Skip to content
TrackPodcasts
technologySep 3, 20261:54:32

Forking Cal.com to closed source (Interview)

About this episode

The Changelog: Software Development, Open Source is made possible by:


This week I'm joined by Peer Richelsen, co-founder of Cal.com. What if the majority of open source repositories are already compromised and we just don't know it yet? That's the theory Peer brings to the table this week. We dig into how AI has flattened the knowledge graph to the point that a 16-year-old can vibe hack a power station just as easily as their mom can vibe code an iOS app, why the reporting culture that has kept open source safe all these years is collapsing under AI generated noise, Cal.com's move to fork its own codebase and take the sensitive parts private, and the eye opening reality that shipping "$1 of AI tokens for pennies on the dollar" is now a common startup business model.

Get every episode summarized

Each time The Changelog: Software Development, Open Source publishes, we email you a written briefing from the transcript — the topics, who appeared, and any specific claims, with the ad reads skipped.

Email me new episodes

Free for 3 shows. No card needed.

Transcript ready

1,068 searchable segments. Every word is indexed and playable.

Forking Cal.com to closed source (Interview)

The Changelog: Software Development, Open Source

0:00
1:54:32

Full transcript

The Changelog: Software Development, Open SourceForking Cal.com to closed source (Interview). Machine-transcribed; use the interactive transcript above to jump the player to any line.

What's up friends welcome back this is the change log. What if the majority of open source repos out there? They're already compromised and we just don't know yet. That is the unsettling theory, PureRitualsson, co-founder of KataCon brings to this podcast this week. We dig into how AI has flattened the knowledge graph so a 16 year old can vibe hack a power station as easily as their mom can vibe code and I was that why the reporting culture that has kept open source safe and secure all these years is collapsing under the AI generated noise, slop, whatever you want to call it. KataCom's move to fork its own code base and take the sensitive parts private and the eye opening reality that shipping one dollar of AI tokens for pennies on a dollar that is now a common start of business model. Lots going on, lots changing, a massive thank you to our friends and our partners at fly.io.

Your agents they need computers. My agents they need computers. We host everything we do on fly.io and you should too. Check them out at fly.io. Okay let's do this. Well friends this episode of brought to you by our friends at coder.com secure environments where developers and agents work in parallel and I'm joined by Nikki Pike field CTO for coder. Nikki what is a field CTO? So I get that question a lot and it's you know half the people understand it half the people don't so field CTO I describe it very simply as we're dev realm for the CVE suite. We provide a bridge between the customer voice between the C suite and the managers and the leadership teams of our customers back into our product and then we go through and we help enable our teams to have the same message to make sure that the message is correct and that we're building on something that people actually want not just something that

we think they want. Okay so we're taking the laptop away from the developer not really though we're putting them in a cloud development environment a secure environment where they can work with their agents in parallel these are blessed environments. What's wrong with the laptop? The laptop is the is the trap here and not only because the fact that it could be stolen you could lose it at breaks and you're out of work while you're waiting for a new one but there's also just the consistency that you got there. We all know developers developers are going to be looking for some of the latest and greatest and if you're not really controlling how they get out there that's where you get this it works on my machine it doesn't work on in production it doesn't work anywhere else because you don't have that consistency you don't have that ability to really standardize what that environment looks like and this is a problem not only for new people coming in you know the onboarding statement as it average I think is like four to five weeks for a new employee to really get their their local laptops set up and ready to start doing their first time of code and you know the time to first commit is a metric that almost everybody knows and the reason they can't do that is because there's a lot of tribal knowledge out there they got to go talk to other developers what are we using where do we get our dependencies are

we getting them from public are we getting them from private repositories but there's also the security and the supply chain aspect of this when you have local machines out there look at like the shy halund you know that virus that went out not long ago this was a compromise of the mpm public repositories they went and downloaded things mpm did what it did next thing you know you you're compromised but when you use something like what we're doing with cloud development environments then you can mandate and you can put restrictions on there to say hey you can only go get your packages from our private repo those packages are expected to have been thoroughly vetted we know that they're clean now does this stop everything like shy halund no if that compromise package gets into your private repo you can still have that but it really reduces the surface area of the attack and it also reduces the blast area of the compromise should it happen because if your laptop gets compromised and you have to kill the laptop for whatever reason that's weeks out of work while you're either fixing that or you're getting a new laptop in the cloud development environments allows you to kill that start back up fresh

and you're back and running in in five minutes you don't have to wait all that time well friends the first step is to go to coder.com install coder self-hosted environments for your teams to enjoy to standardize around and it's open source so you can try it out today once again coder.com well friends I'm here with an old friend it's been a while it's it's been too long here wait a minute co-founder of one of my favorite counties out there I usually daily call is how we schedule this thank you very much for being the backbone of all my scheduling it is about time since we've gotten back on the pod yes the poem was intended thank you so much I think actually our first pop was really about how it was about time where the initial conversation started began with

this era where cow.com I'm not even sure if you had cow.com at the very moment we did that podcast or not but it was we were users of Calonley when I say we I mean the organization change log and Calonley has been around for a while but they had changed they weren't working I mean a lot of different stuff which I'm sure you're aware of but one of the things one of the undercurrents the themes of that podcast was it is about time and so you know this very well because you probably live eating breath all the things around time being one of the co-founders of cow.com but thank you for going back on and yes it is about time thank you so much it's been it's been time and we need to make more time I think it was right around the time when we bought Caloncom which may or may not be four years ago or three years ago I don't time is a weird concept it is so yeah thank you for having me again I'm excited and I guess like full disclosure I am a very small check

investor in Cal a very small seed investor through I think your angelist stuff that you had way back and that's how much I believed in it because I was like okay I think even then if I'm recalling correctly because I'm trying to go back on my memory open source was core to your mission you know you've been open source for a very long time your commercial product is probably a license differently which I'm not familiar with exactly which license you chose and how that's laced out I know things are changing even too this year around open source I'm sure you have thoughts on that so I'm happy to go wherever you want to but yeah big fan of cow.com user daily of cow.com and it's been too long to catch up and I'm sure that this new era of cows can be different I suppose in this next era of agents where you probably have a lot of folks using agents to act on their behalf to maybe create events manage their availability even book time

with someone what is it like in this world that we're in with agents running a muck or maybe not a muck in this era for you. I think all the cars have been shuffled and nobody knows what's coming next I think I don't think there's a single person who can predict what the outcome is going to be like predicting how a certain stock goes like that person is a liar you can never really say what's going to happen but one thing for sure is that I think a lot of things are happening that we could not predict as easily as before like usually you start a SaaS company you have a playbook you know you have you know you get from 0 to 1 million from 1 to 10 million you know from 10 to 100 billion there's certain you know pattern matching and playbooks etc I don't think any of that works anymore and even when it comes to how to you know build in public or how to build in open source how to build you know the safest software or the fastest growing software like everything

has been reshuffled I think about seven months ago we joked that Dario said like in six months from now everybody will be using AI agents to write code I have not written a line of code like in weeks and samples to our anti-engineering team it's all code code gen and AI agent assistant and so it's like that prediction was so back seven months ago and everybody was laughing at it and now it's like it's the technologies here right and so the question is like what what else will change in terms of and I can only focus on startups I don't want to touch broad society aspects of like how what's the meaning of jobs and work like I don't want that stuff but like I think for startups like it's a really weird time right now like some like time that you could never really predict before and then you start as always some weird journey but now it feels like extra

volatile I'd say and and and and I think to to get to your point to open source and I think open source multiplies that by like a factor of 10 like you're basically drinking from the fireholes because you know when you're when you have a private source or the closed source business you're the only one committing to it there's no such thing as a public repository where people can like look inside and contribute etc etc for open source businesses and I strictly focus on commercial open source you just have so much noise and like back in the days it was like if somebody opens a pull request you would immediately know okay it's black and white either it's a well thought out pull request and you can with tests and everything and well you know thought out structure or it's whack and if it's whack you close it and it's like anyone can look at it and be like okay yeah this is worth closing that one's worth reviewing and then you you know you you you build on top of that

and you engage with the author nowadays everything looks the same like you get a pull request and it's always written by by clot by clot code or by maybe codex or maybe if you're lucky by some other coding assistant right but it's like back in the days you had a thousand open source contributors and you would have a thousand opinions right and one person would do something and then the other person would like reject that idea and now you just have a thousand people using two different coding assistants right and so it's like the this whole notion of like the best idea wins it's like the best large language model wins but you only have or maybe the best prompt given to that large language model wins because there's still some variation among prompts right but like it's really really hard to distill what should be merged into the project and whatnot and then what's even worse is that like the confidence of that pull request is so high because

