# AI Security Shifts Open Source Strategy

**Podcast:** The Changelog: Software Development, Open Source
**Published:** 2026-09-03

## Transcript

What's up, friends?
Welcome back.
This is the changelog.
What if the majority of open source repos out there, they're already compromised and we just don't know it yet?
That is the unsettling theory.
Peter Richelson, co-founder of cow.com brings to this podcast this week.
We dig into how AI has flattened the knowledge graph so a 16 year old can vibe hack a power station as easily as their mom can vibe code.
And I always have why the reporting culture that has kept open source safe and secure all these years is collapsing under the AI generated noise, slop, whatever you want to call it.
Cow.com's move to fork its own code base and take the sensitive parts private and the eye opening reality that shipping one dollar of AI tokens for pennies on a dollar.
That is now a common startup business model.
Lots going on.
Lots changing.
A massive thank you to our friends and our partners at fly.io.
Your agents, they need computers.
My agents, they need computers.
We host everything we do on fly.io.
And you should too.
Check them out at fly.io.
Okay, let's do this.
Well, friends, this episode is brought to you by our friends at coder.com, secure environments where developers and agents work in parallel.
And I'm joined by Nikki Pike, field CTO for Coder.
Nikki, what is a field CTO?
So I get that question a lot and it's, you know, half the people understand it, half the people don't.
So a field CTO, I describe it very simply as we're DevRel for the C-suite.
So we provide a bridge between the customer voice, between the C-suite and the managers and the leadership teams of our customers back into our product.
And then we go through and we help.
enable our teams to have the same message to make sure that the message is correct and that we're building on something that people actually want, not just something that we think they want.
Okay, so we're taking the laptop away from the developer.
Not really, though.
We're putting them in a cloud development environment, a secure environment where they can work with their agents in parallel.
These are blessed environments.
What's wrong with the laptop?
The laptop is the trap here.
And not only because the fact that it could be stolen, you could lose it, it breaks, and you're out of work while you're waiting for a new one.
But there's also just the consistency that you got there.
We all know developers.
Developers are going to be looking for some of the latest and greatest.
And if you're not really controlling how they get out there, that's where you get this.
It works on my machine.
It doesn't work in production.
It doesn't work anywhere else because you don't have that consistency.
You don't have that ability to really standardize what that environment looks like.
And this is a problem not only for new people coming in, you know, the onboarding statement is average, I think, is like four to five weeks for a new employee to really get their local laptop set up and ready to start doing their first time of code.
And, you know, the time to first commit is a metric that almost everybody knows.
And the reason they can't do that is because there's a lot of tribal knowledge out there.
They got to go talk to other developers.
What are we using?
Where do we get our dependencies?
Are we getting?
them from public?
Are we getting them from private repositories?
But there's also the security and the supply chain aspect of this.
When you have local machines out there, look at like the Shai Halud, you know, that virus that went out not long ago.
This was a compromise of the NPM public repositories.
They went and downloaded things.
NPM did what it did.
Next thing you know, you're compromised.
But when you use something like what we're doing with cloud development environments, then you can mandate and you can put restrictions on there to say, hey, you can only go get your packages from our private repo.
Those packages are expected to have been thoroughly vetted.
We know that they're clean.
Now, does this stop everything like Shai Halud?
No.
If that compromised package gets into your private repo, you can still have that.
But it really reduces the surface area of the attack.
And it also reduces the blast area of the compromise should it happen.
Because if your laptop gets compromised and you have to kill the laptop for whatever reason, that's weeks out of work while you're either fixing that or you're getting a new laptop in.
The cloud development environments allows you to kill that.
start back up fresh and you're back and running in five minutes.
You don't have to wait all that time.
Well, friends, the first step is to go to coder.com, install Coder, self-hosted environments for your teams to enjoy, to standardize around, and it's open source.
So you can try it out today.
Once again, coder.com.
Well, friends, I'm here with an old friend.
It's been a while.
It's been too long, Pierre.
Wait a minute.
But it was, we were users of Calendly.
And when I say we, I mean the organization ChangeLog.
And Calendly has been around for a while, but they had changed.
They weren't working.
I mean, a lot of different stuff, which I'm sure you're aware of.
But one of the things, one of the undercurrents, the themes of that podcast was it is about time.
And so you know this very well because you probably live, eat, and breathe all the things around time.
being one of the co-founders of Cal.com.
But thank you for coming back on.
And yes, it is about time.
Alan, thank you so much.
It's been time and we need to make more time.
I think it was right around the time when we bought Cal.com, which may or may not be four years ago or three years ago.
Time is a weird concept.
It is.
So yeah, thank you for having me again.
I'm excited.
And I guess slight full disclosure.
I am a very small check investor in Cal, a very small seed investor through, I think, your AngelList stuff that you had way back.
And that's how much I believed in it because I was like, okay, I think even then, if I'm recalling correctly, because I'm trying to go back in my own memory, open source was core to your mission.
You've been open source for a very long time.
Your commercial product is probably licensed differently, which I'm not familiar with.
exactly which license you chose and how that sliced out.
I know things are changing even too this year around open source.
I'm sure you have thoughts on that.
So I'm happy to go wherever you want to, but yeah, big fan of cow.com user daily of cow.com and it's been too long to catch up.
And I'm sure that this new era of cows can be different.
I suppose in this next era of agents where you probably have a lot of folks using agents to act on their behalf, Maybe create events, manage their availability, even book time with someone.
What is it like in this world that we're in with agents running amok or maybe not amok in this era for you?
I think all the cards have been shuffled and nobody knows what's coming next.
I think I don't think there's a single person who can predict what.
The outcome is going to be like predicting how a certain stock goes, like that person is a liar.
You can never really say what's going to happen.
But one thing for sure is that I think a lot of things are happening that we could not predict as easily as before.
Like usually you start a SaaS company, you have a playbook, you get from zero to 1 million, from 1 to 10 million, from 10 to 100 million.
There's certain pattern matching and playbooks, et cetera.
I don't think any of that works anymore.
And even when it comes to how to, you know, build in public or how to build open source, how to build, you know, the safest software or the fastest growing software, like everything has been reshuffled.
I think about seven months ago, we joked that Dario said, like in six months from now, everybody will be using AI agents to write code.
I have not written a line of code like in.
And same goes to our entire engineering team.
It's all code, code gen and AI agent assistant.
And so it's like that prediction was so whack seven months ago and everybody was laughing at it.
And now it's just like, it's the technologies here.
Right.
And so the question is like, what, what else will change in terms of.
And I can only focus on startups.
I don't want to touch broader society aspects of what's the meaning of jobs and work.
I don't want to touch that.
But I think for startups, it's a really weird time right now.
A time that you could never really predict before.
I mean, startups are always a weird journey.
But now it feels like extra.
volatile, I'd say.
And I think to get to your point, to open source, and I think open source multiplies that by like a factor of 10.
Like you're basically drinking from the firehalls because, you know, when you have a private source, a closed source business, you're the only one committing to it.
There's no such thing as a public repository where people can like look inside and contribute, et cetera, et cetera.
For open source businesses, and I strictly focus on commercial open source, you just have so much noise.
And like back in the days, it was like if somebody opens a pull request, you would immediately know, OK, it's black and white.
Either it's a well thought out pull request and you can with tests and everything and well thought out structure or it's whack.
And if it's whack, you close it.
And it's like.
Anyone can look at it and be like, okay, yeah, this is worth closing.
That one's worth reviewing.
And then you build on top of that and you engage with the author.
Nowadays, everything looks the same.
Like you get a pull request and it's always written by cloud code or by maybe codecs or maybe if you're lucky by some other coding assistant, right?
But it's like back in the days you had a thousand open source.
contributors and you would have a thousand opinions right and one person would do something and then the other person would like reject that idea and now you just have a thousand people using two different coding assistants right and so it's like the this whole notion of um like the best idea wins it's like the best large language model wins but you only have or maybe the best prompt given to that large language model wins because there's still some variation among prompts right but like um It's really, really hard to distill what should be merged into the project and whatnot.
And then what's even worse is that like the confidence of that pull request is so high because the large language model is like, here's the best thing delivered to you on a golden plate.
And then you start to peel off the layers of the on-the-end and you're like, wow, even these tests are like hallucinated.
Like none of this makes sense.
Like it looks so real, right?
wow, this is like the best thing ever.
And then you start to run it and you're like, wait, why is that thing hard coded?
Like, you know, like so many question marks and it's like, you're like, why am I even reviewing this?
And so imagine being a commercial open source company.
There's so many tweets out there.
We don't even need to reference one.
There's so many, just search for like open source and AI.
And they're like shutting down external pull requests.
And having this like vouch system where only like really close people who went through like multiple rounds of interviews are able to commit to the repository because it's just so much AI slop, like literally AI coded slop being thrown at your repository.
So that's problem number one.
That's why I'm saying like drinking from the fire hose.
Imagine you have one cracked engineer on cloud code, like spamming your private repository.
Okay, now have a hundred of those who just...
And some of these pull requests are literally just like, hey, Claude, can you fix this GitHub issue for me?
And then they open a pull request.
And I'm like, okay, but thanks, but I could have done that.
Where's your added knowledge?
There's no added knowledge, and you're just essentially adding more slop to the code base.
So it's really hard.
That's problem number one.
I'm happy to go over many more problems.
I was talking to a friend of mine, Adam Jacob.
Did you know Adam Jacob by any chance?
Is he a name you know?
Jacob.
He's famous for being the founder of Chef and maybe infamously being the founder of Chef.
If he was here, he'd probably be laughing at this moment.
But he created a company called System Initiative.
Yes, back here.
And they had begun to rethink.
CI, no, sorry, not CI, but they began to rethink infrastructure.
It was very visual, very innovative, but they focused on this visual layer, and this is pre-AI, and obviously we know how things have played out.
And so they've sort of failed product market fit, but a lot of the ideas were still really good, and they parlayed a lot of that good stuff into what's now called Swamp.Club, and they are AGPL v3 open-sourced.
