The Changelog: Software Development, Open Source - Forking Cal.com to closed source (Interview)
Episode Date: September 3, 2026This week I'm joined by Peer Richelsen, co-founder of Cal.com. What if the majority of open source repositories are already compromised and we just don't know it yet? That's the theory Peer brings to ...the table this week. We dig into how AI has flattened the knowledge graph to the point that a 16-year-old can vibe hack a power station just as easily as their mom can vibe code an iOS app, why the reporting culture that has kept open source safe all these years is collapsing under AI generated noise, Cal.com's move to fork its own codebase and take the sensitive parts private, and the eye opening reality that shipping "$1 of AI tokens for pennies on the dollar" is now a common startup business model.
Transcript
Discussion (0)
What's up, friends.
Welcome back.
This is the change log.
What if the majority of open source repos out there, they're already compromised, and we just don't know it yet.
That is the unsettling theory.
Pierre Richelson, co-founder of cow.com brings to this podcast this week.
We dig into how AI has flattened the knowledge graph so a 16-year-old can vibe hack a power station as easily as their mom can vibe code.
and iOS app, why the reporting culture that has kept open source safe and secure all these years is collapsing under the AI generated noise, slop, whatever you want to call it.
Cow.com's move to fork its own codebase and take the sensitive parts private and the eye-opening reality that shipping $1 of AI tokens for pennies on a dollar, that is now a common startup business model.
Lots going on. Lots changing. A massive thank you.
to our friends and our partners at fly.io.
Your agents, they need computers.
My agents, they need computers.
We host everything we do on fly.io.
And you should too.
Check them out at fly.com.
Okay, let's do this.
Well, friends, this episode is brought to you by our friends
at coder.com secure environments
where developers and agents work in parallel.
And I'm joined by Nikki Pike, Field CTO, Forecoder.
Nikki, what is the field CTO?
So I get that question a lot.
And it's, you know, half the people understand it, half the people don't.
So a field CTO, I describe it very simply as we're Dev rel for the C suite.
So we provide a bridge between the customer voice, between the C suite and the managers and the leadership teams of our customers back into our product.
And then we go through and we help enable our teams to have the same message to make sure that the message is correct.
and that we're building on something that people actually want,
not just something that we think they want.
Okay, so we're taking the laptop away from the developer.
Not really, though.
We're putting them in a cloud development environment,
a secure environment where they can work with their agents.
In parallel, these are blessed environments.
What's wrong with the laptop?
The laptop is the trap here.
And not only because the fact that it could be stolen,
you could lose it, it breaks,
and you're out of work while you're waiting for a new one,
but there's also just the consistency that you got there.
We all know developers.
Developers are going to be looking for some of the latest and greatest,
and if you're not really controlling how they get out there,
that's where you get this.
It works on my machine.
It doesn't work in production.
It doesn't work anywhere else because you don't have that consistency.
You don't have that ability to really standardize what that environment looks like.
And this is a problem not only for new people coming in, you know, the onboarding statement
is average, I think, is like four to five weeks for a new employee to really get their local
laptops set up and ready to start doing their first time of code.
And, you know, the time to first commit is a metric that almost everybody knows.
And the reason they can't do that is because there's a lot of tribal not.
out there. They got to go talk to other developers. What are we using? Where do we get our
dependencies? Are we getting them from public? Are we getting them from private repositories?
But there's also the security and the supply chain aspect of this. When you have local machines out
there, look at like the shy Hulud, you know, that virus that went out not long ago. This was a compromise
of the MPM public repositories. They went and downloaded things. MPM did what it did. Next thing you
know, you're compromised. But when you use something like what we're doing with cloud development
environments, then you can mandate and you can put restrictions on there to say, hey, you can only go
get your packages from our private repo. Those packages are expected to have been thoroughly vetted.