the large language model is like here's the best thing delivered to you on a golden plate and then you start to peel peel off the layers of the on the end and you're like wow even these tests are like hallucinated like none of this makes sense like it looks so real right like it's wow this is like the best thing ever and then you start to run and you're like wait why is that thing hard coded like you know like so many question marks and it's like you're like why am I even reviewing this and so imagine being a commercial open source company there's so many tweets out there we don't even need to reference one there's so many just search for like open source and AI and they're like shutting down external pull requests and having this like vouch system where only like really close people who went through like multiple rounds of interviews are able to commit to the repository because it's just so much AI slop like literally AI coded slop being thrown at your repository so that's problem number one that's what I'm saying like drinking from the fire was imagine you have one

cracked engineer or cloud code like spamming your private repository okay now have a hundred of those who just and and some of these pull requests are literally just like hey cloud can you fix this GitHub issue for me and then they open a pull request and I'm like okay but like thanks but I could have done that you know like where's your uh well added knowledge come you know this is no no added knowledge and you're just essentially adding more slop to the code base so it's really hard um that's problem number one I'm happy to go over many more problems now let's talk into a friend of mine uh a friend of mine Adam Jacob did you know Adam Jacob money chance to see a name you know Adam Jacob he's famous for being the founder of chef and maybe infinitely being the founder chef it was here you'd probably be laughing at this moment but he created a company called system initiative and they had begun to rethink C.I. or sorry not C.I

but they began to rethink infrastructure it was very visual very innovative but they focus focus on this visual layer and this is pre-AI and obviously we know how things have played out and so they've sort of failed product market fit but a lot of the ideas were still really good and they parliate a lot of that good stuff into what's now called swamp.club and they are a gplv3 open sourced but very specifically they are open sourced but not open to contributions they do issue based contributions now is this is this where you're thinking like hey you can file an issue you can file bug you can file your your concerns but we'll never accept a pull request ever that's fine I mean I I think so here's my here's my current issue with everything open source um we we're clearly training AI that's okay I mean that's connected AI companies are already

giving open source companies tons of free tokens which is you know great like I have a free box max I have a free codex I'm very grateful for that I understand that we are producing the code that they are training the next large language modern on and that's I think is fine I mean it's still violating the license I guess but um silaree but I think the problem is um that when entire open source repository is as it is right now gets overwhelmed with slop it just destroys cold quality I mean look it's still our job to as maintain us to review and and approve and merge and change poor requests so it's still our job to to make sure the quality is high but it's just so much more work now to differentiate between bad PR and good PR that it's simply not possible like

humanly possible and I know Peter from open clause that he's not reading his his own gifts anymore like his own cloud codex PR's I don't think necessarily that that's the solution that we just like close our eyes and hope for the best and then like have tests etc because um there's this this graphic that was like the moment you introduced slop through your code base now the coding agent looks at your existing project and then adopts bad practices and you know it's kind of like a recursive loop of poo right like it just gets worse or worse over time same thing happens with with large language models right the worst quality of an open source repository the worst AI will be in the future learning from that bad code right and so um um that's another issue I have the open source where if you cannot get the resources in place to actually have really really high quality and and bear in mind that means you need to end up

hiring really like I see five I see seven level people who know what they're doing because you hire a generic I see one I see two I see three chances are they will be using cloud code and they they're incentivized to use cloud code because that's just how the whole industry works today and that's okay I'm not saying that's bad but like you still need these like sorry to say this like study computer scientists who know what oh and it's and a lot of them don't and uh so yeah um I it's not it's not a great outlook if slop gets multiplied you know um so I think the whole training aspect and the you know code and public aspect is really really the coming issue yeah as you're speaking about uh your concerns and challenges I'm looking at cow.com's open source repository github.com slash cow.com slash cow.com and I'm on the port requests

tab and you can probably see there's just an immense I mean oh yes more than you would probably ever want to or be able to know there's no chance there's no chance we will get to the bottom of this it's just so it's um well and and this also hurts the community right like people expect to get the same level of treatment for like a one nine hey cloud please fix issue one one five yeah then someone who's investing deep knowledge and and time and resources into making something better that they feel deserves to be merged so it's like it's almost like um how would you describe this best like the best way it's it's like it's like mass propaganda where you where you just post so much misinformation that it's just impossible to know what's the truth and what's not because you're just drowning in the sea of everything's fake and then the reality just gets murky right and the same with Paul with us like you just don't know what's good anymore

when everything looks equally good and then there's like a stellar PR and then the rest is just uh two line prompts from cloud you know so it's like it's really tough like I it's it's I don't envy any I don't even envy freemium open source maintainers who back in the days would be happy you would be happy for every pull request that would come in you would be hey like she's must off they think something I could change it yeah let's do it when when when we first had a conversation we probably had 20 open pull requests and then when you had like suddenly you had five more you'd be like whoa where did they come from and and you would like reach out to these people and be like individually like oh my god thank you so much for you know contributing this has been a blast you said right so it's like yeah it's um and it's and it pains me because also there's um this is another problem that um people are facing that they think they are more likely to get hired if they can show open source contributions so now they their entire pipeline is let me find the

top 10 repositories let me orchestrate 12 different agents and they're all trying to find different issues like basically the the clawed instruction is find the most uploaded issue and then submit a PR and these five different it's almost like you're spamming your your CV which is also really terrible strategy by the way into like hundreds of companies and trying to hope one of them sticks and then your AI agent comes back with like oh I've opened 20 different pull requests in these in these in these different repositories does that make you more likely to get hired I don't know so it's weird it's a really weird time I'm I'm not saying there's uh this is it's it's weird I it's weird we are really struggling we're really struggling yeah well I mean so let me I didn't say the number so you've got 358 pull requests yes no sorry 356 yes um and that's still a lot even

358 is I mean it's two more it's a lot of not a big dramatic difference there between 556 and 358 but that's a that's a dramatic amount of four requests if that were my pull requests inbox I would just say inbox zero ed and just cancel it right I mean no get yeah or or just literally cancel the PR tab altogether which I think is kind of what I was mentioning before Adam Jacob his his philosophy was swamping club and that is the or else swamp dot club it's the coolest thing ever and you guys check it out um they're just like forget it we're not gonna do it you know and there I don't think their their problem was the amount of pull requests or even the pull requests that would be or likely be a slop it was more like we know we're building we don't we want to build we're happy to take your ideas we just don't want your code we want code that we would write that matches our style of code that our engineers uh can curate whether it's with an agent or not

it matches our style it matches our lingo it goes at our pace it fixes our problems that we think are worth fixing we're happy to hear ideas who want to use swamp but it's issue-based co-contributions and you'll give us the problem or the challenge or the solution in in pros and they may even bring that into context behind the scenes but they may even write a promise and they may even write the the initial problem that that starts the journey I agree so um it's uh they they are clearly there's multiple reasons and benefits to be open source right like something simply have to be open source react jas has to be open source javascript has to be open source python has to be open source just to run the thing carot com necessarily doesn't have to be open source right so we've been open source for many different reasons but but to in order to run it that's not all the open source right we're not a javascript framework we're not a UI library so for us the

the the the pitch and the idea was always like building public build trust built them and then another thing build them most secure code base because I would say up until January 26 I would say open source is always more secure than closed source like I would stand by that statement and that's the problem today I no longer think that right so like the pendulum has swung you know if this is like very safe open source because bear might when you were open source you have security researchers making really good PRs fixing the holes fixing vulnerabilities reporting will believe that there was a reporting culture the reporting culture no longer exists 99% of the reporting we get our AI generated like we have an inbox security at calacom that people send vulnerabilities and 99% of them are AI generated like including that email that sends it because people

are spamming repositories and and half of those vulnerabilities are also hallucinated like they just simply don't exist you you reproduce it and it's not there or it it it got something wrong and it's using the wrong API and point and so the culture of like open source makes you more secure because you have actual human beings who know what they're doing checking your code base has kind of form behind and then at the same time so that's gone and then at the same time the autonomous attack attacking tools have gotten so good that the amount of knowledge needed to attack a repository is basically can you run a shell command in your terminal right so like we went from pan-testing requires crazy amounts of tooling and knowledge and reverse engineering of APIs and and and a man in the middle attacks and yeah the idea like so much work had to go in into

basically finding and abusing vulnerability let's say you're a black hat hacker right like let's say you are an evil person you want to extort people it was really hard you had to be really good these are really smart people who would execute those attacks nowadays maybe not with cloud because of all the security features but there are large language models out there that are so good at pan and pan-testing and and well cloud security to be honest of their product that it's really easy to find dormant vulnerabilities like Firefox had like 12 p0 vulnerabilities reported by AI react react react have vulnerabilities found by AI next JS had its own fair shares of vulnerabilities reported by AI so it's like we're really in trouble because I'm not saying our engineering team is flawless from pre-AI like obviously this is not AI versus pre-AI code but the amount of money resources and talent

to find and abuse vulnerabilities has like a hundred acts in terms of ease of use right and so you're giving basically evil people a single prompt in their terminal to find and abuse open source repositories so the whole pendulum of like oh we open source we're more secure has completely swung in the other direction where it's like wow this is so easy to hack any open source repository my theory is that the majority of open source repositories are compromised right now we just don't know yet like a firefox says to a firefox a firefox is 12 p0 vulnerabilities like what do you think yours open source repositories looking like you know yeah that's funny it's not it's really grim so yeah we just had that you know one of the more recent ones was light LLM it was compromised by supply chain attack I mean that's even more unique one was malicious in how

