The development world is cluttered with buzzwords and distractions. Speed, focus, and freedom? Gone.
I’m Nicky Pike. And it’s time for a reset.
[Dev]olution is here to help you get back to what matters: creating, solving, and making an impact. No trend chasing, just asking better questions.
What do devs really want?
How can platform teams drive flow, not friction?
How does AI actually help?
Join me every two weeks for straight talk with the people shaping the future of dev.
This is the [Dev]olution.
Nicky Pike (00:00):
A machine read through more than a thousand open source projects, software that you're probably running right now, and it came back with over 6,000 high and critical security vulnerabilities. 97 of them have been fixed. 97. And that counter, it hasn't moved since May. Now, I know where your head goes with a number like that because mine went there too. Scary AI, broken open source, everybody panic. Well, stick with me because that gap tells us where the actual problem's been this whole time. And I promise you, you're looking in the wrong place. Now, I didn't get here on my own. I got here because of 90 seconds in a conversation that I had a few weeks ago. Recently, I sat down with Gene Kim for 75 minutes. We talked, citizen developers, The Outer Loop. What happens to your processes when writing code stops being the hard part.
(00:53):
Go watch it. It's honestly one of my favorite conversations that I've had on this show, but there's about 90 seconds in there that I haven't been able to get out of my head. Near the end of the interview, Gene's telling me about a talk that he heard from Erik Meijer. Now, Meijer is a serious guy. Created LINQ, led Reactive Extensions. 13 years in Microsoft, nine more at Meta. Here's how Gene put it, and I'm quoting Gene because these are his words about somebody else's talk. He's like, "You've got to be crazy." Got to be crazy if you're running open source software. If you're coupled to the thing that always have vulnerabilities in it. I'm like, "What?" Gene's response in the room was, "So you're saying open source?" Open source is only for poor people? And everybody laughed. But then Gene sat with that statement. He told me on camera that he's conflicted about it.
(01:37):
Hell, I'm conflicted about it too. And let me be clear right up front, because that's exactly the kind of sentence that gets clipped and posted without context or anything around it. Nobody in this conversation is telling you to rip open source out of your stack. Not Mayor, not Gene, not me. What I want to do is figure out why somebody that credible would say it out loud at all. I'm Nicky Pike, and this is the [Dev]olution. Today, we're going after the oldest assumption in open source security and what happened when somebody finally tested it. Now, to understand why the 97 is the number that matters here and not the 6,000, we need to have two rules in our head at the same time. So let's go ahead and stack those up. First one you probably already know, Linus's law. Given enough eyeballs, all bugs are shallow.
(02:23):
That was a deal we made. You take code from somebody you've never met with no contract, no SLA, nobody to sue when it goes sideways, and in exchange, you get more people reading it than any single vendor could ever afford to pay for with the understanding that this makes the code more secure. Every open source policy and every enterprise on the planet is sitting on top of that one sentence. And read that promise close because it matters. The promise is about how many people are looking. That's it. That's the whole thing. The second rule is genes, and it's straight out of the interview. Coding was historically the bottleneck, which is why every process in your company exists to protect it. Prioritization, budgeting, capital allocation, all of it built to ration developer time. And when coding stops being scarce, everything else becomes the bottleneck. Now point that second rule at the first.
(03:16):
That's what we're talking about here. Before we get anywhere near the AI, let's check whether those eyeballs were ever actually there. March 2024, XZ Utils, a compression library sitting underneath basically every Linux distribution on earth. Somebody spent roughly two years being a helpful contributor, patient, friendly, fixing real bugs. They earned commit access the honest way. And then they slipped in a back door targeting SSH authentication that made it into Debian's testing branch, Fedora Rawhide, and the Ubuntu 24.04 Beta. You want to know how that one got caught? A Postgres developer at Microsoft named Andres Freund was running benchmarks on something completely unrelated. And he noticed that SSHD was burning CPU on login attempts that were already failing. So he pulled the thread. Valgrind errors. Logins running about a half a second slow. A guy annoyed enough to go find out why. One guy, a benchmark and a bad mood on Tuesday.
