38 subscribers
התחל במצב לא מקוון עם האפליקציה Player FM !
פודקאסטים ששווה להאזין
בחסות
The Software Risk That Affects Everyone and How To Address It with Michael Winser and Jarek Potiuk
Manage episode 472389708 series 2053958
The security of open-source software is a growing concern, especially as dependencies and regulations become more complex, making it essential to understand how to manage software supply chains effectively.
In this episode, we sit down with Michael Winser, Co-Founder at Alpha-Omega and Security Strategy Ambassador at Eclipse Foundation, and Jarek Potiuk, Member of the Security Committee at the Apache Software Foundation, to discuss the challenges of securing Airflow’s dependencies, the evolving landscape of open-source security and how contributors can help strengthen the ecosystem.
Key Takeaways:
(02:43) Jarek quit his full-time engineer position and uses Airflow as a freelancer.
(04:32) Michael finds happiness in having meaningful work with open-source security.
(07:01) Software supply chain security focuses on correctness, integrity and availability.
(08:44) Airflow’s 790 dependencies present a unique security challenge.
(09:43) Airflow’s security team has significantly improved its vulnerability response.
(10:22) The transition to Airflow 3 emphasizes enterprise security readiness.
(16:20) The ‘Three Fs’ approach: fix it, fork it, or forget it.
(18:45) Dependency health is often more critical than fixing known vulnerabilities.
(23:32) The ‘Three Fs’ in action.
(26:26) Open-source contributors play a key role in supply chain security.
Resources Mentioned:
https://www.linkedin.com/in/michaelw/
https://www.linkedin.com/in/jarekpotiuk/
https://airflow.apache.org/
Apache Software Foundation | LinkedIn -
https://www.linkedin.com/company/the-apache-software-foundation/
Apache Software Foundation | Website -
https://www.apache.org/
Eclipse Foundation | LinkedIn -
https://www.linkedin.com/company/eclipse-foundation/
Eclipse Foundation | Website -
https://www.eclipse.org/org/foundation/
https://openssf.org/community/openssf-working-groups/
Astronomer Roadshow: Exploring Apache Airflow 3 | London
https://www.astronomer.io/events/roadshow/london/
Astronomer Roadshow: Exploring Apache Airflow 3 | New York
https://www.astronomer.io/events/roadshow/new-york/
Astronomer Roadshow: Exploring Apache Airflow 3 | Sydney
https://www.astronomer.io/events/roadshow/sydney/
Astronomer Roadshow: Exploring Apache Airflow 3 | San Francisco
https://www.astronomer.io/events/roadshow/san-francisco/
Astronomer Roadshow: Exploring Apache Airflow 3 | Chicago
https://www.astronomer.io/events/roadshow/chicago/
Thanks for listening to “The Data Flowcast: Mastering Airflow for Data Engineering & AI.” If you enjoyed this episode, please leave a 5-star review to help get the word out about the show. And be sure to subscribe so you never miss any of the insightful conversations.
#AI #Automation #Airflow #MachineLearning
56 פרקים
The Software Risk That Affects Everyone and How To Address It with Michael Winser and Jarek Potiuk
The Data Flowcast: Mastering Apache Airflow ® for Data Engineering and AI
Manage episode 472389708 series 2053958
The security of open-source software is a growing concern, especially as dependencies and regulations become more complex, making it essential to understand how to manage software supply chains effectively.
In this episode, we sit down with Michael Winser, Co-Founder at Alpha-Omega and Security Strategy Ambassador at Eclipse Foundation, and Jarek Potiuk, Member of the Security Committee at the Apache Software Foundation, to discuss the challenges of securing Airflow’s dependencies, the evolving landscape of open-source security and how contributors can help strengthen the ecosystem.
Key Takeaways:
(02:43) Jarek quit his full-time engineer position and uses Airflow as a freelancer.
(04:32) Michael finds happiness in having meaningful work with open-source security.
(07:01) Software supply chain security focuses on correctness, integrity and availability.
(08:44) Airflow’s 790 dependencies present a unique security challenge.
(09:43) Airflow’s security team has significantly improved its vulnerability response.
(10:22) The transition to Airflow 3 emphasizes enterprise security readiness.
(16:20) The ‘Three Fs’ approach: fix it, fork it, or forget it.
(18:45) Dependency health is often more critical than fixing known vulnerabilities.
(23:32) The ‘Three Fs’ in action.
(26:26) Open-source contributors play a key role in supply chain security.
Resources Mentioned:
https://www.linkedin.com/in/michaelw/
https://www.linkedin.com/in/jarekpotiuk/
https://airflow.apache.org/
Apache Software Foundation | LinkedIn -
https://www.linkedin.com/company/the-apache-software-foundation/
Apache Software Foundation | Website -
https://www.apache.org/
Eclipse Foundation | LinkedIn -
https://www.linkedin.com/company/eclipse-foundation/
Eclipse Foundation | Website -
https://www.eclipse.org/org/foundation/
https://openssf.org/community/openssf-working-groups/
Astronomer Roadshow: Exploring Apache Airflow 3 | London
https://www.astronomer.io/events/roadshow/london/
Astronomer Roadshow: Exploring Apache Airflow 3 | New York
https://www.astronomer.io/events/roadshow/new-york/
Astronomer Roadshow: Exploring Apache Airflow 3 | Sydney
https://www.astronomer.io/events/roadshow/sydney/
Astronomer Roadshow: Exploring Apache Airflow 3 | San Francisco
https://www.astronomer.io/events/roadshow/san-francisco/
Astronomer Roadshow: Exploring Apache Airflow 3 | Chicago
https://www.astronomer.io/events/roadshow/chicago/
Thanks for listening to “The Data Flowcast: Mastering Airflow for Data Engineering & AI.” If you enjoyed this episode, please leave a 5-star review to help get the word out about the show. And be sure to subscribe so you never miss any of the insightful conversations.
#AI #Automation #Airflow #MachineLearning
56 פרקים
כל הפרקים
×
1 Building an End-to-End Data Observability System at Netflix with Joseph Machado 38:54