I executed it but how they got there was really interesting you know the social engineering behind it we're even just getting the keys and stuff like that and using the the blessed pipeline to get the thing in the pi pi you know that was really interesting and we're seeing that more and more and more because there's always been holes right I know what you're trying to say too there's there's always been holes and it's not you know then versus not kind of thing no it's that now the holes execution layers so much more efficient yeah right well the tool is now more evenly distributed so the knowledge graph has kind of come down to every human being that is in some sort of first world scenario that can afford 20 bucks a month maybe even the free version of it that's the same access to the same tool that the world's greatest engineers at some of the biggest companies are using right they're we're all using a version of the similar and same tool and so the knowledge graph has kind of flattened dramatically and you're right the bad actors now have the same thing and not only do they have the same thing it's a faster tool than we've ever been able to script

before we've always been able to script back there's always been there and sure it's always been fast on the given CPU but now the ability to write it and infiltrate and to just pen test security security security researchers call this vibe hacking because you're no longer knowing what you're doing like you're literally just instructing the agent the same way you have vibe coding and now like everyone's everyone's neighbor is vibe coding their iOS apps which by the way it's great like democratizing access to technology big five but like what happens when the same like when the mother is vibe coding an iOS app and then the 16 year old son is vibe hacking the power station nearby right like that's not great so the yeah is this exactly like the the access to technology also means that like malicious hackers have like they are so happy about all of this right they it's it's like a birthday present like what do you what do you mean I don't

I no longer need to you know do spend 16 hours studying the code base I can just have an AI find all the holes for me that's awesome here's my bitcoin address pay me money otherwise I publish your data on the dark web like you who yay that's great and even that is probably fully autonomously executed including sending the email and opening the wallet and checking whether the funds got received and yeah so it's a great it's a great situation right here it's a great you seem very grim and not very excited about the future of open source would you would you agree so I said you think things are some jeopardy or what I think I would I would probably summarize this like if you run a commercial open source business you have a huge target on your head because you are a business and a business means you have customers and the customers mean you have sensitive data and you can potentially be extorted if you run an open source free GitHub project even

if you run open claw like open claw does not have an enterprise edition that they sell to Fortune 500 that runs on the same code base even if they had to they were probably not publish it on the same GitHub you go so it's like if you run a UI framework a library that I don't know helps you work with time zones like you find like stay open source well unless you find you you accidentally import an NPM package that completely compromises your project which will happen so that's another attack vector obviously but like but any business today that has an open source let's call it this way any open source project that eventually makes a database call you are in trouble and and I'm saying this after five years of being open source and 15 years in the industry you should probably take your project private and rewrite everything that touches off database and encryption which is what we're doing now as color come like this has been a big change

we've been doing this under the hood for quite some time but basically starting 15th of April we're taking the commercial version private so we still have the community version fully open source you can use it at your own risk you can self hosted you can run it on your own infrastructure ideally behind many firewalls but the same code base that runs on app.cal.com we no longer be publicly accessible because it's just it's too risky for us like we have we have a commitment to open source but we also have a commitment to every single of our customers and given this like pandalam swing we just that the risk reward ratio just really sucks yeah is this is the change I understand what the change is predicated on but is it because the visibility into the flaws are more visible now because the tool is better and faster is that the kind of the one of the kind of core reasons that change so the security researchers we spoke to right we have a couple of those and and

obviously there's also the good people helping you with providing tools to find vulnerabilities before the black hackers but everybody says if you have an open source report you're like five to 10 times easier to to hack than a closed source repository right so think about a five to 10 times is not like 10 15 percent is like five to 10 times that's a big delta and so the reason it's so much easier is it's called black box hacking like you basically need to guess and reverse engineer like you call an API endpoint we try to guess them it like what does it do how could I attack this with open source you literally see the back then you see the function call you see is this an idle or is whatever is there something else that I can like is there a way I can inject a script or whatever and again pre AI you would need to spend eight 16 20 hours to research and study

every single function call and find these things you know manually and that's what what good security researchers would do and they would get a bounty for and that that's what black hackers would do and typically speaking so to say this the smart ethical hackers are faster and better than the script keys which is want to extort you some Bitcoin that's just facts that's always been facts right like an honorable security researcher who's a white hacker who gives you bounties is always more intelligent than some dumbass sitting in some random kitchen hacking yourself where that's just always facts but now again with AI it doesn't matter because both are just putting the same prompt find a vulnerability in this and this and that repository and run the same prompt and guess what the black hack hackers usually fast because they have an incentive right they have an immediate extortion incentive to hack and blackmail that's a big problem right so yeah I would be really

cautious if you have a repository that has a database that has customers in that database to run that out in public and that doesn't mean you should you should like close your open source we're not shutting down our repository I mean hack it's it's an amazing piece of software that we've published but it just means that you need to internally fork your existing code and just make sure that you just rewrite every single function call that is vulnerable like that is you know hackable you know don't care about some random front and library that's fine like a drag and drop component keep that but like the way you do all the way you do database calls the way it may be even rewrite your entire middle layer and the in Christmas calls everything like probably like start today or start yesterday and take all of that private it's just not worth the risk until that whole pendulum swings back into

security which you know could happen could have could also not happen it's just it's it's it's yeah we don't know we really don't know well friends I'm here with the CTO of build kite and one of the most challenging problems of modern era software development is continuous integration and continuous delivery and so lockland on old build kite ctio what are you thinking about today's teams the challenges they face the speeds at which they're developing new features new code it is just overwhelming how do you all think about that such a good question is the question everyone's asking right now all of our big customers are asking us at the minute like you know if we five or ten x are three put this year or a thousand x it what breaks and when and you know my answer is kind of same as it's been for the past 20 years which is that the bottleneck is still trying to integrate those code

changes in and then deploy them and check they work and then keep them working as you keep throwing more and more code at it I think a lot of the fundamentals are the same but we're just a thousand xing the speed of it and you know that changes nearly every variable yeah for sure okay so we're where does build kite thrive what particular type of team or enterprise do you thrive in the area that build kite has always thrived in is is like this like fastest moving tech companies of the world like we've been disproportionately successful in that small niche they're kind of Shopify class Uber class you know open AI class of um fakes that have this key problem around iterating really really fast and you know the thing about all of those fakes is they all have subtly different needs subtly different problems and so we've tended historically towards building like really well engineered Lego blocks that scale like orders of magnitude more than what our nearest competitor

does so you know I think that that puts puts our system in this tension where you know you've got a spend some time assembling those building blocks that those Lego blocks to get the thing that you want but the end results is far and away more performant and scalable and the experience is better than what you get from something that's off the shelf so I think we've started from a position of really well engineered Lego blocks and then are kind of working backwards towards kind of creating the thing that scales down to a startup that starts with one person and 10 agents next week my friends go to buildkite.com that's buildkite.kite.it.com you deserve better CI engineer for the frontier we are all facing trusted by the teams setting the pace again buildkite.com once again buildkite.com so the way you're if I understand correct which just said that the mechanics of how you're making

this change the change we understand what the change is influenced by but then on the how you're saying to internally fork and in your case your commercial open source company and so you've had all of your code out there your open source has been licensed one way but if you go a certain way there's certain features that were always available open and open source source available that you can see you're saying that you're changing that so that all of that code base will remain there the license of freeing up in source will remain the same but internally your mechanism is to fork it and rewrite the areas the surface areas that are at risk or at most risk yeah correct and we also obviously point the production URL to the private repository right so like because you know what you see on GitHub today is what we've run on the website that's just how open source works right that was the whole point like you see the code that runs my service that was the whole spiel so that spiel is no longer safe enough to be valuable for your customers like it's

it's an unnecessary attack vector so that doesn't mean we're no longer open source we are still open source it's just that we have an internal fork the same way other many companies like WordPress.com is an internal fork of WordPress.org I get still WordPress uses the same plugin system but if you sign into WordPress.com today it's a different experience than if you get the open source WordPress so they kind of like did that change well probably more from a commercial point of view not from a security point of view but I think they internally most definitely have different things in their off system than what's out there which I don't blame them but the narrative of like one code base for everyone you know self-hosted and production environment just no longer makes sense it's just it's it's it's it's from a security point of view it's it it went from