Yep, same.
But very specifically, they are open source but not open to contributions.
They do issue-based contributions now.
Is this where you're thinking of like, hey, you can file an issue, you can file a bug, you can file your concerns, but we'll never accept a pull request ever?
That's fine.
I mean I think – so here's my current issue with everything open source.
We're clearly training AI.
That's okay.
I mean, that's kind of like the AI companies are already giving open source companies tons of free tokens, which is, you know, great.
Like I have a free thought max.
I have a free codex.
I'm very grateful for that.
I understand that we are producing the code that they are training the next large language model on.
And that's, I think it's fine.
I mean, it's still violating the license, I guess, but, um, But I think the problem is that when entire open source repositories, as it is right now, gets overwhelmed with slop, it just destroys code quality.
I mean, look, it's still our job as maintainers to review and approve and merge and change pull requests.
So it's still our job to...
to make sure the quality is high.
But it's just so much more work now to differentiate between bad PR and good PR that it's simply not possible, like humanly possible.
And I know Peter from Open Claw said he's not reading his own diffs anymore, like his own codex PRs.
I don't think necessarily that that's the solution.
that we just close our eyes and hope for the best and have tests, etc.
Because there's this graphic that was like the moment you introduced Slop to your codebase, now the coding agent looks at your existing project and then adopts bad practices.
And it's kind of like a recursive loop of poo, right?
Like it just gets worse and worse over time.
Same thing happens with large language models, right?
The worst quality...
of an open source repository, the worse AI will be in the future learning from that bad code, right?
And so that's another issue I have with open source where if you cannot get the resources in place to actually have really, really high quality, and bear in mind, that means you need to end up hiring really like IC5, IC7 level people who know what they're doing.
You hire a generic IC1, IC2, IC3, chances are they will be using cloud code and they're incentivized to use cloud code because that's just how the whole industry works today.
And that's okay.
I'm not saying that's bad.
But you still need these, sorry to say this, studied computer scientists who know what ON is.
And a lot of them don't.
And so, yeah, it's not a great outlook.
Slop gets multiplied, you know.
So I think the whole training aspect and the, you know, code and public aspect is really, really becoming an issue.
Yeah.
As you're speaking about your concerns and challenges, I'm looking at cow.com's open source repository, github.com slash cow.com slash cow.com.
And I'm on the pull requests.
tab and you can probably see there's just an immense, I mean, more than you would probably ever want to or be able to merge.
No, there's no chance.
There's no chance we will get to the bottom of this.
It's just, so it's, well, and this also hurts the community, right?
Like people expect to get the same level of treatment for like a one line, hey, Claude, please fix issue 115.
Then someone who's investing deep knowledge and time and resources into making something better that they feel deserves to be emerged.
So it's like, it's almost like, how would you describe this best?
Like the best way it's, it's like, it's like mass propaganda where you, where you, where you just post so much misinformation that it's just impossible to know what's the truth and what's not, because you're just drowning in the sea of everything's fake.
And then the reality just gets murky.
Right.
And the same with poll requests, like you just don't know what's good anymore when everything looks equally good.
And then there's like a stellar PR and then the rest is just, uh, two line prompts from Claude, you know?
So it's like, It's really tough.
I don't even envy freemium open source maintainers who back in the days would be happy.
You would be happy for every pull request that would come in.
You would be, yay.
It's just my stuff.
I could change it.
Yeah, let's do it.
When we first had a conversation, we probably had 20 open pull requests.
And then when you had like suddenly you had five more, you'd be like, whoa, where did they come from?
And you would reach out to these people and be like, oh my God, thank you so much for contributing.
This has been a blast, et cetera, et cetera.
And it pains me because also this is another problem that people are facing that they think they are more likely to get hired if they can show open source contributions.
So now their entire pipeline is, let me find the top 10 repositories.
orchestrate 12 different agents and they're all trying to find different issues.
Like basically the, the cloud instruction is find the most uploaded issue and then submit a PR and these five different, it's almost like you're spamming your, your CV, which is also really terrible strategy, by the way, into like hundreds of companies and trying to hope one of them sticks.
And then your AI agent comes back with like, oh, I've opened 20 different pull requests in these and these and these different repositories.
Does that make you more likely to get hired?
I don't know.
So it's weird.
It's a really weird time.
I'm not saying there's a – this is – it's weird.
It's weird.
We're really struggling.
We're really struggling.
Yeah.
Well, I mean – so let me – I didn't say the number.
So you've got 358 pull requests.
No, sorry, 356.
Yes.
And that's still a lot.
Even 358 is, I mean, it's two more.
It's a lot of dramatic difference there between 356 and 358, but that's a dramatic amount of pull requests.
If that were my pull request inbox, I would just say inbox zero it and just cancel it, right?
I mean.
Nuke it.
Or just literally.
cancel the PR tab altogether, which I think is kind of what I was mentioning before, Adam Jacob, his, his philosophy was swamp.club.
And that is the URL swamp.club.
It's the coolest thing ever.
And you guys check it out.
They're just like, forget it.
We're not going to do it.
You know, and there, I don't think their, their problem was the amount of poor requests or even the poor request that would be, or likely be a slop.
It was more like, we know we're building.
We don't, we want to build.
We're happy to take your ideas.
We just don't want your code.
We want code that we would write that matches our style of code that our engineers can curate, whether it's with an agent or not.
It matches our style.
It matches our lingo.
It goes at our pace.
It fixes our problems that we think are worth fixing.
We're happy to hear your ideas.
We want you to use Swamp, but it's issue-based co-contributions, and you'll give us the problem or the challenge.
or the solution in prose, and they may even bring that into context behind the scenes.
And they may even write a prompt.
And they may even write the initial prompt that starts the journey.
I agree.
So there are clearly, there's multiple reasons and benefits to be open source, right?
Like some things simply have to be open source.
React.js has to be open source.
JavaScript has to be open source.
Python has to be open source.
Just to run.
the thing.
Cloud.com necessarily doesn't have to be open source, right?
So we've been open source for many different reasons, but in order to run it, that's not why we open source, right?
We're not a JavaScript framework.
We're not a UI library.
So for us, the pitch and the idea was always like build in public, build trust, build them.
And then another thing, build the most secure code base because I would say up until January 26, I would say open source is always more secure than closed source.
Like I would stand by that statement.
And that's the problem.
Today, I no longer think that.
Right.
So like the pendulum has swung, you know, this is like very safe open source because bear in mind.
When you were open source, you had security researchers making really good PRs, fixing the holes, fixing vulnerabilities, reporting vulnerabilities.
There was a reporting culture.
The reporting culture no longer exists.
99% of the reportings we get are AI generated.
Like we have an inbox security at cal.com that people send vulnerabilities.
And 99% of them are AI generated, like including that email that sends it.
Because people.
are spamming repositories and half of those vulnerabilities are also hallucinated.
Like they just simply don't exist.
You reproduce it and it's not there or it got something wrong and it's using the wrong API endpoint.
And so the culture of like open source makes you more secure because you have actual human beings who know what they're doing, checking your code base has kind of fallen behind.
And then At the same time, so that's gone.
And then at the same time, the autonomous attacking tools have gotten so good that the amount of knowledge needed to attack a repository is basically can you run a shell command in your terminal, right?
So like we went from pen testing requires crazy amounts of tooling and knowledge and reverse engineering of APIs and a man in the middle attacks and yada, yada, yada.
So much work had to go into basically finding and abusing vulnerability.
Let's say you're a black hat hacker, right?
Let's say you are an evil person.
You want to extort people.
It was really hard.
You had to be really good.
These are really smart people who would execute those attacks.
Nowadays, Maybe not with cloud because of all the security features, but there are large language models out there that are so good at pen testing and cloud security, to be honest, of their product, that it's really easy to find dormant vulnerabilities.
Like Firefox had like 12 P0 vulnerabilities reported by AI.
React, react.
React had vulnerabilities found by AI.
Next.js had its own fair shares of vulnerabilities reported by AI.
So it's like, we're really in trouble because I'm not saying our engineering team is flawless from pre-AI.
Like, obviously this is not a AI versus pre-AI code, but the amount of money, resources, and talent to find and abuse vulnerabilities has like, a hundred X in terms of ease of use, right?
And so you're giving basically evil people a single prompt in their terminal to find and abuse open source repositories.
So the whole pendulum of like, oh, we're open source, we're more secure, has completely swung in the other direction where it's like, wow, this is so easy to hack any open source repository.
My theory is that the majority of open source repositories are compromised right now.
We just don't know yet.
Firefox has 12 P0 vulnerabilities.
What do you think your open source repository is looking like?
You know?
Yeah, that's funny.
It's really grim.
We just had that one of the more recent ones was Lite LLM.
It was compromised by supply chain attack.
I mean, that was even more.
One, it was malicious in how it executed it, but how they got there was really interesting.
The social engineering behind it, or even just getting the keys and stuff like that.
And using the blessed pipeline to get the thing in the PyPy, that was really interesting.
And we're seeing that more and more and more because there's always been holes, right?
I know what you're trying to say too.
There's always been holes and it's not a then versus now kind of thing.
It's that now the holes.
The execution layer is so much more efficient.
Right.
Well, the tool is now more evenly distributed.
So the knowledge graph has kind of come down to every human being that is in some sort of first world scenario that can afford 20 bucks a month, maybe even the free version of it.
There's the same access to the same tool that the world's greatest engineers at some of the biggest companies are using.
We're all using a version of the similar and same tool.
And so the knowledge graph has kind of flattened.
dramatically and you're right the bad actors now have the same thing and not only do they have the same thing it's a faster tool than we've ever been able to script before we've always been able to script bash has always been there and sure it's always been fast on any given cpu but now the ability to write it and infiltrate and to just pen test Security research is called this Vibe hacking because you're no longer knowing what you're doing.
Like you're literally just instructing the agent the same way you have Vibe coding.
And now like everyone's everyone's neighbor is Vibe coding their iOS apps, which, by the way, is great.