(04:14):
That's what stood between a back door and every Linux systems on the planet. And let's be honest, finding that one was luck. But it just keeps happening. Just a few weeks ago, somebody stole a publishing credential and they published five poisoned versions of Jscrambler's NPM package. And Jscrambler is a security company. They sell JavaScript protection for a living. The payload went hunting for crypto wallets, cloud credentials. And here's the part that should probably get your attention. It specifically went looking for your cloud desktop config, your dot cloud file and your cursor MCP config. A supply chain attack that steals the setup of the AI coding tools half of you are running right now. Socket, one of the outfits that watches NPM for exactly this, flagged it in about six minutes. About 1400 people had already pulled it down. So that's the eyeballs. Sometimes there are none at all and a back door sits inside an XZ Utils for two years.
(05:09):
Sometimes they're excellent and socket catches Jscrambler in six minutes, but 1400 people get burned anyway. So follow that second one away. That's the shape of everything coming next. In April, somebody built eyes that never get tired. Anthropic launches Project Glasswing with a serious consortium behind it. AWS, Apple, Google, Microsoft, Nvidia, JP Morgan, the Linux Foundation. A vertical who's who in this industry. They point a model called Metis at open source and they let it hunt. 6,200 findings that it rated higher critical. Though careful with that number because that's the model's own estimate. Outside firms spot checked a sample and about 60% held up at that severity. So let's call it roughly 4,000 real ones. Anthropic's own projection lands right about there. 4,000. Still an enormous number. And some of those, they're genuinely nasty. The best documented one is in wolfSSL. CVE-2025-5194.
(06:12):
And it's ugly. Certificate authentication bypass, CVSS score of 9.3. And Wolf SSL, they say that their library ships in about five billion applications and devices. Now it was patched the next day and all credit where it's due to them for doing that. But Anthropic said back in May that they would publish the full technical breakdown in the coming weeks. That was over two months ago and we're still waiting. Now, I do want to be careful here because not everything in this Metis pile is that solid. There's a claim going around that Metis found a flaw sitting in OpenBSD for 27 years. We went looking for that one. There's no CVE. OpenBSD hasn't credited anybody. Nobody's published how the 27 years actually got calculated. Anthropic released cryptographic commitments instead of the technical details. So right now, nobody outside the company can check the work. Now I'm not calling anyone a liar.
(07:06):
I'm just telling you where the evidence sits because that's the promise that we made to you on this channel. But here's what actually matters though. Finding vulnerabilities was always possible. It was just rate limited by how many humans were willing to read somebody else's code for free on a Saturday. Glasswing has taken the governor off. So what happened downstream? 97. 97 vulnerabilities patched. And that's Anthropic's own dashboard, their own number. That's the friendly one. Their own language is that fewer than 1% of what they found has actually been patched by maintainers. That dashboard was last updated on May 22nd. That's over 83 days ago. Remember that WOF SSL write up that was supposed to be coming in a few weeks? Still waiting. Same with the full public accounting that they promised for this month. In short, the finding got a press release. The follow through, it got a to-do list.
(07:58):
And this isn't just me squinting at a webpage. The security research firm, Voncheck, ran an independent audit in June. 10 of those findings had already blown past Anthropic's own 90-day disclosure deadline. Another 168? Those are going to be hit it within the next month. And here's a quote that reframed the whole thing for me. David Linder, CISO at Contrast Security, talking to Fortune back in April. We've never had a problem finding vulnerabilities. We find them every day. We actually have a pile of them that we just don't fix. That's in April. He's describing the world before any of this scaled up. The man was already drowning. Now bolt a machine that never sleeps to the front of that pipeline. Daniel Stenberg maintains curl. You're running curl right now, whether you know it or not. He went from about one vulnerability report a week before AI to one every 18 hours this June.