wow this is safe because we've been supposed to is that really the smartest safest decision you should make as a business that has customers and that you want to keep them safe you know yeah I guess the question might be why even remain open source at all and I don't mean that is like anti open source I mean it more from a tour standpoint so if you've got a fork your own code base and now you don't want your vulnerabilities out there so that means there's a buffer layer between what is open source and what is closed source i.e the fork that you have internally the tour it must be to keep those two code bases and even remotely and sync and not have you know developer gymnastics playing around like what's the point of open source then for a commercial open source company that was you know has been in your shoes but you're not making this change I mean it is it's it's it's a really it's a really terrible situation you know it's like

yes this is pick your poison I would argue the reason to keep an open source project and by the way we're also rebranding it to cal.di we got that domain so like do it yourself essentially like I like that it's it it's a whole it's there's going to be big red letters like use at your own risk not production ready like you can self-host this for your whatever hobby or maybe small business um I think the benefit is if people end up self-hosting a quote unquote community edition it's they are not going to be the one being hacked right like it's us it's the largest company that gets attacked the one with the most money the most reputation your neighbor barber who self-host cal.di.i.y like a you need to find that server b you need to know exactly who you're targeting who

you're like it's it's kind of like security by distribution right like when you're self-hosting you're not going to be the target unless it's like a very easy to attack multiple multiple nodes in a way like if it's if every node runs the same software then you do like this like mass attack but it's just not commercially viable for hackers to hack your neighbor's barber shop so theoretically speaking yes the cal.di.i version will have the codebase off today right the potentially we we don't even know if it's insecure we just know it's out there but let's say it's slightly less secure than the private fork sure but it gains its security by being just so relevant in terms of distribution right like five people here 10 people there five people here one person there so you're kind of like gaining that security back by just being more like less of a target you know less of a targeting your back and then at the same time we can always obviously um and I'm only

strictly strictly talking about like auth and database and middle layer etc like if the community builds great features we can we can adopt them and credit them if we build sick features which we do we push them back into the open source community edition so I hope to keep that relationship strong the same way WordPress has been doing it for many years so it's not like a unique idea like we've always had private and public folks of open source projects Docker has its own enterprise edition that's private source yeah but like I think and if I'm being honest with you all of these forks have been for commercial reasons some investor has pushed you some IPO some bank look that you'd be like we need some proprietary code because of whatsoever so it looks better in our brochure but trust me with my fullest heart this is not a commercial like we are we are growing like seven to 12 percent month over month we are not in any way short on cash we have no investors who

are bullying us to go private source we have the most open source friendly investors on our cap table we had to convince them this is the right decision this is like a a a like nuclear problem for commercial open source you know and so it's um I wish it was a commercial decision because then I can like say okay this is only affecting us but this is this is affecting the entire industry this is like a yeah like the quantum computing cracks encryption type of level you know yeah that quantum what do they call that quantum safe or quantum ready in terms of security and whatnot exactly I mean that's that's really insane thing too what other examples can you give I know that you kind of give a couple but what are some explicit examples of other commercial open source companies that think like you do or have the same problems you do

and can you enumerate their challenge in the public that's being showcased well I can I have many conversations you know that I really cannot make public because of security and like in just the risk inherent risk and what's on x what do you see on x what would you rate I mean well I mean I can definitely talk about public situations right like this and I also don't want to throw anyone under the bus but there's you know there's there's tooling around logging right like lock systems that lock user activity those products are usually open source because it's a developer package you need to like you need to import the SDK so those have been hacked by AI which is really bad because now that attacker has access to all your users actions that makes sense like the events that they send for them they're really screwed because they they have to be open source for the sake of being a developer kid right so I would say that's two companies that are directly

affected and I know of there's a CMS which is open source which is really struggling because when you're a CMS you simply cannot expose your internal systems to the world I mean just think about how much knowledge is locked up in a CMS and or the risk of somebody I don't know hack like imagine you get right access to someone CMS and you're publishing something on Nike.com you know like that's just not great so there's a there's a lot of commercial open source businesses out there that that have to be open source in order to to run in that regard we're almost somewhat lucky that we don't depend as much as others to be self-hosted boy again 99% of our revenue comes from our SaaS app.cal.com it's not like we sell a code snippet that people inject in their business

so yeah it's and then there's a couple payment providers that like call themselves the open source version of Stripe obviously anything that touches payments is hypercritical you know that's always tricky I don't even want to talk about crypto because I really don't like crypto but all of these crypto projects are being cracked open that open source it's so while we're out there and so you're if you are a doctor doctor peer yeah your prescription for these commercial open source companies in these high impact areas is to rethink their model and follow you in terms of forking internally creating a new relationship with the open source version if you even keep it in your case you're keeping it you know cow dot DIY or DIY which I think it's super cool I had a little case of of dyslexia there for a moment there but cow dot DIY did it again DIY DIY cow dot DIY do it yourself come on Adam

well on the bright side on the bright side yeah on the bright side and maybe on the bad side like what's open source stays open source right like we we went up disappearing tomorrow like a record is yeah more like cleaning the rock and making okay back in the back in the rock okay back in the we're vacuuming the rock and and closing the door to access it to you can look at it it's beautiful it's a beautiful rock but you can no longer step on it um no because like look there's like so many folks out there a calmer comment is not going anywhere like we can legally not no we can physically not get rid of the code what we can do is move forward gracefully and make sure that the most vulnerable pieces of any piece of software is not public I think that's a very fair statement to say because back in the days you would have those public because it's just really hard to hack them now it's easy to hack thereby I need to take these things private

and by the way having private code is not for tech you from being hacked I don't nobody thinks that that's the golden solution but it is a security researcher of many security researchers say it's five to ten times easier to hack you when you open source you have to listen to the security experts if you don't listen to them you're literally well probably you could use that as a way to even go to jail if you get hacked I don't know I don't I'm not a lawyer but like if you ignore multiple warnings from experts you should probably rethink why you're even the co-founder of the business right so my recommendation my medicine is first don't freak out there's a high chance you're not compromised most likely you run a really small project you're not a big target second is to run many of these AI scanning tools and and just see what the blast radius is today most likely it

is quite high like every single project I've talked to was experiencing an uptake of reports by these AI tools but like tenfold like it's just messy it's really bad turns out humans are really bad at coding for many years including everything before AI so chances are you just have vulnerabilities that's just that's just the fact and then my recommendation would be to at least temporarily go private and work on all these vulnerabilities because here's another problem and this this really hybrid right when there's a hacker who actually wants to compromise your project they are also running code scans against your own pull requests right so yeah so they today probably if if let's say you really want to screw someone right you would run code scans against their own pull requests and if you detect a pull request that fixes a previously

non-vulubility that you potentially found or ready or maybe not right like an AI can understand whether a pull request is a feature or a fix of a vulnerability right like you you give an AI just random code and and ask it like what is this PR about and it will tell you this is fixing a vulnerability so they're using that I I mean whatever is technically possible will happen right I'm not making this up I don't know what personally any hackers but I am that's what I would do if I was evil you would scan the PR you would identify this PR fixing the vulnerability and in that second I would abuse that vulnerability and send them an extortion letter right that's just the that's just a scary part right that's not what you think there right that's I should I should not become a Marvel evil model super villain but anyway again everything is technically possible is out there and it's happening so I'm not I'm not giving you the playbook that's literally

what's probably discussed in these dark web forums and so your best shot today is to take the repo private fix all of these things in private and then merge it back into one you know chunk that's just you best like this is quite like commit don't give them a exact path to change don't don't feed don't feed the machine don't feed the machine that's gonna extort you for Bitcoin you know well if I don't know you were talking about this when you came on this podcast I don't mind I'm glad you got me down over here man maybe we should not maybe we should not publish this I mean this is good stuff I think this is this is truthful I mean this is where my head's been at as well yeah and you're bringing some new light to some things with me I'm gonna go back to if you don't mind not so much to fully backtrack but I want to go back to your port request tab and not specifically just yours but the port request tab yeah and the reason why I mean so you're seeing what you're seeing about commercial open source companies I don't

think open source is dying I do think port requests may be changing in or becoming not irrelevant but just fraught with a lot of slop that people don't want to deal with so even projects like ghosty they're not taking on port requests like they were before a lot of folks that you know like ghosty is a great terminal and for a lot of reasons it needs to be and wants to be open source for the for the true nature of what open source is but they're being open source not open to contribution so I want to I want to pose this thought experiment here how does this change get up is it is get up at jeopardy in any way as a business maybe not because a lot of their commercial features are on top of things that aren't there but like if a lot of us are on get up because that's where open source is and if the relationship we have with open source changes or open source changes enough you know is get up in a risky scenario because I mean they're banking almost everything on co-pilot

right I mean that's the large majority of their their infrastructure even npm I don't know they have some changes coming out and I'd love to talk to them at whoever's working at get hub behind the scenes or in front of the scenes if there is any on npm I'm not saying any negative about those folks at all I just know that there's there's neglect there's neglect there around npm so even of the things that is the largest package manager and registry known demand on planet earth is npm it's so important I mean that's where the access act just happened and we know how that went down right yeah yeah you know what is the picture of get hub if all this change we hear thoughts on that well I mean it's not it's not it's not bright for commercial open source I can tell you that so like if you obviously run packages etc freemium open source you're probably more okay sure you build a new react alternative or self-kid whatever and tell when alternatives um but get hub

obviously has to rethink it's on like I wouldn't call it economic model but like place in the world with AI where and this I would even say this goes beyond secure way beyond security because like look if somebody like peter doesn't read its own diffs and the neighbor who vibe codes it's ios app do people really care about the source code do you want to see the source code like they are probably already projects out there where the community has looked at more of your code than you yourself who published that repository right simply I mean that yeah totally I mean that that's gonna happen right where the maintainers have seen less of the code based then than the community combined usually it's like the maintainer who writes the code knows the code but now it's like I can prompt any project and publish it on get hub and then chance I