We know that they're clean. Now, does this stop everything like Shai Halud? No, if that compromised package
gets into your private repo, you can still have that, but it really reduces the surface area of the
attack. And it also reduces the blast area of the compromise should it happen, because if your
laptop gets compromised and you have to kill the laptop for whatever reason, that's weak.
out of work while you're either fixing that or you're getting a new laptop in. The cloud
development environments allows you to kill that, start back up fresh, and you're back and running
in five minutes. You don't have to wait all that time. Well, friends, the first step is to go to
coder.com, install coder, self-hosted environments for your teams to enjoy, to standardize
around, and it's open source so you can try it out today. Once again, coder.com.
Well, friends, I'm here with an old friend. It's been a while. It's, uh, it's been too.
To Lump here.
Great to know.
Co-founder of one of my favorite companies out there.
I use you daily.
Cal is how we scheduled this.
Thank you very much for being the backbone of all my scheduling.
It is about time since we've gotten back on the pod.
Yes, the poem was intended.
Thank you so much.
I think actually our first pod was really about how it was about time,
where the initial conversation sort of began with this era where
Cal.com, I'm not even sure if you had cow.com at the very moment we did that podcast or not.
But it was,
We were users of Cal and when I say we, I mean the organization changed log.
And Cal only has been around for a while, but they had changed.
They weren't working.
I mean, a lot of different stuff, which I'm sure you're aware of.
But one of the things, one of the undercurrents, the themes of that podcast was it is about time.
And so you know this very well because you probably live, eat, and breathe, all the things around time being one of the co-founders of Cal.com.
But thank you for going back on.
And yes, it is about time.
Thank you so much.
It's been time and we need to make more time.
I think it was right around the time when we bought Cal.com,
which may or may not be four years ago or three years ago.
Time is a weird concept.
It is.
So, yeah, thank you for having me again.
I'm excited.
And I guess, like full disclosure.
I am a very small check investor.
in Cal, a very small seed investor through, I think, your angelist stuff that you had way back.
And that's how much I believed in it because I was like, okay, I think even then, if I'm recalling correctly, because I'm trying to go back on my own memory, open source was core to your mission.
You know, you've been open source for a very long time.
Your commercial product is probably licensed differently, which I'm not familiar with exactly which license you chose and how that sliced out.
I know things are changing even too this year around open source.
I'm sure you have thoughts on that.
So I'm happy to go wherever you want to.
But yeah, big fan of cow.com user daily of cow.com.
And it's been too long to catch up.
And I'm sure that this new era of cows can be different.
I suppose in this next era of agents where you probably have a lot of folks using agents
to act on their behalf to maybe create events, manage their,
availability, even book time with someone.
What is it like in this world that we're in with agents running amok or maybe not a muck
in this air for you?
I think all the cards have been shuffled and nobody knows what's coming next.
I think I don't think there's a single person who can predict what the outcome's going
to be is like predicting how a certain stock goes like that person is a liar.
You can never really say,
what's going to happen.
But one thing for sure is that I think a lot of things are happening
that we could not predict as easily as before.
Like usually you start a SaaS company,
you have a playbook, you know, you have, you know,
you get from zero to one million, from one to ten million,
you know, from ten to a hundred million.
There's certain, you know, pattern matching and playbooks, etc.
I don't think any of that works anymore.
And even when it comes to how to, you know, build,
public or how to build open source, how to build, you know, the safest software or the fastest
growing software.
Like everything has been reshuffled.
I think about seven months ago, we joked that Dario sat.
Like in six months from now, everybody will be using AI agents to write code.
I have not written a line of code like in weeks.
And same goes to our anti-engineering team.
It's all code, code gen and AI agent.
system. And so it's like that prediction was so whack seven months ago and everybody was laughing at it.
And now it's just like it's the technologies here, right? And so the question is like what,
what else will change in terms of, and I can only focus on startups. I don't want to touch broader
society aspects of like how what's the meaning of jobs and work. Like I don't want to touch that.
But, like, I think for startups, like, it's a really weird time right now.
Like, some time that you could never really predict before.
I mean, these startups are always a weird journey.