Like democratizing access to technology, big fan.
But like what happens when the same like when the mother is Vibe coding an iOS app and then the 16 year old son is Vibe hacking.
the power station nearby, right?
Like that's not great.
So the, yeah, as you said correctly, like the, the, the access to technology also means that like malicious hackers have like, they, they are so happy about all of this, right?
They, it's, it's like a birthday present.
Like, what do you, what do you mean?
I don't, I no longer need to, you know, do spend 16 hours studying the code base.
I can just have an AI find all the holes for me.
That's awesome.
Here's my Bitcoin.
address, pay me money, otherwise I'll publish your data on the dark web.
Like, yoo-hoo, yay, that's great.
And even that is probably fully autonomously executed, including sending the email and opening the wallet and checking whether the funds got received.
It's a great situation we're in here.
You seem very grim and not very excited about the future of open source.
Would you agree with that?
Do you think things are just in jeopardy or what?
I think I would probably summarize this like if you run a commercial open source business, you have a huge target on your head because you are a business and a business means you have customers and the customers mean you have sensitive data and you can potentially be extorted.
If you run an open source free GitHub project, even if you run OpenClaw, like OpenClaw does not have.
an enterprise edition that they sell to Fortune 500 that runs on the same code base.
Even if they had to, they would probably not publish it on the same GitHub repo.
So it's like, if you run a UI framework, a library that, I don't know, helps you work with time zones, like you're fine, like stay open source.
Well, unless you accidentally import an NPM package that completely compromises your project, which will happen.
So that's another attack vector, obviously.
But any business today that has an open source, let's call it this way, any open source project that eventually makes a database call, you are in trouble.
And I'm saying this after five years of being open source and 15 years in the industry, you should probably take your project private and rewrite everything that touches off database.
encryption, which is what we're doing now as Cal.com.
This has been a big change.
We've been doing this under the hood for quite some time, but basically starting 15th of April, we're taking the commercial version private.
So we still have the community version, fully open source.
You can use it at your own risk.
You can self-host it.
You can run it on your own infrastructure, ideally behind many firewalls.
The same code base that runs on app.cal.com will no longer be publicly accessible because it's just, it's too risky for us.
Like we have, we have a commitment to open source, but we also have a commitment to every single of our customers.
And given this like pendulum swing, we just, that the risk reward ratio just really sucks.
Yeah.
Is this, is the change, I understand what the change is predicated on, but is it because the visibility into the flaws are more visible now because the tool is better and faster?
Is that one of the kind of core reasons to change?
So the security researchers we spoke to, right, we have a couple of those.
And obviously, there's also the good people helping you with providing tools to find vulnerabilities before the black hackers.
But everybody says if you have an open source repo, you're like five to 10 times easier to.
to hack than a closed source repository.
Right?
So think about it, five to 10 times, it's not like 10, 15%, it's like five to 10 times.
That's a big delta.
And so the reason it's so much easier is it's called black box hacking.
Like you basically need to guess and reverse engineer, like you call an API endpoint and you try to guess them at like, what does it do?
How could I attack this?
With open source, you literally see the backend.
You see the function call.
You see, is this an ID or R or whatever?
Is there something else that I can, like, you know, is there a way I can inject a script or whatsoever?
And again, pre-AI, you would need to spend 8, 16, 20 hours to research and study every single function call and find these things, you know, manually.
And that's what good security researchers would do and they would get a bounty for.
And that's what black hat hackers would do.
And typically speaking, sorry to say this, the smart ethical hackers are faster and better than the script kiddies who just want to extort you some Bitcoin.
That's just facts.
That's always been facts, right?
Like an honorable security researcher who's a white hat hacker who gives you bounties is always more intelligent.
then some dumbass sitting in some random kitchen hacking your software, right?
That's just always facts.
But now, again, with AI, it doesn't matter because both are just putting the same prompt, find a vulnerability in this and this and that repository and run the same prompt.
And guess what?
The black hat hacker is usually fast because they have an incentive, right?
They have an immediate extortion incentive to hack and blackmail.
That's a big problem, right?
Yeah, I would be really cautious if you have a repository that has a database that has customers in that database to run that out in public.
And that doesn't mean you should close your open source.
We're not shutting down our repository.
I mean, heck, it's an amazing piece of software that we've published, but it just means that you need to internally fork your existing code.
and just make sure that you just rewrite every single function call that is vulnerable.
Like that is, you know, hackable.
Don't care about some random front-end library.
That's fine.
Like a drag-and-drop component, keep that.
But like the way you do auth, the way you do database calls, the way maybe even rewrite your entire middle layer and Prisma calls, everything.
Like probably...
like start today or start yesterday and take all of that private.
It's just not worth the risk until that whole pendulum swings back into security, which, you know, could happen, could also not happen.
It's just, it's, it's, it's, yeah, we don't know.
We really don't know.
Well, friends, I'm here with the CTO of BuildKite and one of the most challenging problems of modern era software development is continuous integration and continuous delivery.
And so Lachlan Donald, Bill Kite, CTO.
What are you thinking about today's teams, the challenges they face, the speeds at which they're developing new features, new code?
It is just overwhelming.
How do you all think about that?
Such a good question.
It's the question everyone's asking right now.
All of our big customers are asking us at the minute, like, you know, if we 5 or 10x our throughput this year or 1,000x it, what breaks and when?
And, you know, my answer is...
Kind of same as it's been for the past 20 years, which is that the bottleneck is still trying to integrate those code changes in and then deploy them and check they work and then keep them working as you keep throwing more and more code at it.
I think a lot of the fundamentals are the same, but we're just 1000xing the speed of it.
And, you know, that changes nearly every variable.
Yeah, for sure.
OK, so where does BuildKite thrive?
What particular type of team?
or enterprise do you thrive in?
The area that Billkite has always thrived in is like this like fastest moving tech companies of the world.
Like we've been disproportionately successful in that small niche, the kind of Shopify class, Uber class.
you know, open AI class of folks that have this key problem around iterating really, really fast.
And, you know, the thing about all of those folks is they all have subtly different needs, subtly different problems.
And so we've tended historically towards building like really well engineered Lego blocks that scale like orders of magnitude more than.
what our nearest competitor does.
So, you know, I think that that puts our system in this tension where, you know, you've got to spend some time assembling those building blocks, those Lego blocks to get the thing that you want.
But the end result is...
far and away more performant and scalable and the experience is better than what you get from something that's off the shelf.
So I think we've started from a position of really well engineered Lego blocks and then are kind of working backwards towards kind of creating the thing that scales down to a startup that starts with one person and 10 agents next week.
Well, friends, go to buildkite.com.
That's buildkite, K-I-T-E dot com.
You deserve better CI.
Engineer for the frontier we are all facing, trusted by the teams setting the pace.
Again, buildkite.com.
Once again, buildkite.com.
So the way you're, if I understand correctly what you just said, that the mechanics of how you're making this change, the change, we understand what the change is influenced by.
But then on the how, you're saying to internally fork, and in your case, your commercial open source company.
And so you've had all of your code out there.
Your open source has been licensed one way, but if you go a certain way, there are certain features that were always available, open and open source, source available that you can see.
You're saying that you're changing that so that all of that code base will remain there.
The license of free and open source will remain the same, but internally your mechanism is to fork it and rewrite the areas, the surface areas that are at risk or at most risk.
Yeah, correct.
And we also obviously point the production URL to the private repository, right?
Right.
Because what you see on GitHub today is what we've run on the website.
That's just how open source works, right?
That was the whole point.
You see the code that runs my service.
That was the whole spiel.
So that spiel is no longer safe enough to be valuable for your customers.
It's an unnecessary attack vector.
So that doesn't mean we're no longer open source.
We are still open source.
It's just that we have an internal fork the same way other many companies like WordPress.com is an internal fork of WordPress.org.
It's still WordPress, uses the same plugin system.
But if you sign into WordPress.com today, it's a different experience than if you get the open source WordPress.
So they kind of like did that change.
probably more from a commercial point of view, not from a security point of view, but I think they internally most definitely have different things in their off system than what's out there, which I don't blame them.
But the narrative of like one code base for everyone, you know, self-hosting in production environment just no longer makes sense.
It's just, it's from a security point of view, it's...
It went from, wow, this is safe because we're open source to, is that really the smartest, safest decision you should make as a business that has customers and that you want to keep them safe, you know?
Yeah.
I guess the question might be, why even remain open source at all?
And I don't mean that as like anti-open source.
I mean, more from a chore standpoint.
So if you've got to fork your own code base and now you don't want your vulnerabilities out there, so that means there's a buffer layer between what is open source and what is closed source, i.e.
the fork that you have internally, the chore must be to keep those two code bases even remotely in sync and not have developer gymnastics playing around.
What's the point of open source then for a commercial open source company that has been in your shoes but you're not making this change?
I mean, it's a really terrible situation.
You know, it's like, yeah, pick your poison.
I would argue the reason to keep an open source project, and by the way, we're also rebranding it to cal.diy.
We got that domain, so like do it yourself, essentially.
Oh, I like that.
It's a whole...
There's going to be big red letters like use at your own risk, not production ready.
Like you can self-host this for your whatever hobby or maybe small business.
I think the benefit is if people end up self-hosting a quote unquote community edition, it's they are not going to be the one being hacked.
Right.
Like it's us.
It's the largest company that gets the attack.
The one with the most money, the most reputation.
Your neighbor barber who self-hosts Cal.DIY, like A, you need to find that server.
B, you need to know exactly who you're targeting, who you're like.
It's kind of like security by distribution, right?
Like when you're self-hosting, you're not going to be the target unless it's like a very easy to attack multiple.
multiple nodes in a way.
Like if every node runs the same software, then you do like this mass attack.
But it's just not commercially viable for hackers to hack your neighbor's barbershop.
So theoretically speaking, yes, the Cal.DIY version will have the code base off today, right?
Potentially, we don't even know if it's insecure.
We just know it's out there.