I badly scratch the surface of the code that I've published right it's like as long as it works and it looks good why would I read the code you know and it's safe safe so obviously distributing code almost feels like distributing binary at some point and get hub wouldn't work if people just publish their binaries you know the thing it still works but like who's gonna read that or like you just put the the bytecode the assembly code whatever the binary code up there you know 0 0 1 0 0 1 that's great cool so if source code as sad as it sounds really isn't like I'm not a fan of this but if source code becomes unreadable because nobody knows what the is doing anyway so if if nobody knows programming anymore new students come out of university and they don't they can't read source code they don't know what it I don't know what if statement is they don't know what a you know what what point has get hub besides being a CDN to share zip files

if zip even is around that time or you know or DMG files like you you're basically turning into a mega upload where people just throw up all their garbage so yeah they 100% have to rethink everything about like what is the meaning of code in 2027 2030 what is the meaning of code in 2030 you know yeah and then obviously it's not in any way AI first I mean the fact that you know what I just explained anyone can open pull requests for anyone you know there should be guardrails there should be rules who can contribute like we're using these third party GitHub actions that like auto-close pull requests from people who are not verified that's all just hacks you know that should be first party coming from GitHub why do I have to install different third party plugins to make sure only legitimate people are opening pull requests that should be your job GitHub you know

well friends I'm back with a good friend of mine Michael Grinich Michael I know that I love work OS our audience may not know about work OS but what are the challenges developers face starting a new project choosing the rate tools choosing the rate database choosing the rate off take me there when a developer starts a new project the decisions that they make at the very beginning end up having long lasting consequences what language you build in what platform you build on top of what database you choose these are things that are very hard to change later on so they have like major consequences and especially if they limit your ability to grow and scale at some point as the product starts to take off you're going to have to stop developing the product features and go re-architect to rebuild your system and that might be a killing blow right at the moment you need to accelerate so these decisions are really on are really really important and I think that's why developers gravitate towards solutions that are mature things that they know that will scale even things that are open source you're going to pick you know something like planet scale

for your database provider not because it's the cheapest or because it's the you know most fun to use but because you know it's going to be a durable provider that you can scale on for years and work OS is like that for off you know at the earliest earliest days if you look across all these different services they kind of look very similar but at day 1000 or day 2000 or day 10,000 you're going to want to have made sure that you picked a platform that could scale with you and today work OS is powering off an identity and security and permissions for all these AI companies literally the fastest growing companies in the world like opening eye and dropping cursor for complexity work OS is under the hood there so I think when people pick work OS early on really what they're doing is trying to pick the defaults to allow them to grow and wrap up the scale and there's no platform other than us that's that's done that at the same level well friends the next step is to go to work os.com sign up today check it out free for a million active users tried today there's no excuse not to it is your default you should choose it so do so work OS.com once again work os.com

did you catch that post from Mitchell Hashimoto Bonnie chance on x uh can you give it a recap probably give you a recap so many them it wasn't long ago it was March 25th of this year and he started off by saying here's what I would do if I was in charge of GitHub in this order and he says establish a North Star around being critical infrastructure because there's been a lot of downtime yeah they go the double 9s back with the aid in front yeah yeah he talks about coming back uh establishing a North Star around being critical infrastructure for agent code life cycles and determine a set of ways to measure that number two was fire everyone who works on or advocates for co-pilot and shut it down he's not about the people he's trying to be kind here uh I'm sure there's many talents for carcass uh acquired carcass uh right pay whatever money is possible yeah and he says buy Pierre

which is computer that computer we've talked about on the pod before you may be aware of it as well here um buy Pierre and launch agentic repo hosting as the first agentic product hmm and I can paraphrase more of it if I needed to but then the last one was re-evaluate all product lines and initiatives against the new North Star which is really predicated on being critical infrastructure I gave back those 9s of course and he says I suspect 50% get cut to make room for the different ones yeah and so I mean I'm not sure if he's accurate wrong or right but uh there's a lot of folks who are upset at the uptime and downtime stability at GitHub I mentioned before there I know they make a lot of money I've get a better prize as well but I think they're really banking on uh get up co-pilot and I just had Berk Holland on the podcast he's one of the developer advocates on the uh get up co-pilot team so he's largely aware of what's going on there uh has some more conversations I know more co-pilot advocates than co-pilot users

you know I'm not a get up co-pilot user I'm also not I mean either it's just I don't think you're trying to be I also I also don't hate polar bears I just don't see that all the places sure I love polar bears um what I think is interesting if we look back uh because I've also had a podcast with Amelia Wattenberger and if you recall do you know Amelia Wattenberger money chance the name regabelle to you she works on the get up next team which is where get up co-pilot came out of oh my co-pilot was already in place and in motion before she got there but she was a role she played a role in GitHub next which was sort of an offshoot of the office to the CTO I get up so it became this area to innovate uh and that office of the CTO is predicated on Jason Warner Jason Warner's idea was get up actions get up actions as largely why

you know got acquired by a Microsoft I'm compressing a lot of the history here just for the dovetail and so this get up next area was this laboratory where a lot of the innovation came from that's where get up co-pilot came from and a lot of the race and current status of the race of where at was was uh you know around get a co-pilot being tab completion they were the first they were the first while factor and here they are the the late runner not the front runner of this yeah how do they lose that yeah yeah it's just kind of wild to see the picture kind of come full full pendulum there on that and you know Microsoft this Microsoft has any race in the coding industry right now besides just co-pilot right I mean is that the store for the price so you know the promise we have Chris we have Chris we have codex from chat to begin we have clawed or clock code which is primarily terminal obviously

and then we have what's the called windsurf I believe and I believe windsurf trade in it no I just got acquired but what's it acquired by Microsoft I remember cool I want to change and then there's some anti gravity anyway and everything is yes and replicate yeah true yeah and then you know what I'm doing pretty cool stuff I haven't used their stuff yet but I know some people who are and you know what there is a landscape there is a landscape it's not only two but but I think what I what I really find sad about Microsoft is that I think they have the head screwed in the right place but they just don't have the execution right like yeah they they came up with co-pilot they were the first investors in open AI the first big ones that they made it big they fully banged on it and now they seem like they profit the least of it yeah I'm not really sure but I just think it is kind of what look back at you know we were all

enamored with get up co-pilot tap completion function completion things like that and and now it's not really the major player in the race but it seems like GitHub is banking big on that but as a team and individuals like you bar and we are that have have we're not sure of the future of GitHub I don't know either I just don't know but I know that they're they seem to be largely focused on co-pilot and their inf their uptime has been down dramatically now Mortwood word who's developer advocate for you know the dev team there he's come out and talk about it Ryan Daagle COO not CEO because there is no CEO of GitHub anymore came out of the will work and started talking on Twitter about slash x around these things and it's cool please talk about it but there's something going on there and there's something changing there and there's code right now we're talking about even sure who's moving to codeberg I think a lot of it

might be potentially self hosted so what keeps you at GitHub stays if you're not open source you know that's how that comes out that's more dramatically open source like you were before what keeps you what keeps GitHub your epicenter it's it's not really much of your episode oh no and look what what happens if if the user base of GitHub is agents it's not a really nice business yeah you know the whole beauty because the reason why I struggle with that one and I want to maybe and maybe you can draw this line too is largely agents but is largely agents there on behalf of a human so that's where I I draw the line because I've got agents and I'm a human being and so I have intent right and those agents are acting on my behalf and so bots versus agents maybe a little bit different and I'm not sure well how do you draw the one there well how how much is it a human intent if you ask Claude like research the top 10

frameworks and and and then of those repositories picked the the most popular issue and open a PR for it is that really your intent I mean it's no different than search right and search was still be you would still say it's a top search results right it's just a new way to search you're skipping a lot of intention that's what I'm saying like your agent makes a lot of assumptions and decisions that detach you from it I would say yeah that line will continue to be examined and blurred in my opinion I think I sit on the side that if I were making that search to say hey go out and find me the top 10 repositories and help me learn how to commit a PR I think that's still user intent I would probably still draw that back to user intent I think that's cool and I think everybody should do that but if that AI makes that decision for you and just makes it for you the PR and everything you