(08:50):
His read on it's this. They asked the AI, the AI said something. They have no idea if it's right or wrong. They just pass it on to us. And Anthropic says this out loud in their own writeup. Maintainers have asked them to slow down reporting because they need more time to design patches. A thousand times more eyes, same number of hands. So here's where I landed on this. For 25 years, the security case for open source has always been about scrutiny. More people looking, therefore safer. We wrote policy on that. We passed audits with it. Now scrutiny has always been incomplete. XZ proves that. 4,000 findings prove that. So the eyeballs promise was oversold and we all kind of knew it, but incomplete scrutiny was never what was actually holding us back. Linder had a pile that he couldn't get through before a model ever touched a line of code.
(09:41):
Stenberg had more reports than he had weekends. Back when finding was slow, we already had more than we could work. So making finding fast didn't buy us more security. It just made our pile hauler. That's why a guy like Erik Meijer starts wondering out loud whether the dependency is worth carrying. Open source is the same thing it always was. We were just counting on it for the easy part while the hard part never had a staffing plan, which if you watch the Gene Kim episode, should sound pretty familiar. When the thing that you've built everything around stops being scarce, the bottleneck moves. It lands somewhere nobody planned for and that nobody hired for. Gene said that about shipping software. Turns out it's just as true about securing it and he wasn't even talking about security. So what do you do with that on a Monday?
(10:30):
Because a diagnosis with no treatment plan is basically just bad news. Start out by finding which of your dependencies have one maintainer or zero. That's your actual risk register. And I would bet money that almost nobody watching this has built it. Fund the people maintaining what you ship on. It's the least satisfying answer in the world, but it has the most evidence behind it. Treat AI findings as raw material. Somebody with a brain still has to work every one of them because the patch suggestions are rarely complete. Sign your artifacts. Absolutely. Just know exactly what that buys you. Back in June, somebody published 32 poison releases under Red Hat's name on NPM. Security experts at Wiz dug into it and they found that every one of them was signed. The Providence checked out clean. The crypto did its job perfectly. And what it certified was that the malicious code came from exactly where it said it came from.
(11:22):
And rewriting a dependency yourself, the Meijer move, works fine for narrow, stable, boring utilities. Try it on cryptography and you'll deserve what happens next. The day you rewrite something, you own that code forever. No upstream, nobody else reading it. You traded somebody else's risk for your own maintenance bill. Sometimes that's worth it. So make sure you do it with purpose. One question to walk away with. For the stuff that's on your critical path, do you know who fixes it and how fast when somebody finds something wrong? Who fixes it? Say that person's name out loud. And if the answer is a volunteer that you've never sent a single dollar to, that is your dependency risk. It was your dependency risk before any of this started. You just couldn't see it yet. Thousands found, 97 fixed, and a counter that stopped moving in May. We've spent 25 years telling ourselves that somebody was looking.
(12:17):
Somebody has now scaled that looking. And what we found out is that looking was never the part we were bad at. 90 seconds out of 75 minute conversation. Gene's got a lot more where that came from. Go watch the whole thing. Links down below. Now, before you go, I want to hear from you on this one because I don't think there's a clean answer and I would rather argue with you guys about it than pretend I've got it all figured out. 6,000 found, 97 fixed. So did AI make open source safer or did it hand a bill to a bunch of volunteers who were already barely treading water? Tell me in the comments. And if there's a dependency sitting in your stack right now that you would rewrite tomorrow rather than to keep carrying it, name it. I want to see that list. Now, if this landed, like and subscribe to join the [Dev]olution if you haven't already.
(13:07):
We've built it for the grey area developer. Those engineers and leaders who aren't chasing trends, they're just trying to do great work and keep up with an industry that won't slow down for anybody. That's our whole mission, bringing the focus back to building good software. See you next time. Thank you for listening to [Dev]olution. If you've got something for us to decode, let me know. You can message me, Nicky Pike on LinkedIn, or join our Discord community and drop it there. And seriously, don't forget to subscribe. You do not want to miss what's next.