Skip to content

About this Episode

In this episode of the GR-OSS Out Podcast, host Jay Faulkner talks with Juan Escalada, maintainer of GitProxy at G-Research Open Source Software, about a serious vulnerability in GitProxy that allowed a second branch push to bypass every security check the tool was designed to enforce.

Juan explains how the bug was found through a security audit, why it went unnoticed in production for years, and how the G-Research team handled responsible disclosure — being transparent about the flaw even when it wasn't the easiest choice from a marketing standpoint.

The conversation also covers how GitProxy works as a network-level proxy for Git requests, unpacking and validating Git pack files, auditing pushes, and blocking data exfiltration before code reaches remotes like GitHub or GitLab. Juan and Jay discuss a new single-push approval workflow in development, and where artificial intelligence (AI) tools help — and where they still fall short — in software architecture and system design.

Juan also shares his path from Major League Hacking (MLH) Fellow to full-time GitProxy maintainer in under two years, the mindset shift required to go from writing code to being responsible for reviewing other people's code, working through imposter syndrome as a new maintainer, and practical advice for engineers applying to the MLH Fellowship — including why a well-lit, professional video call setup matters more than people expect.

GitProxy - https://git-proxy.finos.org/
Open WebUI - https://openwebui.com/
MLH Fellowship - https://fellowship.mlh.com/
"Developers" - https://www.youtube.com/watch?v=8fcSviC7cRM

G-Research is hiring in Dallas, TX and London, UK! Apply at https://gresearch.com/vacancies.

For a video version of this podcast, check out https://youtu.be/zNUTa4s0l3k.

The GR-OSS OUT Podcast is produced by Ben Wiley.