no longer have any emotional connection to that you might not even know which repository your agent committed to yeah I suppose if it's fully autonomous and there's no awareness and the intent is very thin then it does get thinner obviously I think I think it's more than AI agent only I think this whole agent thing well first things first agent is a horrible name because agent theoretically means there is a persona that has its own objectives and then autonomous decisions right everything else to me is like a human scaled with AI right like top completions are different to autonomous coding right like you are still writing codes but you have auto completion we've had auto completion for words since 15 years like that's just not that crazy but but I think the innovation came for coding that it was actually working and not just like brambling we should but to the the the

autonomous future that a lot of people are imagining is what I just said that you have this coding agent who wakes up at 8 a.m. well doesn't sleep doesn't need to and and grinds did have bounties searches the web for whomever probably probably the most profitable agents will be hacker agents you know that try to extort you on a bounty versus extortion metric but let's say you're a white hack white hat hacker agent you would probably autonomously serve the web you would find interesting repositories maybe you are looking for repositories that your company is depending on you try to maybe put your own company policy into that french op freemium open source project or you want to maybe you're trying to improve a certain library that your company depends on I mean even today

already cloud code could analyze your code base today and it could find a potential vulnerable open source dependency you depend on and it would then it could autonomously visit that repositories project and open a PR itself on that project trying to get your fix into like that is not impossible today that's I'm not sure if it's happening at scale it's probably happening in installation but theoretically speaking your agent could hit a wall and then autonomously raise a PR in that dependencies repository right that's not no longer your decision your decision was to improve your product but the agent made the autonomous decision to go out and hunt and open a PR and someone else's repository yeah that to me is very detached from tap completion you add them wants to improve my approach yeah so are you for that against that then that that particular I mean that seems altruistic like while it may not it's you know one step or two steps removed from my

original intent original tent is to learn about the security of my dependency graph and then the two steps removed is you know figuring out which ones have issues and correcting them or finding a correction and some media PR are you for that against that well I think us as this the the tech community we need to find we need to find peace with the fact that like even though this GitHub user has a human avatar this GitHub user has not written a single word of that PR yeah because that's just a reality right so we need to be first we need to be okay with that and then the second thing we need to make peace is did that person even think about my project when they open this PR like are they aware of it do they know me do they like me do they have the same ethics what is their altruistic intent is it to improve their own dependency or is it to find a job

because they ask cloud code like hey I'm unemployed like find the best 20 repositories and get my name out there or is it even trying to build it backdoor or a break a feature or change a button that was previously most clicked and now it's you know you can also you don't have to be a hacker to it's not illegal to raise a PR against calocom that makes our product worse that's not a legal right no um highly unethical but you don't go to prison for that if you ask cloud code to make calocom worse like okay dokey let me let me remove the login button job done you know let's dovetail hard core to the right if you don't mind and let's talk about the success that you've had I mentioned until the show see the investor very small check of course but I was very happy to do that because you know I was using county I like to call out better I like

your mission we had you on the podcast I like your mission I like you know this was a lot of the rage at the time to come out as a commercially open source company we both know JJ I think you were part of OSS capital in terms of your initial raise and support there so there's some history there but tell me about uh give me as a maybe a seed investor give me a give me a glimpse behind the scene of the success that is happening or has been happening yeah um look I mean we we are blessed in terms of timing and the the Renaissance of open source I believe that might even been the topic of our first conversation like where do all these commercial open source startups come from and and they all doing great from what I've seen the people that I'm trying to be close to open source was almost like uh like what did you call it like um wish that for way too long and it was still striving I think now it's getting harder again but I think my vintage of open source

companies has been pretty successful with what they're doing there's many good outcomes um and and and and look open source is awesome I love open source I wish we would not be under this threat which just like can't close your eyes to but um so no cala com has been growing fantastically um we're very happy the teams teams happy we're reaching I'd say like the milestones we we set for us very low-churn um high growth you know sars high margin sars we we don't have a single AI product that's catching on which also means we're not burning any AI tokens which means our margins are great still great it's uh it's quite funny when I talk to founders who're like oh my god we're doing five million in in AI now and I'm like okay and how much what's the bottom line and like oh I mean we're burning 10 million so like okay fantastic so it's like um I mean look every

business is great if you're selling uh like a dollar worth of AI credits for ten cents you know like that every business is fantastic if that's your business model right like if you and then you've seen this on twitter you know like all of these coding assistants are like adding rate limits and reducing usage and trying to upgrade you into two hundred dollar plans and you know like the economics don't make sense in the AI space they they don't make sense yet I maybe they will but it's a it's an uber type thing what's like how's this uber so cheap about duh somebody's paying friend you know fifteen dollars from sf airport to the city yeah right that doesn't have any more but it did it was fantastic times I was loving it that was great that was for good times you know it's like oh god 80 bucks for that ride wow one dollar delivery door dash right that was good I

saw some of the recently they said we'll eat I can't recall what it was but I was so surprised by it they literally said in their marketing will eat the fees I don't know like that's great for marketing because your market is like sweet you know this is a great carrot let's chase let's get some people attracted but you're literally telling the market we're going to lose money we're spending on the get you know we're taking the fee you're basically saying do not invest in this business unless you like to lose money yeah I thought it was kind of funny I was I told my wife I'm like babe that that basically says let's we're just gonna lose money here to get this business we're gonna subsidize it as marketing Adam if you want to have the fastest growing startup in history you could launch a landing page and you say get a clogged API key that works for half the price we pay 50% of it but still pay me right so so you're gonna have you post this on the hack anews and you're

gonna make like a hundred million in the first year and you're gonna burn 200 million because that's the money you pay 50% of it but you're gonna be a startup making a hundred million in the first year and you can go to every podcast and and and say this is how we made a hundred million in the first year without saying you burn 200 million yeah but that is essentially what sadly a lot of startups are doing right now they add some flavors some prompts some system prompts some UI some side bars some orchestration and drag and drop but a lot of these startups are simply doing that not with a 50 50 split but you know maybe a 5% to 95 or 10% split so no to in my eyes it's not a great business but for some it works if you can raise billions of dollars you can do that for quite some time yeah the one agent that hasn't done that and has has done it hasn't done it to the degree what am I trying to say there they haven't they famously

come out and and said weren't we're not gonna sell it for less than it should it's actually expensive and we're charging appropriately is our friends over at AMP code now they're wrapping uh open a eyes api as they're wrapping andthropics api as they're giving you versions of gpt 5.4 codex etc they're giving you versions opus 4.5 at all the different variations of it and they're sprinkling their own abilities on top of that and AMP is I don't know if it's source graph because that's where it's roots came from but um what makes it so good I'd love to like learn what makes it so good but AMP I have you play with AMP on a chance here I have not no well after this podcast going play with AMP AMP code.com I believe it was so successful for them that they spun this out of source graph so AMP was a sub product of source graph which was already largely popular and very successful and they built their own agent called AMP

and it was so successfully had to like spin into its own company so now it's AMP code AMP or AMP AMP one of the two I'm not sure and uh if I have a really hard problem I just know I want to get right I've got to use AMP and they have a a free model which is paid for by ads and now that's changed too that's uh it's like 10 bucks per day you get and they basically said it wasn't successful it was they actually put a 10 million dollar per year business in ad sales on that and they close it down but like by and large they're not subsidizing the tokens they're charging appropriately and profiting on it well not a lot of business that's probably good to everybody else's but it's still growing quite well. Yeah well another business yeah I mean exactly it's it's like how aggressive do you want to grow I mean again you can add your flavor on an AI and rapid and make a good UI and resell it and and make make money without losing money like if perfectly fine it's just yeah the I'd say the coding space is just so competitive that like nobody is

really in it for the UI it's just like where can I get the most compute for lift money um but I mean companies that have not done this also is like mid-June you know like they've always been profitable to boot shop business they never raised funding and I don't know what revenue mid-June is today but um they found a way to profitably sell subscriptions and rate limit accordingly um I mean they pretty early built I mean they always built their own AI right I feel like they've ever bought other AI so maybe the margins make more sense for them because you you're the your own supplier you don't need to buy tokens you just need to buy just buy infrastructure. Yeah they have their inference and the infrastructure and the cost to maintain infrastructure uh keep it up supply. But you're cutting out one you're cutting out one middleman for sure yeah the one that's it's your own market yeah it is a big mess there I think with uh I mean it's a big mess to to manage but it is you're sort of in charge of your own mess