But let's say it's slightly less secure than the private fork.
Sure.
But it gains its security by being just so irrelevant in terms of distribution, right?
Like five people here, 10 people there, five people here, one person there.
So you're kind of like gaining that security back by just being more like less of a target, you know, less of a target on your back.
And then at the same time, we can always obviously, and I'm only strictly talking about like auth and database and and middle layer, et cetera.
Like if the community builds great features, we can, we can adopt them and credit them.
If we build sick features, which we do, we push them back into the open source community edition.
So I hope to keep that relationship strong the same way WordPress has been doing it for many years.
So it's not like a unique idea.
Like we've always had private and public folks of open source projects.
Docker has its own enterprise edition.
That's private source.
Yeah.
But like, I think, and if I'm being honest with you, all of these forex have been for commercial reasons.
Some investor has pushed you, some IPO, some bank looked at you and be like, we need some proprietary code because of whatsoever.
So it looks better in our brochure.
But trust me with my fullest heart, this is not a commercial.
Like we are growing like 7% to 12% month over month.
We are not in any way short on cash.
We have no investors who are bullying us to go private source.
We have the most open source friendly investors on our cap table.
We had to convince them this is the right decision.
This is like a nuclear problem for commercial open source.
And so I wish it was a commercial decision because then I can say, okay, this is only affecting us.
But this is affecting the entire industry.
This is like a...
Yeah, like the quantum computing cracks encryption type of level, you know?
Yeah, that quantum, what do they call that?
Quantum safe or quantum ready in terms of security and whatnot.
Exactly.
Yeah, exactly.
I mean, that's a really insane thing too.
What other examples can you give?
I know that you kind of give a couple, but what are some explicit examples of other commercial open source companies that think like you do or have the same problems you do?
And can you enumerate their challenge in the public that's being showcased?
Well, I can, I can, I have many conversations, you know, that I really cannot make public because of security and like, and just the risk, the inherent risk.
What's on X?
What do you see on X?
What would you retweet?
Well, I mean, I can definitely talk about public situations, right?
Like there's, and I also don't want to throw anyone under the bus, but there's, you know, there's.
There's tooling around logging, like log systems that log user activity.
Those products are usually open source because it's a developer package you need to import the SDK.
So those have been hacked by AI, which is really bad because now that attacker has access to all your users' actions, if that makes sense, like the events that they send.
For them, they are really screwed because they have to be open source for the sake of being a developer kid, right?
So I would say that's two companies that are directly affected and I know of.
There is a CMS, which is open source, which is really struggling because when you're a CMS, you simply cannot expose your...
internal systems to the world.
I mean, just think about how much knowledge is locked up in a, in a CMS and, or the risk of, of, of, um, somebody, I don't know, like imagine you get right access to someone's CMS and you're publishing something on Nike.com, you know, like that's just not great.
Um, so, uh, there's a, there's a lot of commercial open source businesses out there that, um, that have to be open source in order to, to run.
Um, In that regard, we're almost somewhat lucky that we don't depend as much as others to be self-hostable.
Again, 99% of our revenue comes from our SaaS, app.cal.com.
It's not like we sell a code snippet that people inject in their business.
So yeah, and then there's a couple of payment providers that call themselves the open source version of Stripe.
Obviously, anything that touches payments is hypercritical.
You know, that's always tricky.
I don't even want to talk about crypto because I really don't like crypto, but all of these crypto projects are being cracked open that are open source.
It's a wild west out there.
And so if you were a doctor, Dr.
Peer, your prescription for these commercial open source companies in these high impact areas, is to rethink their model and follow you in terms of forking internally, creating a new relationship with your open source version, if you even keep it.
In your case, you're keeping it, you know, cow.dyi or DIY, which I think is super cool.
I had a little case of dyslexia there for a moment there.
But nonetheless, cow.dyi.
I did it again.
DIY.
DIY.
DIY.
Cow.DIY.
Do it yourself.
Come on, Adam.
Well, on the bright side, on the bright side.
What's your prescription?
Yeah, on the bright side and maybe on the bad side, like what's open source stays open source, right?
Like we're not disappearing tomorrow.
You're not red pulling.
Yeah.
Red shifting.
More like cleaning the rug and making sure nobody...
Okay, vacuuming.
We're vacuuming the rug.
We're vacuuming the rug and closing the door to access it.
You can look at it.
It's beautiful.
It's a beautiful rug, but you can no longer step on it.
No, because look, there's so many folks out there.
Telecom is not going anywhere.
We can physically not get rid of the code.
What we can do is move forward gracefully and make sure that the most vulnerable pieces of any piece of software is not public.
I think that's a very fair statement to say because back in the days you would have those public because it's just really hard to hack them.
Now it's easy to hack.
Thereby, I need to take these things private.
And by the way, Having private code does not protect you from being hacked.
Nobody thinks that that's the golden solution.
But if a security researcher, if many security researchers say it's five to ten times easier to hack you when you're open source, you have to listen to the security experts.
If you don't listen to them, you're literally, well, probably you could use that as a way to even go to jail if you get hacked.
I don't know.
I'm not a lawyer, but if you ignore...
Multiple warnings from experts.
You should probably rethink why you're even the co-founder of the business, right?
So my recommendation, my medicine is first, don't freak out.
There's a high chance you're not compromised.
Most likely you run a really small project.
You're not a big target.
Second is to run many of these AI scanning.
tools and just see what the blast radius is today.
Most likely it is quite high.
Like every single project I've talked to was experiencing an uptick of reports by these AI tools by like tenfold.
Like it's just messy.
It's really bad.
Turns out humans are really bad at coding for many years, including everything before AI.
So chances are you just have vulnerabilities.
That's just a fact.
And then my recommendation would be to at least temporarily go private and work on all these vulnerabilities because here's another problem.
And this really, right?
When there's a hacker who actually wants to compromise your project, they are also running code scans against your own pull requests, right?
Wow, yeah.
So they, today, probably, if let's say you really want to, screw someone, right?
You would run code scans against their own pull requests.
And if you detect a pull request that fixes a previously known vulnerability that you potentially found already, or maybe not, right?
Like an AI can understand whether a pull request is a feature or a fix of a vulnerability, right?
Like you give an AI just random code and ask it like, what is this PR about?
And it will tell you this is fixing a vulnerability.
So they're using that.
I mean, whatever is technically possible will happen, right?
I'm not making this up.
I don't know personally any hackers, but that's what I would do if I was evil.
You would scan that PR.
You would identify this PR is fixing the vulnerability.
And in that second, I would abuse that vulnerability and send them an extortion letter, right?
That's just the scary part, right?
And how do you think, Pierre?
Right?
I should not become a Marvel evil, Marvel super villain.
But anyway, again, everything that's technically possible is out there and is happening.
So I'm not giving you the playbook.
That's literally what's probably discussed in these dark web forums.
And so your best shot today is to take the repo private, fix all of these things in private, and then merge it back into one.
you know, chunk.
That's just your best.
Like, yeah, squash that commit.
Don't give them a path to the change.
Don't, don't feed, don't feed the machine.
Don't feed the machine.
That's going to extort you for Bitcoin, you know?
Well, if I don't know you were talking about this, when you came on this podcast, I'd probably not invite you.
You got me down over here, man.
Maybe we should not, maybe we should not publish.
I mean, this is good stuff.
I think this is, this is truthful.
I mean, this is where my head's been at as well.
Yeah.
And you're bringing some new light to some things with me.
I want to go back to, if you don't mind, not so much to fully backtrack, but I want to go back to your pull request tab and not specifically just yours, but the pull request tab.
Yeah.
And the reason why, I mean, so you're seeing what you're seeing about commercial open source companies.
I don't think open source is dying.
I do think pull requests may be changing and are becoming.
not irrelevant, but just fraught with a lot of slop that people don't want to deal with.
So even projects like Ghosty, they're not taking on pull requests like they were before.
A lot of folks that, you know, like Ghosty is a great terminal and for a lot of reasons it needs to be and wants to be open source for the true nature of what open source is, but they're being open source, not open to contribution.
So I want to pose this thought experiment here.
How does this change?
Is GitHub at jeopardy in any way as a business?
Maybe not because a lot of their commercial features are on top of things that aren't there, but like if a lot of us are on GitHub because that's where open source is.
And if the relationship we have with open source changes or open source changes enough, you know, is GitHub in a risky scenario?
Because, I mean, they're banking almost everything on Copilot, right?
I mean, that's a large majority of their infrastructure, even NPM.
I know they have some changes coming out, and I'd love to talk to whomever's working at GitHub behind the scenes or in front of the scenes if there is any on NPM.
I'm not saying anything negative about those folks at all.
I just know that there's neglect.
There's neglect there around NPM.
So even one of the things that is the largest package manager and registry known to man on planet Earth is NPM.
It's so important.
I mean, that's where the Axios hack just happened, and we know how that went down, right?
Yeah.
You know, what is the picture of GitHub if all this changes?
What are your thoughts on that?
Well, I mean, it's not bright for commercial open source, I can tell you that.
So like if you obviously run packages, et cetera, freemium open source, you're probably more okayish or you build a new React alternative or self-kit, whatever, tailwind alternatives.
But GitHub obviously has to rethink its own, like, I wouldn't call it economic model, but like placed in the world with AI where, and this, I would even say this goes beyond security, way beyond security.
Because like, look, if somebody like Peter doesn't read its own diffs and the neighbor who Vibe codes its iOS app, do people really care about the source code?
Do you want to see the source code?
Like there are probably already projects out there where, the community has looked at more of your code than you yourself who published that repository.
Right.
Simply.
I mean, yeah, totally.
I mean, that that's going to happen, right.
Where the maintainers have seen less of the code base than, than the community combined.
Usually it's like the maintainer who writes the code knows the code, but now it's like, I can prompt any project and publish it on GitHub.
And then chances are I barely.
scratch the surface of the code that I've published.
Right.
It's like, as long as it works and it looks good, why would I read the code?
You know, and it's safe, safe.
