<img height="1" width="1" style="display:none" src="https://www.facebook.com/tr?id=705633339897683&amp;ev=PageView&amp;noscript=1">
Kanish Sharma
Tidelift
Kanish Sharma
Product marketing

Tidelift
Tatu Saloranta
jackson-databind
Tatu Saloranta
Maintainer

jackson-databind
Wesley Beary
Anchor.dev, maintainer of Fog and excon projects
Wesley Beary
Founding engineer and maintainer

Anchor.dev, maintainer of Fog and excon projects
Irina Nazarova
Evil Martians
Irina Nazarova
CEO

Evil Martians
Amy Hays
Tidelift
Amy Hays
Upstream chair

Tidelift
Valeri Karpov
MeanIT Software and Mongoose
Valeri Karpov
Founder and CEO, and maintainer

MeanIT Software and Mongoose
Panel: State of the open source maintainer in 2024

What's it like to be an open source maintainer in 2024? In an annual Upstream tradition, we sit down with a group of maintainers to hear directly from them to find out. This year's panel includes Valeri Karpov from Mongoose, Irina Nazarova of Evil Martians, Tatu Saloranta of jackson-databind, and Wesley Beary, who maintains popular Ruby projects fog and excon. We'll ask them about how the recent xz utils hack made them feel, how community and project health looks from their perspectives, ways enterprise users and organizations can help maintainers, and much more!

What's it like to be an open source maintainer in 2024? In an annual Upstream tradition, we sit down with a group of maintainers to hear directly from them to find out. This year's panel includes...

10-questions

10 questions you should answer before using an open source project

When it comes to open source software security, many organizations rely heavily on software scanning (often called software composition analysis or SCA) as the primary means of defense.

Proactive approach case study

The value of a proactive approach to open source application security

Learn how one large organization saved over $1.6M in manual package evaluation time and eliminated over 3,000 points of risk in applications running in production.

1200x628 (4)

The guide to reducing security risk from bad open source packages

In this guide, we'll discuss how your organization can reduce risk by avoiding “bad” open source packages.