<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" encoding="UTF-8" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" xmlns:admin="http://webns.net/mvcb/" xmlns:atom="http://www.w3.org/2005/Atom/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:googleplay="http://www.google.com/schemas/play-podcasts/1.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:fireside="http://fireside.fm/modules/rss/fireside">
  <channel>
    <fireside:hostname>app01</fireside:hostname>
    <fireside:genDate>Fri, 18 Sep 2026 00:14:42 +0000</fireside:genDate>
    <generator>Fireside (https://fireside.fm)</generator>
    <title>GR-OSS OUT Podcast - Episodes Tagged with “Juan Escalada”</title>
    <link>https://podcast.gr-oss.io/tags/juan%20escalada</link>
    <pubDate>Thu, 17 Sep 2026 14:00:00 -0700</pubDate>
    <description>This podcast takes an honest and unvarnished look at the reality of contributing to open source software projects. Too often, the open source community can paint an idealized picture of seamless collaboration and frictionless progress. But the truth is, working on OSS projects can be challenging, messy, and at times, downright frustrating. From conflicting opinions and coding philosophies to project politics and ownership disputes, there are many potential pitfalls. That's why this podcast gives voice to the personal experiences of actual open source contributors and influencers. They'll share the unfiltered ups and downs they've faced working on real projects. You'll hear war stories of coding battles, community dramas, and those weekly agonizing pull request reviews. But it's not all horror stories! You'll also learn valuable lessons about persevering through challenges, building consensus, and ultimately creating robust open source software that delivers value. Guests will provide insights into cultivating positive OSS communities and effective collaboration processes. So whether you're a veteran open source participant or just getting started, this podcast will prepare you for the gritty realities and help you navigate the unusual situations that so often arise. Join us as we embrace the awkward, frustrating, and yes, even "gross" side of open source software development. It's a journey that every contributor needs to understand.</description>
    <language>en-us</language>
    <itunes:type>episodic</itunes:type>
    <itunes:subtitle>G-Research Open Source Software Outreach podcast</itunes:subtitle>
    <itunes:author>G-Research Open Source Software</itunes:author>
    <itunes:summary>This podcast takes an honest and unvarnished look at the reality of contributing to open source software projects. Too often, the open source community can paint an idealized picture of seamless collaboration and frictionless progress. But the truth is, working on OSS projects can be challenging, messy, and at times, downright frustrating. From conflicting opinions and coding philosophies to project politics and ownership disputes, there are many potential pitfalls. That's why this podcast gives voice to the personal experiences of actual open source contributors and influencers. They'll share the unfiltered ups and downs they've faced working on real projects. You'll hear war stories of coding battles, community dramas, and those weekly agonizing pull request reviews. But it's not all horror stories! You'll also learn valuable lessons about persevering through challenges, building consensus, and ultimately creating robust open source software that delivers value. Guests will provide insights into cultivating positive OSS communities and effective collaboration processes. So whether you're a veteran open source participant or just getting started, this podcast will prepare you for the gritty realities and help you navigate the unusual situations that so often arise. Join us as we embrace the awkward, frustrating, and yes, even "gross" side of open source software development. It's a journey that every contributor needs to understand.</itunes:summary>
    <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/6/68648c4e-4324-457a-8179-49dad78b03c2/cover.jpg?v=3"/>
    <itunes:explicit>no</itunes:explicit>
    <itunes:keywords>oss, open source, community, artificial intelligence, machine learning, python, software</itunes:keywords>
    <itunes:owner>
      <itunes:name>G-Research Open Source Software</itunes:name>
      <itunes:email>podcast@gr-oss.io</itunes:email>
    </itunes:owner>
<itunes:category text="Technology"/>
<itunes:category text="Business"/>
<itunes:category text="Science"/>
<item>
  <title>GitProxy and the MLH fellowship with Juan Escalada</title>
  <link>https://podcast.gr-oss.io/27-gitproxy</link>
  <guid isPermaLink="false">88eaa770-2832-4c41-8e98-a5d394df6d68</guid>
  <pubDate>Thu, 17 Sep 2026 14:00:00 -0700</pubDate>
  <author>G-Research Open Source Software</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/68648c4e-4324-457a-8179-49dad78b03c2/88eaa770-2832-4c41-8e98-a5d394df6d68.mp3" length="86319185" type="audio/mpeg"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>G-Research Open Source Software</itunes:author>
  <itunes:subtitle>In this episode of the GROSS Out Podcast (GR-OSS Out Podcast), host Jay Faulkner talks with Juan Escalada, maintainer of GitProxy at G-Research Open Source Software, about a serious vulnerability in GitProxy that allowed a second branch push to bypass every security check the tool was designed to enforce.</itunes:subtitle>
  <itunes:duration>44:57</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/6/68648c4e-4324-457a-8179-49dad78b03c2/cover.jpg?v=3"/>
  <description>&lt;p&gt;In this episode of the GR-OSS Out Podcast, host Jay Faulkner talks with Juan Escalada, maintainer of GitProxy at G-Research Open Source Software, about a serious vulnerability in GitProxy that allowed a second branch push to bypass every security check the tool was designed to enforce.&lt;/p&gt;