So obviously distributing code almost feels like distributing binary at some point.
And GitHub wouldn't work if people just published their binaries, you know, I mean, it still works, but like.
Who's going to read that?
Or like you just put the byte code, the assembly code, whatever, the binary code up there, you know, 001001.
That's great.
Cool.
So if source code, as sad as it sounds, listen, like I'm not a fan of this, but if source code becomes unreadable because nobody knows what the f*** is doing anyway.
So if nobody knows programming anymore, if new students come out of university and they can't read source code, they don't know what it is.
They don't know what an if statement is.
They don't know what a, you know.
What point has GitHub besides being a CDN to share zip files, if zip even is around that time, or, you know, or DMG files?
Like you're basically turning into a mega upload where people just throw up all their garbage.
So, yeah, they 100% have to rethink everything about.
Like, what is the meaning of code in 2027, 2030?
What is the meaning of code in 2030, you know?
Yeah.
And then obviously it's not in any way AI first.
I mean, the fact that, you know, what I just explained, anyone can open pull requests for anyone, you know, there should be guardrails, there should be rules who can contribute.
Like we're using these third party GitHub actions that like auto close pull requests from people who are not verified.
That's all just hacks, you know?
That should be first party coming from GitHub.
Why do I have to install different third party plugins to make sure only legitimate people are opening pull requests?
That should be your job, GitHub, you know?
Well, friends, I'm back with a good friend of mine, Michael Greenwich.
Michael, I know that I love WorkOS.
Our audience may not know about WorkOS, but what are the challenges developers face starting a new project?
Choosing the right tools, choosing the right database, choosing the right auth.
Take me there.
When a developer starts a new project, the decisions that they make at the very beginning end up having long-lasting consequences.
What language you build in, what platform you build on top of, what database you choose.
These are things that are very hard to change later on.
So they have major consequences.
And especially if they limit your ability to grow and scale, at some point, as the product starts to take off, you're going to have to stop developing new product features and go re-architect or rebuild your system.
And that might...
be a killing blow right at the moment you need to accelerate.
So these decisions early on are really, really important.
And I think that's why developers gravitate towards solutions that are mature, things that they know that will scale, even things that are open source.
You're going to pick something like PlanetScale for your database provider, not because it's the cheapest or because it's the...
you know, most fun to use, but because you know it's going to be a durable provider that you can scale on for years.
And WorkOS is like that for auth.
You know, at the earliest, earliest days, if you look across all these different services, they kind of look very similar.
But at day 1,000 or day 2,000 or day 10,000, you're going to want to have made sure that you picked a platform that could scale with you.
And today WorkOS is powering auth and identity and security and permissions for all these AI companies, literally the fastest growing companies in the world, like OpenAI and Anthropic and Cursor.
perplexity.
WorkOS is under the hood there.
So I think when people pick WorkOS early on, really what they're doing is trying to pick the defaults to allow them to grow and rapidly scale.
And there's no platform other than us that's done that at that same level.
Well, friends, the next step is to go to WorkOS.com, sign up today, check it out, free for a million active users.
Try it today.
There's no excuse not to.
It is your default.
You should choose it.
So do so.
WorkOS.com.
Once again, WorkOS.com.
Did you catch that post from Mitchell Hashimoto, Bonnie Chance on X?
Can you give a recap?
I'll give you a recap.
I see so many tweets.
It wasn't long ago.
It was March 25th of this year.
And he starts it off by saying, here's what I would do if I was in charge of GitHub in this order.
And he says, establish North Star around being critical infrastructure because there's been a lot of downtime.
Yes.
They got the double nines back with the eight in front.
Yeah, he talks about coming back, establishing North Star around being critical infrastructure for agent code life cycles and determine a set of ways to measure that.
Number two was fire everyone who works on or advocates for co-pilot and shut it down.
It's not about the people.
He's trying to be kind here.
I'm sure there's many talented people.
Acquire Corsa.
Pay whatever money is possible.
I think it says buy Pierre, which is Pierre.computer.
We've talked about that on the pod before.
You may be aware of it as well.
Buy Pierre and launch agentic repo hosting as the first agentic product.
And I could paraphrase more of it if I needed to, but then the last one was reevaluate all product lines and initiatives against the new North Star, which is really predicated on being critical infrastructure.
I gave him back those nines, of course, and he says, I suspect 50% get cut to make room for the different ones.
And so, I mean, I'm not sure if he's accurate, wrong or right, but there's a lot of folks who are upset at the uptime and downtime stability of GitHub.
I mentioned before, I know they make a lot of money off GitHub Enterprise as well, but I think they're really banking on GitHub Copilot.
And I just had Burke Holland on the podcast.
He's one of the developer advocates on the GitHub Copilot team, so he's largely aware of what's going on there.
I know more Copilot advocates than Copilot users.
You know, I'm not a GitHub Copilot user.
I'm also not a here.
You know, I'm not a hater, really.
Me neither.
It's just – I don't think you're trying to be – I also don't hate polar bears.
I just don't see them on a daily basis.
Sure.
I love polar bears.
What I think is interesting, if we look back, because I've also had a podcast with Amelia Wattenberger.
And if you recall, do you know Amelia Wattenberger by any chance that name ring a bell to you?
She works on the GitHub Next team, which is where GitHub Copilot came out of.
GitHub Copilot was already in place and in motion before she got there, but she was a role.
She played a role in GitHub Next, which was sort of an offshoot of the office to the CTO at GitHub.
So it became this area to innovate.
And that office of the CTO is predicated on Jason Warner.
Jason Warner's idea was GitHub Actions.
GitHub Actions is largely why.
GitHub got acquired by Microsoft.
I'm compressing a lot of the history here just for the dovetail.
And so this GitHub Next area was this laboratory where a lot of the innovation came from.
That's where GitHub Copilot came from.
And a lot of the race and current status of the race of where we're at was, you know, around GitHub Copilot being tab completion.
They were the first.
They were the first wow factor.
And here they are, the late runner, not the front runner.
of this AI race.
Yeah, how did they lose that?
Yeah.
Yeah, it's just kind of wild to see the picture kind of come full pendulum there on that.
And, you know, I don't know.
Does Microsoft, does Microsoft has any race in the coding industry right now besides, just Copilot, right?
I mean, the story around Copilot is so, you know, the primogen.
We have Cursor, we have Codex from ChatGPG, and we have Cloud or Cloud Code.
which is primarily terminal, obviously.
And then we have, what's it called?
Windsurf, I believe.
I believe Windsurf turned into Carsh, didn't it?
No, Windsurf got acquired, but was it acquired by Microsoft?
I don't remember.
Google, I think.
There's a lot of change there.
Oh, and then there's anti-gravity.
Anyway.
And Replit.
And Replit, yeah, true.
Yeah, Replit's actually doing some pretty cool stuff.
I haven't used their stuff yet, but I know some people who are.
There is a landscape.
It's not only true, but I think what I really find sad about Microsoft is that I think they have the head screwed in the right place, but they just don't have the execution, right?
They came up with CoPilot.
They were the first investors in OpenAI, the first big ones.
They made it big.
fully banked on it and now they seem like they profit the least of it.
I'm not really sure, but I just think it is kind of wild to look back at, you know, we were all enamored with GitHub Copilot, tab completion, function completion, things like that.
And now it's not really the major player in the race, but it seems like GitHub is banking big on that.
But as a team and individuals like you are and we are that have have we're not sure of the future of GitHub.
And I don't know either.
I just don't know.
But I know that they're they seem to be largely focused on copilot and their their uptime has been down dramatically.
Now, Morton Woodward, who's a developer advocate for, you know, the dev team there, he's come out and talked about it.
Ryan Daigle.
COO, not CEO, because there is no CEO of GitHub anymore.
Came out of the woodwork and started talking on Twitter about slash X around these things.
And it's cool.
Please talk about it.
But there's something going on there and there's something changing there.
And there's Codeberg now, which I'm not even sure who's moving to Codeberg.
I think a lot of it might be potentially self-hosted.
So what keeps you at GitHub these days?
If you're not open source, if you, Cal.com, is open source, you're more dramatically open source like you were before.
What keeps GitHub your epicenter?
It's not really much of your epicenter.
I know.
And look, what happens if the user base of GitHub is agents?
It's not really a nice business.
Yeah.
You know, I struggle with that one because the reason why I struggle with that one, and maybe you can draw this line too, is largely agents, but is largely agents there on behalf of a human.
So that's where I draw the line because I've got agents and I'm a human being.
And so I have intent, right?
And those agents are acting on my behalf.
And so bots versus agents may be a little bit different.
And I'm not sure.
How do you draw the line there?
Well, how much is it a human intent if you ask Claude, like research the top 10 frameworks and then of those repositories, pick the most popular issue and open a PR for it?
Is that really your intent?
I mean, it's no different than search, right?
And search would still be, you would still say it's a top search result, right?
It's just a new search.
You're skipping a lot of intention.
That's what I'm saying.
Like your agent makes a lot of assumptions and decisions that detach you from it, I would say.
Yeah.
That line will continue to be examined and blurred.
in my opinion.
I think I sit on the side that if I were making that search and say, hey, go out and find me the top 10 repositories and help me learn how to commit a PR, I think that's still user intent.
I would probably still draw that back to user intent.
I think that's cool and I think everybody should do that.
But if that AI makes that decision for you and just makes it for you, the PR and everything, you no longer have any...
emotional connection to that.
You might not even know which repository your agent committed to.
Yeah.
I suppose if it's fully autonomous and there's no awareness and the intent is very thin, then it does get thinner.
Obviously, I think it's more like an AI agent only.
I think this whole agent thing, well, first things first, agent is a horrible name because agent theoretically means there is a persona that has its own.
objectives and autonomous decisions, right?
Everything else to me is like a human scaled with AI, right?
Like tab completion is very different to autonomous coding, right?
Like you are still writing codes, but you have auto completion.
We've had auto completion for words since 15 years.