But now it feels like extra volatile, I'd say.
And I think to get to your point to open source, and I think open source multiplies that by, like, a factor of 10.
like you're basically drinking from the fireholes because you know when you're when you have a private source a close source business you're the only one committing to it there's no such thing as a public repository where people can like look inside and contribute etc etc for open source businesses and i strictly focus on commercial open source um you just have so much noise and like back in the days
it was like, if somebody opens a pull request,
you would immediately know, okay, it's black and white.
Either it's a well-thought-out poll request,
and you can, with tests and everything,
and well-thought-out structure, or it's whack.
And if it's whack, you close it.
And it's like, anyone can look at it and be like,
okay, yeah, this is worth closing,
that one's worth reviewing,
and then you build on top of that
and you engage with the author.
nowadays, everything looks the same.
Like you get a pool request and it's always written by by clot code or by maybe codex or maybe if you're lucky by some other coding assistant.
Right.
But it's like back in the days you had a thousand open source contributors and you would have a thousand opinions, right?
And one person would do something and then the other person would like reject that idea.
And now you just have a thousand people using two different coding assistants, right?
And so it's like this whole notion of like the best idea wins, it's like the best large language model wins.
But you only have, or maybe the best prompt given to that large language model wins because there's still some variation among prompts, right?
But like, it's really, really hard to distill what should be merged into the project and whatnot.
And then what's even worse is that like the confidence of that pull request is so high.
because the large language model is like,
here's the best thing delivered to you on a golden plate.
And then you start to peel off the layers of the And then you're like,
wow, even these tests are like hallucinated.
Like none of this makes sense.
Like it looks so real, right?
Like it's, wow, this is like the best thing ever.
And then you start to run in.
You're like, wait, why is that thing hard coded?
Like, what, you know, like so many question marks.
And it's like, you're like, why am I even reviewing this?
And so imagine being a commercial open source company.
There's so many tweets out there.
We don't even need to reference one.
There's so many.
Just search for like open source and AI.
And then like shutting down external pull requests and having this like vouch system
where only like really close people who went through like multiple rounds of interviews
are able to commit to the repository because it's just so much AI slop, like literally
AI coded slop being thrown at your repository.
So that's problem number one.
one. That's why I'm saying, like, drinking from the fire hose. Imagine you have one cracked
engineer on Claude code, like spamming your private repository. Okay, now have a hundred of those
who just, and some of these pull requests are literally just like, hey, Claude, can you
fix this GitHub issue for me? And then they open a pull request. And I'm like, okay, but like,
thanks, but I could have done that. You know, like, where's your, uh, well, added knowledge
There's no added knowledge and you're just essentially adding more slop to the codebase.
So it's really hard.
That's problem number one.
I'm happy to go over many more problems.
I was talking to a friend of mine, a friend of mine, Adam Jacob.
Did you know Adam Jacob by any chance?
Is he a name you know?
Adam Jacob.
He's famous for being the founder of chef and maybe infamously being the founder of chef.
If it was here, you'd probably be laughing at this moment.
But he created a company called System Initiative.
Yes, back here.
And they had begun to rethink CI.
No, sorry, not CI, but they began to rethink infrastructure.
It was very visual, very innovative.
But they focus on this visual layer, and this is pre-AI.
And obviously, we know how things have played out.
And so they've sort of failed product market fit,
but a lot of the ideas were still really good.
And they parlayed a lot of that good stuff into what's now called swamp.
Dot Club.
And they are AGPL V3 open sourced.
Yep, same.
But very specifically, they are open source but not open to contributions.
They do issue-based contributions now.
Is this where you're thinking of like, hey, you can file an issue, you can file a bug,
you can file your concerns, but we'll never accept your pull request ever?
That's fine.
I mean, I think, so here's my, here's my current issue with everything open source.
We're clearly training AI.
That's okay.
I mean, that's kind of like good.
AI companies are already giving open source companies tons of free tokens, which is, you know, great.
Like, I have a free Cloud Max.