&lt;p&gt;Juan explains how the bug was found through a security audit, why it went unnoticed in production for years, and how the G-Research team handled responsible disclosure — being transparent about the flaw even when it wasn't the easiest choice from a marketing standpoint.&lt;/p&gt;

&lt;p&gt;The conversation also covers how GitProxy works as a network-level proxy for Git requests, unpacking and validating Git pack files, auditing pushes, and blocking data exfiltration before code reaches remotes like GitHub or GitLab. Juan and Jay discuss a new single-push approval workflow in development, and where artificial intelligence (AI) tools help — and where they still fall short — in software architecture and system design.&lt;/p&gt;

&lt;p&gt;Juan also shares his path from Major League Hacking (MLH) Fellow to full-time GitProxy maintainer in under two years, the mindset shift required to go from writing code to being responsible for reviewing other people's code, working through imposter syndrome as a new maintainer, and practical advice for engineers applying to the MLH Fellowship — including why a well-lit, professional video call setup matters more than people expect.&lt;/p&gt;

&lt;p&gt;GitProxy - &lt;a href="https://git-proxy.finos.org/" rel="nofollow noopener"&gt;https://git-proxy.finos.org/&lt;/a&gt;&lt;br&gt;
Open WebUI - &lt;a href="https://openwebui.com/" rel="nofollow noopener"&gt;https://openwebui.com/&lt;/a&gt;&lt;br&gt;
MLH Fellowship - &lt;a href="https://fellowship.mlh.com/" rel="nofollow noopener"&gt;https://fellowship.mlh.com/&lt;/a&gt;&lt;br&gt;
"Developers" - &lt;a href="https://www.youtube.com/watch?v=8fcSviC7cRM" rel="nofollow noopener"&gt;https://www.youtube.com/watch?v=8fcSviC7cRM&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;G-Research is hiring in Dallas, TX and London, UK! Apply at &lt;a href="https://gresearch.com/vacancies" rel="nofollow noopener"&gt;https://gresearch.com/vacancies&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;For a video version of this podcast, check out &lt;a href="https://youtu.be/zNUTa4s0l3k" rel="nofollow noopener"&gt;https://youtu.be/zNUTa4s0l3k&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;The GR-OSS OUT Podcast is produced by Ben Wiley. Special Guest: Juan Escalada.&lt;/p&gt;
</description>
  <itunes:keywords>oss, open source, g-research, technology, GitProxy, Git security, GitHub security, GitLab security, open source security, application security, DevSecOps, continuous integration, continuous deployment, CI/CD, Git internals, software supply chain security, developer relations, DevRel, artificial intelligence, AI in software engineering, secret scanning, open source maintainers, software engineering careers, imposter syndrome, security vulnerabilities, security audit, responsible disclosure</itunes:keywords>
  <content:encoded>
    <![CDATA[<p>In this episode of the GR-OSS Out Podcast, host Jay Faulkner talks with Juan Escalada, maintainer of GitProxy at G-Research Open Source Software, about a serious vulnerability in GitProxy that allowed a second branch push to bypass every security check the tool was designed to enforce.</p>

<p>Juan explains how the bug was found through a security audit, why it went unnoticed in production for years, and how the G-Research team handled responsible disclosure — being transparent about the flaw even when it wasn't the easiest choice from a marketing standpoint.</p>