Like that's just not that crazy, but, but I think the innovation came for coding that it was actually working and not just brambling weird shit.
But the autonomous future that a lot of people are imagining is what I just said, that you have this coding agent who wakes up at 8 a.m., well, doesn't sleep, doesn't need to, and grinds GitHub bounties, searches the web for whomever probably the most profitable agents will be hacker agents that try to extort you.
bounty versus extortion metric.
But let's say you are a white hat hacker agent.
You would probably autonomously serve the web.
You would find interesting repositories.
Maybe you are looking for repositories that your company is depending on.
You try to maybe put...
your own company policy into that fringe freemium open source project, or you want to, maybe you're trying to improve a certain library that your company depends on.
I mean, even today already, Cloud Code could analyze your code base today and it could find a potential vulnerable open source dependency you depend on.
And it would then, it could autonomously visit that repository's project and open a PR itself.
on that project trying to get your fix into it.
That is not impossible today.
I'm not sure if it's happening at scale.
It's probably happening in installation.
But theoretically speaking, your agent could hit a wall and then autonomously raise a PR in that dependencies repository.
That's no longer your decision.
Your decision was to improve your product, but the agent made the autonomous decision to go out and hunt.
and open a PR in someone else's repository.
Yeah.
That to me is very detached from tab completion.
You, Adam, wants to improve my product.
Very much.
Yeah.
So are you for that or against that then?
I mean, that seems altruistic.
Like while it may not, it's, you know, one step or two steps removed from my original intent.
Original intent is to learn about the security of my dependency graph.
And then the two steps removed is...
you know, figuring out which ones have issues and correcting them or finding a correction in somebody's PR.
Are you for that or against that?
Well, I think us as the tech community, we need to find peace with the fact that, like, even though this GitHub user has a human avatar, this GitHub user has not written a single word of that PR.
Yeah.
Right.
Because that's just a reality.
Right.
So we need to be first.
We need to be OK with that.
And then the second thing we need to make peace is did that person even think about my project when they opened this PR?
Like, are they aware of it?
Do they know me?
Do they like me?
Do they have the same ethics?
What is their altruistic intent?
Is it to improve their own dependency or is it to find a job because they ask cloud code like, hey, I'm unemployed, like find a.
best 20 repositories and get my name out there?
Or is it even trying to build a backdoor or break a feature or change a button that was previously most clicked and now it's, you know, you can also, you don't have to be a hacker to, it's not illegal to raise a PR against Cal.com that makes our product worse.
That's not illegal, right?
No.
Highly unethical, but you don't go to prison for that if you ask.
CloudCode to make Cal.com worse.
It'd be like, okie dokie.
Sure.
Let me remove the login button.
Job's done, you know?
Let's dovetail hardcore to the right, if you don't mind.
And let's talk about the success that you've had.
I mentioned the show, seed investor, very small check, of course, but I was...
Very happy to do that because, you know, I was using Calendly.
I liked Cal a lot better.
I liked your mission.
We had you on the podcast.
I liked your mission.
I liked, you know, this was a lot of the rage at the time to come out as a commercially open source company.
We both know JJ.
I think you were part of OSS Capital in terms of your initial raise and support there.
So there's some history there, but tell me about, give me as a, maybe a seed investor, give me a, give me a glimpse behind the scene of the success that.
is happening or has been happening?
Yeah.
Look, I mean, we are blessed in terms of timing and the renaissance of open source.
I believe that might even been the topic of our first conversation.
Like where do all these commercial open source startups come from?
And they're all doing great from what I've seen.
The people that I'm trying to be close to open source was almost like, what do you call it?
wished that for way too long and it was still striving.
I think now it's getting harder again.
But I think my vintage of open source companies has been pretty successful with what they're doing.
There's many good outcomes.
And look, open source is awesome.
I love open source.
I wish we would not be under this threat, which you just can't close your eyes to.
So, no, Calicom has been growing fantastically.
We're very happy.
The team's happy.
We're reaching, I'd say, like the milestones we set for us.
Very low churn, high growth, you know, SaaS, high margin SaaS.
We don't have a single AI product that's catching on, which also means we're not burning any AI tokens, which means our margins are great, still great.
It's quite funny when I talk to founders, we're like, oh my God, we're doing 5 million in AR now.
And I'm like, okay, and how much, what's the bottom line?
And like, oh, I mean, we're burning 10 million.
So it's like, okay.
Fantastic.
So it's like, I mean, look, every business is great if you're selling like a dollar worth of AI credits for 10 cents, you know, like that.
Every business is fantastic if that's your business model, right?
And you've seen this on Twitter, you know, like all of these coding assistants are like adding rate limits and reducing usage and trying to upgrade you into $200 plans.
And, you know, like the economics don't make sense in the AI space.
They don't make sense yet.
Maybe they will, but it's an Uber type thing where it's like, how is this Uber so cheap?
Well, duh, somebody's paying for it.
$15 from SF airport to the city.
Yeah.
Right.
That doesn't happen anymore, but it did.
It did.
It was fun.
Fantastic times.
I was loving it.
That was great.
That was a good time.
See, now it's like, oh gosh, 80 bucks for that ride.
Wow.
One dollar delivery door dash.
Yeah.
Right.
That was good.
I saw something recently.
They said, we'll eat.
I can't recall what it was, but I was so surprised by it.
They literally said in their marketing, we'll eat the fees.
And I'm like, that's great for marketing because your market is like sweet.
You know, this is a great carrot.
Let's chase.
Let's get some people attracted.
But you're literally telling the market we're going to lose money.
We're spending this money to get you.
We're taking the fee.
You're basically saying do not invest in this business unless you like to lose money.
Yeah, I thought it was kind of funny.
I told my wife, I'm like, babe, that basically says we're just going to lose money here to get this business.
We're going to subsidize it as marketing.
Adam, if you want to have the fastest growing startup in history.
You could launch a landing page and you say, get a cloud API key that works for half the price.
We pay 50% of it, but still pay me, right?
So you're going to have, you post this on Hacker News and you're going to make like 100 million in the first year and you're going to burn 200 million because that's the amount.
You pay 50% of it.
But you've got to be a startup making $100 million in the first year.
And you can go to every podcast and say, this is how we made $100 million in the first year without saying you burned $200 million.
But that is essentially what, sadly, a lot of startups are doing right now.
They add some flavor, some prompts, some system prompts, some UI, some sidebar, some orchestration and drag and drop.
But a lot of these startups are simply doing that, not with a 50-50 split, but maybe a 5%.
So 95 or 10% split.
So in my eyes, it's not a great business, but for some it works.
If you can raise billions of dollars, you can do that for quite some time.
You know, the one agent that hasn't done that and has done it, hasn't done it to the degree.
What am I trying to say there?
They haven't, they famously come out and said, we're not going to sell it for less than it should.
It's actually expensive.
And we're charging appropriately is our friends over at AMP.
Now they're wrapping OpenAI's APIs.
They're wrapping Anthropics APIs.
They're giving you versions of GPT 5.4 codecs, et cetera.
They're giving you versions Opus 4.5 at all the different variations of it.
And they're sprinkling their own abilities on top of that.
And AMP is, I don't know if it's Sourcegraph because that's where its roots came from, but...
What makes it so good?
I'd love to learn what makes it so good.
But AMP, have you played with AMP by any chance?
I have not, no.
Well, after this podcast, go and play with AMP.
Ampcode.com, I believe.
It was so successful for them that they spun this out of Sourcegraph.
So AMP was a subproduct of Sourcegraph, which was already largely popular and very successful.
And they built their own agent called AMP.
And it was so successful they had to like spin it to its own company.
So now it's AMP Code Inc.
or AMP Inc., one of the two, I'm not sure.
And if I have a really hard problem, I just know I want to get right, I've got to use AMP.
And they have a free model, which is paid for by ads.
And now that's changed too.
It's like $10 per day you get.
And they basically said it wasn't successful.
They actually built a $10 million per year business.
in ad sales on that and they close it down.
But like by and large, they're not subsidizing the tokens.
They're charging appropriately and profiting on it.
And they're not growing the hockey stick everybody else is, but it's still growing quite well.
Yeah.
Well, another business, yeah, I mean, exactly.
It's like how aggressive do you want to grow?
I mean, again, you can add your flavor on an AI and wrap it and make a good UI and resell it and make.
make money without losing money like it that's perfectly fine it's just yeah the i'd say the coding space is just so competitive that like nobody's really um in it for the ui it's just like where can i get the most compute for the least money um but i mean companies that have not done this also is like mid-journey you know like they've always been profitable it's a bootstrap business they never raised funding and i don't know what revenue mid-journey is today but um they found a way to profitably sell subscriptions and rate limit accordingly.
I mean, they pretty early built, I mean, they always built their own AI, right?
I feel like they've never bought other AI.
So maybe the margins make more sense for them because you, you're the, your own supplier.
You don't need to buy tokens.
You just need to buy, well, just buy infrastructure.
You have to have that inference and the infrastructure and the cost to maintain the infrastructure.
Yeah.
keep it up, supply it with more than you scale.
You're cutting out one middleman for sure, yeah.
The one with your own markup.
It is a big mess there, I think.
I mean, it's a big mess to manage, but you're sort of in charge of your own mess.
So your cost center is different.
You're not buying tokens.
You're purchasing man hours to produce and to sustain and hardware itself and managing that hardware's uptime.
Literally hardware infrastructure, like real hardware, bare metal, as they say.
Oh, wow.
Midjourney calls itself first community funded AI research lab.
That's hilarious.
I like that a lot.
We are lean, self-funded, distributed team, always hiring.
Midjourney has no investors.
We are funded by our own community.
That sounds like the community has ownership, which they do not.
break it to you but that's like saying my customers are my investors which does yeah well i mean yeah non-dilutive capital means i own the ship anyway but i mean look it works i mean look it works for them and and i think that's something like incredible that you can build ai businesses without um burning credits burning burning um the whole Anyway, how do we get there?
I mean, yeah, Telecom.
We don't sell tokens.