so your your cost center is different you're not buying tokens you're purchasing man hours to produce into sustain and hardware itself and managing that hardware is uptime. Yeah literally hardware infrastructure like real hardware bare metal as they say um oh wow mid-June mid-June calls itself first community funded AI research lab. That's a nice I like that look we are lean self-funded to see the team always hiring mid-June has no investors we are funded by our own community. That sounds like the community has ownership which they do not so I'll break it to you but that's the same with customers or my investors which does well I mean yeah non-dilutive capital means I own the ship anyway but I mean look it works I mean look it works for them and I think that something like incredible that you can build AI businesses without burning credits burning

the whole anyway uh how do we get there I mean yeah telecom we don't sell tokens. You still don't have any yeah I wasn't gonna come back to say if you don't have any AI what where's your growth coming from yeah like who would have thought people still use SaaS. SaaS is not that no I mean it's uh yeah it's I think we just continue to do a good job and build a good product that people love and pay money for it's not everything has to be AI surprise surprise. Where are you again another pun here but not on purpose where are you spending your time in terms of product like where is the innovation happening that that contributes to growth what is making that happen. I personally I spend every every day at work looking at product related topics so pretty much every major product decision goes over my desk or comes from my desk which means not only you know

larger new initiatives whether it's like an iOS app or browser extension but also looking at existing features that we need to sharpen the edges not sharpened edges softly the edges sharp obviously border radio zero and yeah like fix tons of bugs make sure to you know get enough buy-in in the company and assign resources so I would say I'm mostly responsible for the product quality today so if there's something inherently broken please send it to me I recently started to do sales again just because I enjoy doing it not because it's um like not because of a short staff but because I really just want to have this conversation with customers and learn from them and understand what they what they go through it's more like a product exploration than necessarily closing the money um that's how I spend most of my time with really

just talking to customers and then trying to bring that to life you want to take a uh I wouldn't call it a bug a bug fix maybe an issue let's call it an issue we do you want to take an issue to have in the air for me for sure yeah for sure isn't it my user I'll spend up my slot code and submit a PR um so we preschedule a lot we have in the past so we either as change log we use uh cow.com to schedule all of our podcasts our entire workflow for creating any new event that is podcast related and I do as well in sales so all my sales calls uh I do a lot of conversations with founders CEOs key uh product leaders and companies that advertise with us we have them on the podcast via voice and so we showcase who they are it's not just me reading an ad it's very unique and informative in our audience loves that uh so I do a lot of scheduling for all the surface area of what we do here and uh so rescheduling is at the core of the crux of what we do

scheduling and also rescheduling because not everybody can show up and we even had a reschedule you and I did and so the challenge that I face one of the challenge I face with rescheduling is what it works great and the only part that doesn't work great is that if I want to reschedule and my availability dictates how I can reschedule I can't break that unless I go into the event and create an override like I know my schedule and I want to reschedule it and I want to be able to pick whatever time I want on my own schedule not have to go jack with my availability to then have it open and create an override I feel like that could be a little smoother and that's been a multi-year challenge because it's never been changed and I never told you I just worked around it so to speak so here we are on the podcast how do you how do you feel about that that kind of change what have you experienced at yourself what do you think about that you know what I think I have this on my never ending list of tickets for like at least a month and I think today is a time where I

finally get to ship that I'm experiencing myself I am always annoyed I always talk about it with the team and then some it hits the fan and it gets deported but I do have to fix this and I do agree it's very annoying and we will the UX has to be spot maybe keep it keep it in the same UI that you do like a normal user would don't take you back to admin do it in the same reschedule and I'm not sure I would give that ability to the invited no do it to the inviting the one who's in charge yeah yeah because we've even had the reschedule podcast and we largely record our podcast at two o'clock p.m. and that's been a standard for us for a long time it's where we mentally block off our own day to even be present in our podcasts but at the same time it may be somebody who's in Europe or maybe even Australia or New Zealand or South Africa or somewhere in

the region where the time is far ahead 15 12 to 15 hours in advance of my time here in Austin Texas which is central standard time you know we'll want to reschedule to weigh out in a morning same day same same concept but I can't even do that in an easy way what I will tell folks is go ahead and put on the calendar and I'll manually change it in my own calendar that's been okay and I've been fine with that but I would say you know keep it in the same UI because this is great UI it functions well but recognize I'm an admin and give me a little bit more ability and maybe even warn me like hey you know I don't know figured out here figured out but that's where it should happen yeah you know what I I just wrote this in my coding agent so maybe we get a p.i. in the next two minutes man that'd be so awesome that'd be so awesome kick that off so great I would be good product is what you're trying to say yeah that's exactly exactly what we were just

doing you know you tell me something that's really frustrating I agree it's really frustrating and then it's my job to make that not so frustrating anymore I know you do that and then you just do that and then you just do that over and over again until people really really like your product yeah make them happy make them happy right I know you just tweeted about this um on March 25th just hit six oh no seven million ARR and I think you mentioned in the pre-call that numbers north of that number by a little bit because your growth rate is 10 12% per month you said it was the what it's all right I mean every month is different between five and 10 you know good months and that month but yeah I'll never we're hoping to three x per year as kind of like always in the agenda and the the milestone we want to go for which is yeah so we we are looking now at was soon to eight million hopefully soon to crack the ten and open some champagne and go to bed at

12 30 instead of 10 three in the morning well you have a party and can I be a little bit to come I'd love to sell it yeah hopefully yeah we should yeah we we we have a company retreat in Japan which we're really excited about so maybe maybe that that would be sick if that overlaps with the 10 million milestone that would be really sweet it would be so we'd be in June so April May June yeah maybe June of this year okay so you're thinking by June of 2026 potentially 10 they are probably nuts probably nuts potentially it's policy from the realm it's in the realm of possibilities yeah okay what what would what would make you grow more and what would change your growth like one of the things that keep you up at night in terms of positivity and negativity I know open source was one of them and a threat there and we've talked about that but what are the positive sides and potentially some of the negative sides that keep you up uh we do have large customers

right like we have a lot of grassroots but we're also large customers and I think there's a bit of a like a sass shop going through the industry where like a lot of companies are really deeply looking at their vendor list and and try to cut corners and cut costs and come with the argument like oh but like we're paying you too much we can buy code you and we can you don't have to buy code color come we literally open source just fork us like it saves you money and tokens like if you think that's the cost cutting approach like just self-hosted portfolio like that's much easier um but yeah that's still thing right so like um I would say the entire sass industry is and it's experiencing some sort of self-shock sass shop where you know just under more due diligence then and then in the golden days of 21 where you know the pockets were a bit deeper and the money was flowing like champagne um but I mean that's just not something that I only look at that's pretty

much everyone's looking at budgets and allocations and what to bring in house scheduling up to this day is still really freaking hard like it's not something you can just one shop like some other sass companies like we have internally stopped using certain products because it was a a weekend of cloud code to to get to 70 80 percent of that functionality yeah um sketching is just like even the first 20 percent is just still really really hard so I think AGI has achieved the moment you can one-shot calvert come without forking um that's my benchmark so yeah I bet it is that's pretty funny yeah I guess you know even as an investor in Cal and as a user of Cal because like anybody I've thought about where do we spend our money now I don't think we spend a lot of money I think I'd be like 30 maybe 60 bucks a month I don't know what the number is I want to say it's at least 30 bucks though yeah um for Cal and yeah even though we're an investor we're a paying user that does

make sense because why would you not um but I think in any case I'm like maybe I can self-host I love the self-host I'm a home lover I was like well maybe I can actually just go a different angle to Cal and not so much say the 30 bucks that was not my concern I was like how much can how much change can actually influence in my bottom line and while 30 bucks a month is not dramatic um you know what control can I get over self-hosting Cal.com you offered open source for a reason you even blessed the Docker image I could run so you make it super easy breathing inconvenience to self-host cal if I want to it's definitely crossed my mind I didn't execute on it it was in my to do list to look into it but only as an exercise of could I not so much should I and I think that's an interesting place to be and around Sass do you have you felt because you're growing but have you felt a retraction and has it been that has it been self-hosteders going and doing it I don't think it's going to be a case but like no one's going to self-host countless they really really want to

well there's I think there's two reasons people self-host as you correctly identify one of some is I want to tinker with it and play around with it and make changes and the other one is security and like putting it behind your own firewall those people have always existed we we do have governments and healthcare that self-host right and they new slash also pay us because they want to and they need support and they need feedback and help and developer our office hours and compliance help and set up and they pay us well so we do have a really small amount of people who self-hosts and pay us now they're most certainly our joker file I haven't checked at it in a long time Calcom has many polls has over a million installations so take it or leave it that's