I have a free Codex.
I'm very grateful for that.
that I understand that we are producing the code that they are training the next large language model on.
And that's, I think, it's fine.
I mean, it's still violating the license, I guess, but, Philairee.
But I think the problem is that when entire open source repositories, as it is right now, gets overwhelmed with slop, it just destroys code quality.
I mean, look, it's still our job to, as maintainers, to review and approve and merge and change poor requests.
So it's still our job to make sure the quality is high.
But it's just so much more work now to differentiate between bad PR and good PR that it's simply not possible, like humanly possible.
And I know Peter from Open Clause said he's not reading his own.
divs anymore, like his own
clod or codex
PRs.
I don't think necessarily that
that's the solution that we just
like close our eyes and hope for the best and
like have tests, etc.
Because there's this
graphic that was like the moment
you introduce slop to your code base,
now the coding agent looks
at your existing project and then
adopts bad practices
and it's kind of like a recursive
loop of poo, right? Like it just gets
worse over time. Same thing happens with large language models, right? The worst quality of an
open source repository, the worst AI will be in the future learning from that bad code, right? And so
that's another issue I have with open source where if you cannot get the resources in place to actually
have really, really high quality. And be in mind, that means you need to end up hiring really like
IC5, IC7 level people who know what they're doing.
Because you hire a generic IC1, IC2, IC3, chances are they will be using cloud code.
And they're incentivized to use cloud code because that's just how the whole industry works today.
And that's okay.
I'm not saying that's bad.
But like you still need these like, sorry to say this, like study computer scientists who know what O.N is.
And a lot of them don't.
And so yeah.
It's not a great outlook if slop gets multiplied, you know.
So I think the whole training aspect and the, you know, code and public aspect is really, really becoming an issue.
Yeah.
As you're speaking about your concerns and challenges, I'm looking at cow.com's open source repository,
GitHub.com slash cowcom slash cow.com.
and I'm on the port requests
tab and you can probably see
there's just an immense
more than you would probably ever
want to or be able to
there's no chance
there's no chance we'll get to the bottom
of this it's just so it's
well and this also
hurts the community right like
people expect to get the same
level of treatment for like a one
line hey claw please fix issue
115
then someone who's investing
deep knowledge and time and resources into making something better that they feel deserves to be emerged.
So it's like, it's almost like, how would you describe this best?
Like the best way, it's like, it's like mass propaganda where you just post so much misinformation
that it's just impossible to know what's the truth and what's not because you're just
drowning in the sea of everything's fake.
and then the reality just gets murky, right?
And the same with poll request.
Like, you just don't know what's good anymore when everything looks equally good.
And then there's like a Stella PR and then the rest is just two line prompts from Claude, you know?
So it's like, it's really tough.
Like, it's, I don't envy any, I don't even envy premium open source maintainers who back in the days would be happy.
You would be happy for every poll request.
that would come in.
You would be,
heck yeah.
Like,
something is just my stuff.
They think something,
I could change it.
Yeah,
let's do it.
When,
when we first had a conversation,
we probably had 20 open pull requests.
And then when you had like,
suddenly you had five more,
you'd be like,
whoa,
where did they come from?
And you would like reach out to these people
and be like,
individually like,
oh my God,
thank you so much for,
you know,
contributing the system in a blast,
et cetera,
et cetera.
So it's like,
yeah,
it's,
and it's,
and it pains me because also there's,
um,
this is another problem that people are facing that they think they are more likely to get hired if they can show open source contributions.
So now their entire pipeline is let me find the top 10 repositories, let me orchestrate 12 different agents, and they're all trying to find different issues.
Like basically the cloud instruction is find the most uploaded issue and then submit a PR and these five different.
It's almost like you're spamming your CV, which is also really terrible strategy, by the way,
into like hundreds of companies and trying to hope one of them sticks.
And then your AI agent comes back with like, oh, I've opened 20 different poll requests and these and these and these different repositories.
Does that make you more likely to get hired?