1 Why Developer Experience Shapes Data Pipeline Standards at Next Insurance with Snir Israeli 30:28

1 Data Quality and Observability at Tekmetric with Ipsa Trivedi 22:49

1 Introducing Apache Airflow® 3 with Vikram Koka and Jed Cunningham 27:28

1 Airflow in Action: Powering Instacart's Complex Ecosystem 25:14

1 From ETL to Airflow: Transforming Data Engineering at Deloitte Digital with Raviteja Tholupunoori 27:42

1 A Deep Dive Into the 2025 State of Airflow Survey Results with Tamara Fingerlin of Astronomer 23:26

1 Airflow’s Role in the Rise of DataOps with Andy Byron 26:15

1 The Software Risk That Affects Everyone and How To Address It with Michael Winser and Jarek Potiuk 28:27

1 Building Scalable ML Infrastructure at Outerbounds with Savin Goyal 36:46

1 Customizing Airflow for Complex Data Environments at Stripe with Nick Bilozerov and Sharadh Krishnamurthy 27:40

1 Harnessing Airflow for Data-Driven Policy Research at CSET with Jennifer Melot 17:54

1 Leveraging Airflow To Build Scalable and Reliable Data Platforms at 99acres.com with Samyak Jain 25:08

1 Hybrid Testing Solutions for Autonomous Driving at Bosch with Jens Scheffler and Christian Schilling 33:45

1 Overcoming Airflow Scaling Challenges at Monzo Bank with Jonathan Rainer 43:39

1 Orchestrating Analytics and AI Workflows at Telia with Arjun Anandkumar 26:00

1 The Role of Airflow in Finance Transformation at Etraveli Group with Mihir Samant 21:19

1 Inside Ford’s Data Transformation: Advanced Orchestration Strategies with Vasantha Kosuri-Marshall 38:54

1 Powering Finance With Advanced Data Solutions at Ramp with Ryan Delgado 24:35

1 Exploring the Power of Airflow 3 at Astronomer with Amogh Desai 30:24

1 Using Airflow To Power Machine Learning Pipelines at Optimove with Vasyl Vasyuta 24:11

1 Maximizing Business Impact Through Data at GlossGenius with Katie Bauer 25:49

1 Optimizing Large-Scale Deployments at LinkedIn with Rahul Gade 27:47

1 How Uber Manages 1 Million Daily Tasks Using Airflow, with Shobhit Shah and Sumit Maheshwari 28:44

1 Building Resilient Data Systems for Modern Enterprises at Astrafy with Andrea Bombino 28:29

1 Inside Airflow 3: Redefining Data Engineering with Vikram Koka 30:08

1 Building a Data-Driven HR Platform at 15Five with Guy Dassa 20:25

1 The Intersection of AI and Data Management at Dosu with Devin Stein 20:18

1 AI-Powered Vehicle Automation at Ford Motor Company with Serjesh Sharma 26:11

1 From Task Failures to Operational Excellence at GumGum with Brendan Frick 24:06

1 From Sensors to Datasets: Enhancing Airflow at Astronomer with Maggie Stark and Marion Azoulai 22:25

1 Mastering Data Orchestration with Airflow at M Science with Ben Tallman 24:36


1 Enhancing Business Metrics With Airflow at Artlist with Hannan Kravitz 23:51

1 Cutting-Edge Data Engineering at Teya with Alexandre Magno Lima Martins 23:46

1 Airflow Strategies for Business Efficiency at Campbell with Larry Komenda 26:10

1 How Laurel Uses Airflow To Enhance Machine Learning Pipelines with Vincent La and Jim Howard 23:58

1 How Vibrant Planet's Self-Healing Pipelines Revolutionize Data Processing 23:51

1 The Future of AI in Data Engineering With Astronomer’s Julian LaNeve and David Xue 23:36

1 The Power of Airflow in Modern Data Environments at Wynn Las Vegas with Siva Krishna Yetukuri 24:31

1 Powering the Texas Rangers World Series Win With AI on Airflow with Alexander Booth 23:38

1 Expanding the Data Engineering Toolkit at Reddit 45:48

1 GDPR, Self-Service Data, and Infrastructure Automation with Typeform 31:26




1 Open Source and Airflow at Google 39:03


1 Role-Based Access Control (RBAC) 37:28







ברוכים הבאים אל Player FM!
Player FM סורק את האינטרנט עבור פודקאסטים באיכות גבוהה בשבילכם כדי שתהנו מהם כרגע. זה יישום הפודקאסט הטוב ביותר והוא עובד על אנדרואיד, iPhone ואינטרנט. הירשמו לסנכרון מנויים במכשירים שונים.