerability information going forward. Expect clear context, practical takeaways, and a path from fragmented signals to trustworthy feeds.đŸŽŸïž See CRob’s full talk at OSFF New York (Oct 21–22, 2025).🌐 More about FINOS: https://www.finos.org/📧 Join our newsletter: https://www.finos.org/newsletter#FINOS #OSFFNY #OpenSourceSecurity #OpenSSF #CVE #CWE #NVD #VulnerabilityManagement #Risk #Compliance #SupplyChainSecurity


The FINOS Open Source in Finance Podcast, presented by FINOS, delves into the practical realities of applying open source principles within the financial sector. This isn't a theoretical discussion; it's a series of conversations with industry experts who share their direct experiences implementing specific technologies. Episodes explore the tangible benefits and challenges of projects focused on areas like desktop interoperability, which streamlines how complex applications work together, and low-code platforms that accelerate development. Listeners will hear detailed analysis on using synthetic data for testing and innovation, as well as approaches to effective data modeling. The dialogue extends into organizational strategy, covering best practices for establishing successful inner source programs and fostering collaborative development cultures inside large institutions. Each episode of this podcast focuses on a concrete use case or a pressing question at the intersection of finance and open collaboration, providing actionable insights rather than abstract concepts. It's a resource for professionals who want to understand how open source is actively shaping tools, processes, and competitive advantages in financial services today.
Author: Language: English Episodes: 100

FINOS Open Source in Finance Podcast
Podcast Episodes
FINOS August 30 2022 Debrief [not-audio_url] [/not-audio_url]

Duration: 23:18
In this episode of the podcast, we return to our FINOS Debrief episodes (now monthly) that wrap up the past month in the FINOS Ecosystem - and look forward to the next month and beyond. More links to come... State of Ope

Project Updates & Hot Topics - James McLeod, FINOS [not-audio_url] [/not-audio_url]

Duration: 32:47
In this episode of the podcast, Niamh interviews James McLeod, Director of Community at FINOS. We talk project updates and what's happening in the FINOS community. James's Info CFP - submit your talks for OSFF NYC by Sep

FINOS August 2022 Debrief [not-audio_url] [/not-audio_url]

Duration: 23:05
In this episode of the podcast, we return to our FINOS Debrief episodes (now monthly) that wrap up the past month in the FINOS Ecosystem - and look forward to the next month and beyond. FINOS August Newsletter (for most

What’s new with FDC3 v2.0? - Kris West, Cosaic [not-audio_url] [/not-audio_url]

Duration: 36:30
In this episode of the podcast, Grizz sits down with Kris West, Principal Engineer at Cosaic, and Lead Maintainer for the FDC3 Project to talk about the release of FDC3 v2.0, Kris' role as a maintainer, and the "why" on

How to get them to Commit? - Elena Lape, Holographic [not-audio_url] [/not-audio_url]

Duration: 23:15
In this episode of the podcast, Grizz sits down with Elena Lape, Co-Founder of Holographic Inc. to talk about her OSFF talk: "How to get them to Commit?". Plus, we talk about developer relations, open source in financial