I don't know.
So it's weird.
It's a really weird time.
I'm not saying there's a, this is, it's weird.
It's weird. We're really struggling. We're really struggling.
Yeah. Well, I mean, so let me, I didn't say the number. So you've got 358 pull requests.
Yes. No, sorry, 356. Yes. And that's still a lot. Even 358 is, I mean, it's two more.
It's a lot of cool requests.
There's not a big dramatic difference there between 356 and 358, but that's a, that's a dramatic amount of full requests.
If that were my pull request inbox, I would just say inbox zero it and just cancel it, right?
I mean,
Nook it.
Or just literally cancel the PR tab altogether, which I think is kind of when I was mentioned before,
Adam Jacob, his philosophy was swamp.
Yeah.
And that is the URL, swamp.
Dot club.
It's the coolest thing ever.
And you guys check it out.
They're just like, forget it.
We're not going to do it.
And I don't think their problem was the amount of poor requests or even the poor request that would be or likely be a slop.
It was more like we know what we're building.
We don't we want to build.
We're happy to take your ideas.
We just don't want your code.
We want code that we would write that matches our style of code that our engineers can curate, whether it's with an agent or not.
It matches our style.
It matches our lingo.
It goes at our pace.
fixes our problems that we think are worth fixing.
We're happy to hear your ideas.
We want you to use Swamp.
But it's issue-based co-contributions.
And you'll give us the problem or the challenge or the solution in in pros.
And they may even bring that into context behind the scenes.
And they may even write a prompt.
And they may even write the initial prompt that starts the journey.
I agree.
So there are clearly, there's multiple reasons.
benefits to be open source, right?
Like something simply have to be open source.
React.js has to be open source.
JavaScript has to be open source.
Python has to be open source, just to run the thing.
CalaCom necessarily doesn't have to be open source, right?
So we've been open source for many different reasons,
but in order to run it, that's not what we're open source.
We're not a JavaScript framework.
We're not a UI library.
So for us, the pitch and the idea was always like build in public, build trust,
and then another thing, build the most secure code base because I would say up until January 26,
I would say open source is always more secure than close source.
Like I would stand by that statement.
And that's the problem.
Today, I no longer think that.
So like the pendulum has swung, you know, if this is like very safe open source, because
bear mind, when you were open source, you had security researchers making really good PRs,
fixing the holes, fixing vulnerabilities, reporting vulnerabilities.
There was a reporting culture.
The reporting culture no longer exists.
99% of the reportings we get our AI generated.
Like we have an inbox security at Cal.com that people send vulnerabilities.
and 99% of them are AI generated,
including that email that sends it,
because people are spamming repositories,
and half of those vulnerabilities are also hallucinated,
like they just simply don't exist.
You reproduce it and it's not there,
or it got something wrong and it's using the wrong API endpoint.
So the culture of open source makes you more secure
because you have actual human beings
who know what they're doing, checking your code base,
has kind of fallen behind.
And then at the same time, so that's gone.
And then at the same time,
the autonomous attacking tools
have gotten so good
that the amount of knowledge needed
to attack a repository
is basically can you run a shell command in your terminal.
Right?
So like, we went from patent testing requires crazy amounts of tooling and knowledge and reverse
engineering of APIs and a man in the middle attacks and yada, yada, yada, yada.
Like so much work had to go in into basically finding and abusing vulnerability.
Let's say you're a black hat hacker, right?
Like, let's say you are an evil person.
You want to extort people.
It was really hard.
You had to be really good.
These are really smart people who would execute those attacks.
Nowadays, maybe not with Claude because of all the security features,
but there are large language models out there that are so good at pun testing and cloud security,
to be honest, of their product, that it's really easy to find dormant vulnerabilities.
Like Firefox had like 12 P0 vulnerabilities reported by AI.
React, React had vulnerabilities found by AI.
NextJS had its own fair shares of vulnerabilities reported by AI.
So it's like, we're really in trouble because I'm not saying our engineering team is flawless from pre-AI.
