Listen

Listened to Ep. 36 | Navigating the future of AI agent security with Dan Moore by Overcommitted
Post details
SummaryIn this episode of the Overcommitted Podcast, Erika and Brittany discuss the evolving landscape of AI agents and their implications for security and identity management. Joined by expert Dan Moore, they explore the challenges posed by non-deterministic agents, the importance of granular permissions, and the need for developers to be aware of security practices as AI technology advances. The conversation also touches on industry standards, the role of developers in navigating these changes, and personal reflections on the future of AI.TakeawaysAI agents are changing the landscape of software development.Non-deterministic agents present new security challenges.Granular permissions are essential for securing AI agents.Developers must be aware of security practices in AI.Industry standards for AI security are still evolving.Separation of concerns can enhance security for agents.The role of identity and authorization is critical in AI.Business implications of AI agents are significant.Developers should stay close to business needs and problem-solving.The future of AI will require new skills and awareness. LinksDan Moore on LinkedIn: www.linkedin.com/in/mooreds/ Dan Moore on Bluesky: https://bsky.app/profile/mooreds.comSimon Willison - The Lethal Trifecta: https://simonwillison.net/2025/Jun/16/the-lethal-trifecta/ FusionAuth: https://fusionauth.io/ AGNTCY: https://agntcy.org/Amazon Bedrock AgentCore: https://aws.amazon.com/bedrock/agentcore/ FusionAuth Guide to OAuth: https://fusionauth.io/articles/oauth/modern-guide-to-oauth MCP and OAuth: https://aaronparecki.com/2025/04/03/15/oauth-for-model-context-protocol MCP Specification: https://modelcontextprotocol.io/specification/2025-06-18/basic/authorization HostsOvercommitted: https://overcommitted.devBrittany Ellich: https://brittanyellich.com Eggyhead: https://github.com/eggyhead

 Listen

Listened to Break | Nearly A Year
Post details
Welcome back to Break, a Fallthrough aftershow! In this episode, the panel continues their conversation from Fallthrough #49.Enjoying the aftershow? Let us know on social media! If you prefer to watch instead of just listen, head over to YouTube where you watch this episode of Break!Thanks for...

 Listen

Listened to Fallthrough | Project Management 2 Shell
Post details
Another Cloudflare outage. A CVSS 10.0 React RCE vulnerability. We've been dealing with quite a lot these last few weeks. In this week's episode, Kris and Matt discuss the outage and vulnerability and have a deeper discussion about project management and how all of these things relate to each...

 Reply

I will say I didn't disagree with DHH's use of "open source" as I will generally let it slide as its not "Open Source", the version that I attribute to following the Open Source Definition as set out by the Open Source Initiative

I agree that there are many who don't understand the distinction and assume that "Open Source" == "open source", and so I do agree that avoiding the use of "open source" where it instead means "non-OSD" makes sense

 Listen

Listened to Blocking Software Supply Chain Attacks with Feross Aboukhadijeh - Software Engineering Daily by SEDaily 
Post details
Modern software relies heavily on open source dependencies, often pulling in thousands of packages maintained by developers all over the world. This accelerates innovation but also creates serious supply chain risks as attackers increasingly compromise popular libraries to spread malware at scale. Feross Aboukhadijeh is the founder and CEO of Socket which is a security

 Listen

Listened to Open Source Security: Updating open source dependencies with Jamie Tanna
Post details
Josh discusses updating open source dependencies with Jamie Tanna. Jamie works on Renovate which gives them a lot of insight into the challenges of keeping your open source updated. We discuss the challenges of semantic versioning, supply chain security, and AI-generated code. If you're new or old to the world of open source dependencies, there's something to learn from this chat. The show notes and blog post for this episode can be found at

 Note

Does anyone know if there's a Charm BubbleTea UI prototyper? I'm trying to find something to have a play with some of the components to test out a UI I'm building, and ideally something drag-and-drop to play around with it would be convenient

 Listen

Listened to Break | We're All Just Writers Now
Post details
Welcome back to Break, a Fallthrough aftershow! In this episode, the panel continues their conversation from Fallthrough #48.Enjoying the aftershow? Let us know on social media! If you prefer to watch instead of just listen, head over to YouTube where you watch this episode of Break!Thanks for...