a really big number we're not in totality or by a certain measure whatever docker hop tells me I don't know the it's the analytics of docker hop are really opaque but it's been pulled a million times now is that a million customers know but it's also not ten yeah so anywhere between ten and a million people are using the self-hosted file container so there's a big number it's not it's not nothing it's it's obviously not a billion people but it's you know it's a million polls but we don't charge them that's okay they would probably be on a free tier you know if these are individuals they would be on a free plan our free plan is as liberal as the open source version we always wanted to be like you don't have to be self-hosting in order to get the product for free right you can be on a sass tier and be for free right I think where where the revenue is coming from

it's just people want to move fast companies want to move fast self-hosting takes time it puts the burden on you to keep it safe and updated and and maintained and a lot of people just simply don't want to do that I mean why is renting popular sucks I'm it's just sometimes you just want to rent and pay people money and then when the sink is broken it's being replaced you know yeah limit your liabilities limit your responsibilities yeah limit your accountability limit limit limit as I like to do that I mean I don't rent purse in my homeowner but I do like to limit my liabilities who doesn't that's just exposure right yeah yeah I mean even that I own my own cars to like I don't lease I lease services and things maybe but not really like those kind of large items and I know people that have said all this is wise or this is not one or or this can be you know this goes from a cat-back to a you know whatever X I mean simple I like to own things like yeah

yeah I mean you can go either way so I imagine this shift from how you're forking your own code base I imagine you've thought to some degree and maybe you haven't have you consider just literally going close source completely um and going like the TL draw route where they have TL draw license it is literally not open source it's not even using a source available license it's just source available and issuing out a license key and being very uh I guess smooth with how you might license something so you might have an an experimenter who's trying to figure it out maybe you've got a home lever who literally wants to home lab and host self-hosted and you just give an instant license key have you ever examined that that wrote it all when it comes to close source source available uh and the only way you can really use it is literally with a license key

otherwise it's in like a demo mode I have never seen the TL draw license and they actually made it up themselves that's so interesting yeah it's a had him on the podcast uh a little while ago it was a really good conversation I'll give you a Tio a Tio DR of this I'm looking at it right now um those violations the TL DR of of their success they largely sell an SDK so they don't even sell you finished software we we came with the analogy during the podcast it's like orange juice concentrate that you put in your freezer you add the water right like it's not even a complete product it's a complete SDK right and that's what they sell and they sell it as close source it's source available and there's been some talk even uh you know they were out there on x famously pulling back their test week because you can easily replicate TL draw from the test suite you know that's I'm sure you've been down that route I've seen that the threads and stuff like that but uh I think it's

because of the threat I'm not anti-opensable because of the threat and the desire to have a sustainable commercial company and have source available because of the reasons why source available makes sense for trust but have that relationship so what a license key let you do yeah and of course in this case is literally everyone who is a user gets a license key and you're very liberal with how you distribute those license keys that are non-paid so you want to be very open with it maybe even instant with a home lab key for example um but you get an email and a name and you can forge a relationship that's very different from here's our free and open source you know cal dot d y d y d y y what is wrong with you today Adam cal dot d y you know you don't have a relationship with anybody who uses it really unless you force the relationship or desire the relationship or get that inbound issue which you don't even really want I mean maybe want the issues but not the poor requests so what do you think about that license key world have

you have you examined this thought at all so as of today or whether the current way the repository split is that you can fully self host cal dot com and then there's a couple of pro features that do require a license key and that are like under a source available license so it's pretty similar what you're explaining the only difference moving forward is that that source available will go private source right so the the cal dot com tomorrow will strictly be an hplv3 potentially even MIT I'm we might even change the MIT um because it's no longer commercially used by us like it's it's there it's public but it's more of a public good than a commercial um asset so the but the source available part will go private source because it's already commercial and it's very sensitive um parts of the product that should not be for the public eye that's kind of like the

I think the decision we made we're not so we we would never take anything well first it's not possible but we would never take anything private that's previously open source but what we do take private in a sense is that we no longer have the source available commercial parts also source available we take that private source and I think what the but the initial question you had just to go back to the initial um start was why even stay open source I think at the end of the day um we are forced to make a decision here whether it's to write over on one time we'll tell the market we'll tell on the technology we'll tell we don't know it's just it feels like the right one a lot of people in the industry agree with me and secure to experts agree with me which is sad I hate it like I don't like it but that's just what it is so we do not want to give up

the open source ethos we keep cal.dii for south hosters for anyone who's you know excited to contribute and and be part of this community it's just simply not that instance that we would be running on our production environment right that that's really just in a tier tier DR or tier tier driver tier DR like the only differences the open source code is now fully open source project we don't run it ourselves we give it to you you can run it yourself if you want to but we have a commercial fork of that thing that can do a little bit more and is a little bit more safer so in a way it's not like we're a private source company you know we just use our own like we use our community addition as the foundation and then we put some locks on it you know given what you share with me and what I've also been seeing myself in terms of how

things are changing I'm I'm sad too by that but I'm not the state is what it is I suppose and I'm I'm sad by the fact that's the fact but I'm okay with how it makes sense to protect the investment the company that you have our responsibility to run one.the customers right like the customers right like sure the the the data we're processing is no longer fun like we have really like like like like important data we're processing right like people are we're so what is going to be at we're who they're going to meet with at a certain time and I know you have like abilities to chart for meetings this like that's like even that you know whether they're making money there's a lot of things you can get from that that that you can you know cross examine with other data that and pick it up none of this none of this is sadly like look if you run a

at chill open source project that I don't know makes a button green and glow when you hover over that's very different to having millions of customers who you know interact with each other whether it's a chatbot you know whether it's discord it makes a discord gets broken open tomorrow and every single DM this public that would freaking suck so what's suck so open source is not dead but it's changing well would you agree with that yeah 100 percent I think I also don't think that commercial open source is that you know open source is creamy open source and commercial open source you know the sub categories if you run a framework you find if you run a package you're probably fine as long as you have your dependencies safe and secure if you run a commercial open source project probably make sure that it's not the same that's running on your production environment and that's usually a good advice but commercial open source is still really valid and

fun and and just a fulfilling place to be in it's it's it's it's a lot of fun yeah all righty well piercing you so much for this situation is depressing it's not it's not a happy ending yet but I do think you know I think what I also hope is that people just simply understand I think there's always haters out there who try to read into into things but I think my my hope is just people just just get it like yeah make sense sucks but I should say it yeah we are at a at a unique position in place for sure and I think there's hard choices to be made and I think things are definitely changing all around and it's a TBD on where it lands in terms of that change I'm long open source same yeah I really am and I hope one day we get back to where it

you know we can be even more forthcoming with with details but I know when you're a high value kind of property it makes sense obviously to do what you need to do to protect yourself and your customers and no one can really value for that and I certainly appreciate the non-route pull aspect of it you know I think there's a lot of folks who would just simply rote pull and that's not at all the case and then you know if you were starting fresh and green and brand new maybe you never even go open source at all maybe you start literally as close source proprietary and you prove yourself in the market or you don't you know I think that the lore to being a commercial open source company these days is dramatically different than I was four years ago totally yeah and and we we don't even know where coding comes out and a year from now yeah so like I think the most important skill for any founders you know like you have to adapt and we're adapting now and you

need to be okay with that change you know we're no longer a buck we're turning into a private butterfly so you just need to be okay with that transition yeah well here thank you for keeping me on time with all my time with Cal.com big fan like as you know a big user as you know daily active user of Cal and I love it I think I when we started using it when we first invested never look back I've you know hit a couple scenarios but you've fixed things over time it's gotten smoother easier better up time has been always amazing and you know for me five stars well I would only I would only knock you maybe a quarter of a point on the one thing I mentioned in this pod but maybe after that it's back to five stars again and I just got a notification from my coding engine who shipped your PR to override hosts get out of here yeah so during the time during the time and I just were in these days and I didn't do a single thing and it looks amazing

so come on now we shall see what happens we shall see while I look forward to using that feature I can't wait yeah I can't wait you'll be the first one to test I'll send you nothing all right here well thank you again for coming to the pod it's been good talking to you I appreciate you thank you well friends a lot is changing out there I don't know about you but every single day I open up X with trepidation and anticipation at the same time like oh I don't even know you know can I get a reset here it's not about you but I'm loving codex personally I'm not really digging club right now I haven't really ventured out to other places open source models are doing cool stuff but by and large codex codex app server and the fun things happening in and around the open AI codex world chat GPT pro world has just got me lasered in gravitational focused in and I'm liking it so I'll be in sif's go here in a few weeks September 14th through September 18th if you're in SF

I would like to say hello I'm trying to plan an IRL yes a change log IRL if we could do it fingers crossed at planet scales headquarters I don't really hope we could do that if the stars align we're making it happen if you're not yet a member go to changelog.com slash community it is free to join get in zoolup get notified of all the things happening and I'll see you there big thanks to the sponsors of this podcast coda.com work os and build kites and of course our partners in crime fly dot i oh okay friends that's it the show's done thank you for tuning in we'll see you again soon you

More episodes

More from The Changelog: Software Development, Open Source

View all episodes →