Like obviously this is not AI versus pre-AI code.
But the amount of money, resources, and talent to find and abuse vulnerabilities has like,
100 X'd in terms of ease of use, right?
And so you're giving basically evil people a single prompt in their terminal to find
an abuse open source repositories.
So the whole pendulum of like, oh, we're open source.
We're more secure.
It has completely swung in the other direction where it's like, wow, this is so easy to
hack any open source repository.
My theory is that the majority of open source repositories are compromised right now.
we just don't know yet.
Like Firefox has 12.
Firefox is 12 P0 vulnerabilities.
Like what do you think your open source repository is looking like?
You know?
Yeah, that's funny.
It's not, it's really grim.
So, yeah.
We just had that, you know, one of the more recent ones was light LLM.
It was compromised by supply chain attack.
I mean, that was even more unique.
One, it was malicious in how it executed it, but how they got there was really interesting, you know, the social engineering behind it or even just getting the keys and stuff like that.
And using the blessed pipeline to get the thing in the pie pie, you know, that was really interesting.
And we're seeing that more and more and more because there's always been holes, right?
I think what you're trying to say, too, there's always been holes.
And it's not, you know, a then versus now kind of thing.
No.
It's that now the holes.
The execution layer is so much more efficient.
Right. Well, the tool is now more evenly distributed.
So the knowledge graph has kind of come down to every human being that is in some sort of first world scenario that can afford 20 bucks a month, maybe even the free version of it.
It has the same access to the same tool that the world's greatest engineers at some of the biggest companies are using, right?
We're all using a version of the similar and same tool.
And so the knowledge graph has kind of flattened dramatically.
And you're right.
the bad actors now have the same thing.
And not only do they have the same thing, it's a faster tool than we've ever been able to script before.
We've always been able to script.
Bash has always been there.
And sure, it's always been fast on a given CPU.
But now the ability to write it and infiltrate and to just pen test.
Security research is called this vibe hacking because you're no longer knowing what you're doing.
Like you're literally just instructing the agent.
the same way you have vibe coding and now like everyone's everyone's neighbor is vibe coding their iOS apps,
which by the way is great.
Like democratizing access to technology, big fan.
But like what happens when the same like when the mother is vibe coding an iOS app and then the 16 year old son is vibe hacking the power station nearby, right?
Like that's not great.
So the yeah, as you said correctly, like the access to technology also means that.
like malicious hackers have, like they are so happy about all of this, right?
It's like a birthday present.
Like, what do you mean?
I don't, I no longer need to, you know, do spend 16 hours studying the code base.
I can just have an AI, find all the holes for me.
That's awesome.
Here's my Bitcoin address, pay me money.
Otherwise, I publish your data on the dark web.
Like, you who, yay, that's great.
And even that is probably fully autonomously executed,
including sending the email and opening the wallet and checking whether the funds got received.
And it's a great situation in here.
You seem very grim and not very excited about the future of open source.
Would you agree with that?
You think things are just in jeopardy or what?
I think I would probably summarize this.
Like if you run a commercial open source business, you have a huge target on your hat
because you are a business.
And a business means you have customers,
and the customers mean you have sensitive data
and you can potentially be extorted.
If you run an open source free GitHub project,
even if you run OpenClaw,
like OpenClaw does not have an enterprise
that they sell to Fortune 500 that runs on the same codebase.
Even if they had to,
they would probably not publish it on the same GitHub repo.
So it's like if you run a UI framework,
a library that, I don't know,
helps you work with time zones.
Like, you're fine.
Like, stay open source.
Well, unless you find, you accidentally import an NPM package that completely compromises your project, which will happen.
So that's another attack vector, obviously.
But like, but any business today that has an open source, let's call it this way, any
open source project that eventually makes a database call, you are in trouble.
And I'm saying this after five years of being open source and 15 years in the industry,
you should probably take your project private and rewrite everything that touches off database and encryption,
which is what we're doing now as Caldocom.