<p>The conversation also covers how GitProxy works as a network-level proxy for Git requests, unpacking and validating Git pack files, auditing pushes, and blocking data exfiltration before code reaches remotes like GitHub or GitLab. Juan and Jay discuss a new single-push approval workflow in development, and where artificial intelligence (AI) tools help — and where they still fall short — in software architecture and system design.</p>

<p>Juan also shares his path from Major League Hacking (MLH) Fellow to full-time GitProxy maintainer in under two years, the mindset shift required to go from writing code to being responsible for reviewing other people's code, working through imposter syndrome as a new maintainer, and practical advice for engineers applying to the MLH Fellowship — including why a well-lit, professional video call setup matters more than people expect.</p>

<p>GitProxy - <a href="https://git-proxy.finos.org/" rel="nofollow noopener">https://git-proxy.finos.org/</a><br>
Open WebUI - <a href="https://openwebui.com/" rel="nofollow noopener">https://openwebui.com/</a><br>
MLH Fellowship - <a href="https://fellowship.mlh.com/" rel="nofollow noopener">https://fellowship.mlh.com/</a><br>
"Developers" - <a href="https://www.youtube.com/watch?v=8fcSviC7cRM" rel="nofollow noopener">https://www.youtube.com/watch?v=8fcSviC7cRM</a></p>

<p>G-Research is hiring in Dallas, TX and London, UK! Apply at <a href="https://gresearch.com/vacancies" rel="nofollow noopener">https://gresearch.com/vacancies</a>.</p>

<p>For a video version of this podcast, check out <a href="https://youtu.be/zNUTa4s0l3k" rel="nofollow noopener">https://youtu.be/zNUTa4s0l3k</a>.</p>

<p>The GR-OSS OUT Podcast is produced by Ben Wiley.</p><p>Special Guest: Juan Escalada.</p>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p>In this episode of the GR-OSS Out Podcast, host Jay Faulkner talks with Juan Escalada, maintainer of GitProxy at G-Research Open Source Software, about a serious vulnerability in GitProxy that allowed a second branch push to bypass every security check the tool was designed to enforce.</p>

<p>Juan explains how the bug was found through a security audit, why it went unnoticed in production for years, and how the G-Research team handled responsible disclosure — being transparent about the flaw even when it wasn't the easiest choice from a marketing standpoint.</p>

<p>The conversation also covers how GitProxy works as a network-level proxy for Git requests, unpacking and validating Git pack files, auditing pushes, and blocking data exfiltration before code reaches remotes like GitHub or GitLab. Juan and Jay discuss a new single-push approval workflow in development, and where artificial intelligence (AI) tools help — and where they still fall short — in software architecture and system design.</p>

<p>Juan also shares his path from Major League Hacking (MLH) Fellow to full-time GitProxy maintainer in under two years, the mindset shift required to go from writing code to being responsible for reviewing other people's code, working through imposter syndrome as a new maintainer, and practical advice for engineers applying to the MLH Fellowship — including why a well-lit, professional video call setup matters more than people expect.</p>

<p>GitProxy - <a href="https://git-proxy.finos.org/" rel="nofollow noopener">https://git-proxy.finos.org/</a><br>
Open WebUI - <a href="https://openwebui.com/" rel="nofollow noopener">https://openwebui.com/</a><br>
MLH Fellowship - <a href="https://fellowship.mlh.com/" rel="nofollow noopener">https://fellowship.mlh.com/</a><br>
"Developers" - <a href="https://www.youtube.com/watch?v=8fcSviC7cRM" rel="nofollow noopener">https://www.youtube.com/watch?v=8fcSviC7cRM</a></p>

<p>G-Research is hiring in Dallas, TX and London, UK! Apply at <a href="https://gresearch.com/vacancies" rel="nofollow noopener">https://gresearch.com/vacancies</a>.</p>

<p>For a video version of this podcast, check out <a href="https://youtu.be/zNUTa4s0l3k" rel="nofollow noopener">https://youtu.be/zNUTa4s0l3k</a>.</p>

<p>The GR-OSS OUT Podcast is produced by Ben Wiley.</p><p>Special Guest: Juan Escalada.</p>]]>
  </itunes:summary>
</item>
  </channel>
</rss>