You still don't have an AI.
I was going to come back to you.
If you don't have an AI, where's your growth coming from?
Who would have thought people still use SaaS?
SaaS is not that.
No, I mean, it's, yeah, I think we just continue to do a good job and build a good product that people love and pay money for.
Not everything has to be AI.
Surprise.
Surprise.
Where are you, again, another pun here, but not on purpose, where are you spending your time in terms of product?
Like where is the innovation happening that contributes to growth?
What is making that happen?
I personally, I spend every day at work looking at product related topics.
So pretty much every major product decision goes over my desk or comes from my desk.
which means not only, you know, larger new initiatives, whether it's like an iOS app or a browser extension, but also looking at existing features that we need to sharpen the edges, not sharpen the edges, soften the edges, sharpen, that'll be sweet, border radius zero.
And yeah, like fix tons of bugs, make sure to, you know, get enough buy-in in the company and assign resources.
So I would say I'm mostly responsible for the product quality today.
So if there's something inherently broken, please send it to me.
I recently started to do sales again just because I enjoy doing it.
Not because it's like not because we're short staff, but because I really just want to have this conversation with customers and learn from them and understand what they...
what they go through.
It's more like a product exploration than necessarily closing the money.
That's how I spend most of my time with really just talking to customers and then trying to bring that to life.
You want to take a, I wouldn't call it a bug, a bug fix, maybe an issue.
Let's call it an issue.
Would you want to take an issue live on the air for me?
Oh, for sure.
Yeah.
For sure.
I'll spin up my cloud code and submit a PR.
So we reschedule a lot.
We have in the past.
So we either, as ChangeLog, we use Cal.com to schedule all of our podcasts, our entire workflow for creating any new event that is podcast related.
And I do as well in sales.
So all my sales calls, I do a lot of conversations with founders, CEOs, key product leaders in companies that advertise with us.
We have them on the podcast via voice.
And so we showcase who they are.
It's not just me reading an ad.
It's very unique and informative, and our audience loves that.
So I do a lot of scheduling for all the surface area of what we do here.
And so rescheduling is at the core of the crux of what we do, scheduling and also rescheduling because not everybody can show up, and we even have a reschedule, you and I did.
And so the challenge that I face, one of the challenges I face with rescheduling is, one, it works great.
And the only part that doesn't work great.
is that if I want to reschedule and my availability dictates how I can reschedule, I can't break that unless I go into the admin and create an override.
Like I know my schedule and I want to reschedule it and I want to be able to pick whatever time I want on my own schedule, not have to go jack with my availability to then have it open and create an override.
I feel like that could be a little smoother and that's been a multi-year.
because it's never been changed.
And I've never told you.
I just worked around it.
Tell me.
So here we are on the podcast.
How do you feel about that kind of change?
Have you experienced that yourself?
What do you think about that?
You know what?
I think I have this on my never-ending list of tickets for like at least a month.
And I think today is the time where I finally get to ship that.
I've experienced this myself.
I am always annoyed.
I always talk about it with the team and then some it hits the fan and it gets deprioritized.
But I do have to fix this and I do agree it's very annoying.
And we will fix that.
The UX has to be spotless though.
Maybe this week.
Keep it in the same UI that you do like a normal user would.
Don't take me back to admin.
Do it in the same reschedule.
And I'm not sure I would give that ability to the invited.
No.
Do it to the invitee.
Oh, yeah.
The one who controls the calendar.
The one who's in charge.
Yeah.
Yeah.
Because we've even had to reschedule a podcast and we largely record our podcast at two o'clock p.m.
And that's been a standard for us for a long time.
It's where we mentally block off our own day to even be present in our podcasts.
But at the same time, it may be somebody who's in Europe or maybe even Australia or New Zealand or.
South Africa or somewhere in the region where the time is far ahead, 12 to 15 hours in advance of my time here in Austin, Texas, which is Central Standard Time.
We'll want to reschedule to way out in the morning.
Same day, same concept, but I can't even do that in an easy way.
What I will tell folks is go ahead and put it on the calendar and I'll manually change it in my own calendar.
That's been okay, and I've been fine with that.
But I would say, you know, keep it in the same UI because it's a great UI.
It functions well, but recognize I'm an admin and give me a little bit more ability and maybe even warn me like, hey, you know, I don't know.
Figure it out here.
Figure it out.
But that's where it should happen.
You know what?
I just wrote this in my coding agent.
So maybe we get a PR in the next two minutes.
Man, that'd be so awesome.
That'd be so awesome.
Kick that off.
So growth is coming from just good product is what you're trying to say.
Yeah, that's exactly what we were just doing.
You know, you tell me something that's really frustrating.
I agree.
It's really frustrating.
And then it's my job to make that not so frustrating anymore.
I know you tweeted about this.
And then you just do that over and over again until people really, really like your product.
Yeah.
Make them happy.
Make them happy, right?
I know you just tweeted about this.
on March 25th, just hit six, oh no, 7 million ARR.
And I think you mentioned in the pre-call that numbers north of that number by a little bit, because your growth rate is 10, 12% per month.
You said it was the, what did the breakdown?
I mean, every, every month is different between five and 10, you know, good months and bad months, but yeah, on average, we were hoping to three X per year.
That's kind of like always been the agenda and the milestone we want to go for.
Which is, yeah.
So we are looking now at, well, soon to 8 million.
Hopefully soon to crack the 10 and open some champagne and go to bed at 12.30 instead of 10.
Three in the morning.
Will you have a party?
And can I be invited?
I'd love to come.
I'd love to celebrate.
Hopefully.
Yeah, we should.
We have a company retreat in Japan, which we're really excited about.
So maybe.
Maybe that would be sick if that overlaps with the 10 million milestone.
That would be really sweet.
That would be in June.
So April, May, June.
Yeah, maybe.
June of this year.
Okay, so you're thinking by June of 2026, potentially 10 mil ARR.
Probably not.
Probably not.
Potentially.
I would say it's in the realm of possibilities.
Okay.
What would make you grow more and what would change your growth?
Like what are the things that keep you up at night in terms of positivity and negativity?
I know open source was one of them and a threat there, and we've talked about that.
But what are the positive sides and potentially some of the negative sides that keep you up when it comes to Comic Con?
We do have large customers, right?
Like we have a lot of grassroots, but we also have large customers.
And I think there's a bit of a – like a SaaS shock going through the industry where like a lot of companies are really deeply looking at their vendor list and try to cut corners and cut costs and come with the argument like, oh, but like we're paying you too much.
We can vibe code you in a weekend.
You don't have to vibe code Cal.com.
We literally open source, just fork us.
It saves you money and tokens.
If you think that's the cost-cutting approach, like just self-host it, por favor, that's much easier.
But yeah, that's still a thing, right?
So I would say the entire SaaS industry is experiencing some sort of SaaS shock where just under more due diligence than in the golden days of 21 where the pockets were a bit deeper and the money was flowing like champagne.
But I mean, that's just not something that I only look at.
That's pretty much everyone's looking at budgets and allocations and what to bring in-house.
Scheduling up to this day is still really freaking hard.
Like it's not something you can just one shot like some other SaaS companies.
Like we have internally stopped using certain products because it was a weekend of cloud code to get to 70, 80% of that functionality.
Yeah.
Sketching is just like even the first 20% is just still really, really hard.
So I think AGI has achieved the moment you can one-shot Cal.com without forking.
That's my benchmark.
Yeah, I bet it is.
That's pretty funny.
Yeah, I guess, you know, even as an investor in Cal and as a user of Cal, Because like anybody, I've thought about where do we spend our money?
Now, I don't think we spend a lot of money.
I think it might be like 30, maybe 60 bucks a month.
I don't know what the number is.
I want to say it's at least 30 bucks though.
Yeah.
For Cal.
And yeah, even though we're an investor, we're a paying user.
That does make sense.
Because why would you not?
But I think in any case, I'm like, maybe I can sell folks.
I love to sell folks.
I'm a home labber.
It's like, well, maybe I can actually just.
go a different angle to Cal and not so much save the 30 bucks.
That was not my concern.
It was like, how much can, how much change can I actually influence in my bottom line?
And while 30 bucks a month is not dramatic, you know, what control can I get over self hosting Cal.com?
You offered open source for a reason.
You even bless the Docker image I could run.
So you make it super easy, brilliant and convenient to self host Cal if I want to.
It's definitely crossed my mind.
I didn't execute on it.
It was in my to-do list to look into it, but only as an exercise of could I, not so much should I.
And I think that's an interesting place to be in around Zast.
Do you, have you felt, because you're growing, but have you felt a retraction and has it been that?
Has it been self-hosters going and doing it?
I don't think that's going to be a case, but like no one's going to self-host Calum unless they really, really want to.
Well, I think there's two reasons people self-host, as you correctly identified.
One of them is I want to tinker with it and play around with it and make changes.
And the other one is security and putting it behind your own firewall.
Those people have always existed.
We do have governments and healthcare that self-host, right?
Newsflash also pay us because they want to and they need support and they need feedback and help and developer office hours and compliance help and setup.
And they pay us well.
So we do have a really small amount of people who self-host and pay us.
Now, they're most certainly in our Docker file.
I haven't checked at it in a long time.
Calcom has how many polls has over a million installations.
So take it or leave it.
That's a really big number.
We're not in totality or by a certain measure, whatever Docker hub tells me, I don't know that it's the analytics of Docker hub are really opaque, but it's been pulled a million times.
Now, is that a million customers?
No, but it's also not 10.
Yeah.
So anywhere between 10 and a million.
People are using the cell hosted file container.
So it's a big number.
It's not nothing.
It's obviously not a billion people, but it's a million polls.
But we don't charge them.
That's okay.
They would probably be on a free tier.
If these are individuals, they would be on a free plan.
Our free plan is as liberal as the open source version.
We always wanted to be like, You don't have to be self-hosting in order to get the product for free, right?
You can be on a SaaS tier and be for free, right?
I think where the revenue is coming from is just people want to move fast.
Companies want to move fast.
Self-hosting takes time.
It puts the burden on you to keep it safe and updated and maintained.
And a lot of people just simply don't want to do that.
I mean, why is renting popular?
It sucks.
I'm, it's just, sometimes you just want to rent and pay people money.
And then when the sink is broken, it's being replaced, you know?
Yeah.
Limit your liabilities, limit your responsibilities, limit your accountability, limit, limit, limit as a, I like to do that.
I mean, I don't rent personally, I'm a homeowner, but I do like to limit my liabilities.
Who doesn't?
That's just exposure, right?
Lease a car.
Yeah.
Yeah.
I mean, even that I own my own cars too.
Like I don't lease.
At least services and things maybe, but not really like those kind of large items.
And I know people that have said, oh, this is wiser, this is not wiser, or this can be, you know, this goes from a CapEx to a, you know, whatever X.
I'm in the same boat.
I like to own things.
Yeah.
I mean, you can go either way.
So I imagine this shift from how you're forking your own code base.
I imagine you've thought.
to some degree, and maybe you haven't.
Have you considered just literally going closed source completely and going like the TL draw route where they have TL draw license.
It is literally not open source.
It's not even using a source available license.
It's just source available and issuing out a license key and being very I guess, smooth with how you might license something.
So you might have a, an experimenter who's trying to figure it out.
Maybe you've got a home lab or who literally wants to home lab and host self-host it.
And you just give an instant license key.
Have you ever examined that, that world at all when it comes to closed source source available?
And the only way you can really use it is literally with a license key.
Otherwise it's in like a demo mode.
I have never seen the TL draw license and they actually made it up themselves.
That's so interesting.
Yeah.
It's, I had him on the podcast a little while ago.
It was a really good conversation.
I'll give you a TL, a TLDR of this.
I'm looking at it right now.
The TLDR of their success, they largely sell an SDK.
So they don't even sell you finished software.
We came up with the analogy during the podcast.
It's like orange juice concentrate that you put in your freezer.
You add the water, right?
Like it's not even a complete product.
It's a complete SDK.
Right.
And that's what they sell.
And they sell it as closed source.
It's source available.
And there's been some talk even, you know, they were out there on X famously pulling back their test suite because you can easily replicate.
You'll draw from the test suite.
You know, that's I'm sure you've been down that road.
I've seen that the threats and stuff like that.
But I think it's because of the threat.
I'm not anti-open source, but because of the threat and the desire to have a sustainable commercial company and have source available because of the reasons why source available makes sense for trust, but have that relationship.
So what a license key lets you do in this case is literally everyone who is a user gets a license key, and you're very – liberal with how you distribute those license keys that are non-paid.
So you want to be very open with it, maybe even instant with a Homelab key, for example.
But you get an email and a name and you can forge a relationship that's very different from here's our free and open source, you know, cow.diy.
What is wrong with you today, Adam?
Cow.diy.
You know.
You don't have a relationship with anybody who uses it, really, unless you force the relationship or desire the relationship or get that inbound issue, which you don't even really want.
I mean, maybe you want the issues, but not the pull requests.
So what do you think about that license key world?
Have you examined this thought at all?
So as of today, or whether the current way the repository split is that you can.
fully self-host Cal.com.
And then there's a couple of pro features that do require a license key and that are like under a source available license.
So it's pretty similar what you're explaining.
The only difference moving forward is that that source available will go private source, right?
So the Cal.com of tomorrow will strictly be an AGPL v3, potentially even MIT.
We might even change to MIT.
because it's no longer commercially used by us.
Like it's there, it's public, but it's more of a public good than a commercial asset.
But the source available part will go private source because it's already commercial and it's very sensitive parts of the product that should not be for the public eye.
That's kind of like the...
I think the decision we made, we're not, so we would never take anything, well, first it's not possible, but we would never take anything private that's previously open source.
But what we do take private in a sense is that we no longer have the source available commercial parts also source available.
We take that private source.
And I think, but the initial question you had, just to go back to the initial start was, Why even stay open source?
I think at the end of the day, we are forced to make a decision here, whether it's the right or wrong one.
Time will tell, the market will tell, and the technology will tell.
We don't know.
It's just, it feels like the right one.
A lot of people in the industry agree with me and security experts agree with me, which is sad.
I hate it.
Like, I don't like it, but that's just what it is.
We do not want to give up the open source ethos.
We keep Cal.DIY for self-hosters, for anyone who's, you know, excited to contribute and be part of this community.
It's just simply not that instance that we would be running in our production environment.
That's really just in a TLDR, not TLDR, but TLDR.
The only difference is the open source code is now fully open source project.
We don't run it ourselves.
We give it to you.
You can run it yourself if you want to, but we have a commercial fork of that thing that can do a little bit more and is a little bit more safer.
So in a way, it's not like we're a private source company now.
We just use our own private, like we use our community edition as the foundation and then we put some locks on it.
You know, given what you share with me and what I've also been seeing myself in terms of how things are changing, I'm sad too by that.
But I'm not – the state is what it is, I suppose.
And I'm sad by the fact that's the fact.
But I'm okay with how it makes sense to protect the investment, the company that you have.
our responsibility to run wisely, properly.
Well, the customers, right?
Like the customers, right?
Yeah, for sure.
The data we're processing is no longer fun.
Like we have really like important data we're processing, right?
Like people are meeting with.
And where somebody is going to be at, with who they're going to meet with at a certain time.
And I know you have like abilities to charge for meetings and stuff like that.
So like even that.
whether they're making money.
There's a lot of things you can get from that that you can cross-examine with other data.
None of this is sadly...
Look, if you run a chill open source project that makes a button green and glow when you hover over it, that's very different to having millions of customers who interact with each other, whether it's a chatbot.
You know, whether it's Discord.
Imagine Discord gets broken open tomorrow and every single DM is public.
That would freaking suck.
That would suck.
So open source is not dead, but it's changing.
Would you agree with that?
Yeah, 100%.
I think I also don't think that commercial open source is dead.
You know, open source is freemium open source and commercial open source, you know, the subcategories.
If you run a framework, you're fine.
If you run a package, you're probably fine as long as you have your dependencies safe and secure.
If you run a commercial open source project, probably make sure that it's not the same that's running on your production environment.
I think that's usually good advice.
But commercial open source is still really valid and fun and just a fulfilling place to be in.
It's a lot of fun.
Yeah.
All righty.
Well, Pierre, thank you so much.
This situation is depressing.
It's not a happy ending yet, but I do think, you know, I think what I also hope is that people just simply understand.
I think there's always haters out there who try to read into things, but I think my hope is just people just get it.
Like, yeah, it makes sense.
It sucks, but I should say it.
Yeah, we are at a unique position and place for sure.
And I think there's hard choices to be made.
And I think things are definitely changing all around.
And it's TBD on where it lands in terms of that change.
I'm long open source.
Same.
I really am.
And I hope one day we get back to where we can be even more forthcoming with details.
But I know when you're a high value, kind of property, it makes sense, obviously, to do what you need to do to protect yourself and your customers.
And no one can really foul you for that.
And I certainly appreciate the non-RugPool aspect of it.
You know, I think there's a lot of folks who would just simply rug pull and that's not at all the case.
And then, you know, if you were starting fresh and green and brand new.
maybe you never even go open source at all.
Maybe you start literally as closed source proprietary and you prove yourself in the market or you don't, you know, I think that the lore to being a commercial open source company these days is dramatically different than it was four years ago.
Totally.
Yeah.
And, and we, we don't even know where coding comes out in a year from now.
Yeah.
So like, I think it's, I think the most important skill for any founder is, you know, like, You have to adapt.
And we're adapting now, and you need to be okay with that change.
We're no longer a buck.
We're turning into a private butterfly.
So you just need to be okay with that transition.
Yeah, yeah.
Well, Pierre, thank you for keeping me on time with all of my time with Cal.com.
Big fan, as you know.
Big user, as you know.
Daily active user of Cal.
And I love it.
When we started using it, when we first invested, Never look back.
I've hit a couple of scenarios, but you've fixed things over time.
It's gotten smoother, easier, better.
Uptime has been always amazing.
And, you know, for me, five stars.
I would only knock you maybe a quarter of a point on the one thing I mentioned in this pod, but maybe after that, it's back to five stars again.
Who knows?
And I just got a notification from my coding agent who shipped your PR to override hosts.
Get out of here.
Yeah.
So during the pod.
Wow.
That's the way we're in these days.
And I didn't do a single thing and it looks amazing.
Come on now.
We shall see what happens.
We shall see.
Well, I look forward to using that feature.
I can't wait.
You'll be the first one to test.
I'll send you an update.
All right, Pierre.
Well, thank you again for coming on the pod.
It's been good talking to you.
I appreciate you.
Thank you.
Well, friends, a lot is changing out there.
I don't know about you, but...
Every single day I open up X with trepidation and anticipation at the same time.
Like, oh, I don't even know, you know, can I get a reset here?
So I don't know about you, but I'm loving Codex personally.
I'm not really digging cloud right now.
I haven't really ventured out to other places.
Open source models are doing cool stuff.
But by and large, Codex, Codex App Server and the fun things happening in and around the.
Open AI Codex World, ChatGPT Pro World.
It's just got me lasered in, gravitational focused in, and I'm liking it.
So I'll be in San Francisco here in a few weeks, September 14th through September 18th.
If you're in SF, I would like to say hello.
I'm trying to plan an IRL.
Yes, a changelog IRL.
If we could do it, fingers crossed, at PlanetScale's headquarters, I really hope we can do that.
If the stars align, we're making it happen.
If you're not yet a member, go to changelog.com slash community.
It is free to join, get in Zulip, get notified of all the things happening.
And I'll see you there.
Big thanks to the sponsors of this podcast, Coder.com, WorkOS, and BuildKite.
And of course, our partners in crime, Fly.io.
Okay, friends, that's it.
The show's done.
Thank you for tuning in.
We'll see you again soon.