This has been a big change.
We've been doing this under the hood for quite some time.
But basically starting 15th of April, we're taking the commercial version.
private. So we still have the community version fully open source. You can use it at your own
risk. You can self-host it. You can run it on your own infrastructure, ideally behind many
firewalls. But the same codebase that runs on app.com will no longer be publicly accessible.
Because it's just, it's too risky for us. Like we have we have a commitment to open source,
but we also have a commitment to every single of our customers. And given this like pendulum swing,
we just, that the risk reward ratio just really sucks.
Yeah.
Is this, is the change, I understand what the change is predicated on,
but is it because the visibility into the flaws are more visible now
because the tool is better and faster?
Is that one of the kind of core reasons of change?
So the security researchers we spoke to, right?
We have a couple of those.
And obviously there's also the good people helping you with providing tools to find vulnerabilities
before the black hackers,
but everybody says if you have an open source repo,
you're like five to ten times easier to hack than a closed source repository.
Right.
So think about it five to ten times.
It's not like 10, 15 percent.
It's like five to ten times.
That's a big delta.
And so the reason it's so much easier is it's called black box hacking.
Like you basically need to guess and reverse engineer like you,
you call an API endpoint and you try to guess them it, like, what does it do?
How could I attack this?
With open source, you literally see the backend.
You see the function call.
You see, is this an ID or R or is whatever?
Is there something else that I can, like, is there a way I can inject a script or whatsoever?
And again, pre-AI, you would need to spend 18, 20 hours to research and start.
every single function call and find these things, you know, manually.
And that's what good security researchers would do and they would get a bounty for.
And that's what black had hackers would do.
And typically speaking, sorry to say this, the smart ethical hackers are faster and better
than the script kitties who just want to extort you some Bitcoin.
That's just facts.
That's always been facts, right?
Like an honorable security researcher who's a white hat hacker who gives you bounties is always more intelligent than some dumber sitting in some random kitchen hacking or software, right?
That's just always facts.
But now, again, with AI, it doesn't matter because both are just putting the same prompt, find a vulnerability in this and this and that repository, and run the same prompt.
And guess what?
The black hat hackers usually fast because they have an incentive.
right they have an immediate extortion incentive to to hack and blackmail
that's a big problem right so yeah I would be really cautious if you have
a repository that has a database that has customers in that database to run that
out in public and that doesn't mean you should you should like close your open source
we're not shutting down our repository I mean heck it's it's an amazing piece of
software that we've published, but it just means that you need to internally fork your existing
code and just make sure that you just rewrite every single function call that is vulnerable.
Like that is, you know, hackable.
You know, don't care about some random front-end library.
That's fine.
Like a drag-and-drop component, keep that.
But like the way you do off, the way you do database calls, the way maybe even rewrite your,
your entire middle layer and Prisma calls, everything,
like probably start today or start yesterday
and take all of that private.
It's just not worth the risk
until that whole pendulum swings back into security,
which, you know, could happen.
Could also not happen.
It's just, it's, it's, yeah, we don't know.
We really don't know.
Well, friends, I'm here with the CTO of Buildkite
and one of the most challenging problems.
of modern era software development is continuous integration and continuous delivery.
And so Lockland Donald, Bill Kite, CTO, what are you thinking about today's teams, the challenges
they face, the speeds at which they're developing new features, new code, is just overwhelming.
How do you all think about that?
Such a good question.
It's the question everyone's asking right now.
All of our big customers are asking us at the minute, like, you know, if we five or 10x,
our throughput this year or a thousand exit, what breaks and when.
And you know, my answer is kind of same as it's been for the past 20 years,
which is the bottleneck is still trying to integrate those code changes in
and then deploy them and check they work and then keep them working as you keep
throwing more and more code at it.
I think a lot of the fundamentals are the same, but we're just 1,000xing the speed of it.
And, you know, that changes nearly every variable.
Yeah, for sure.
Okay.
So where does Bill Kite thrive?
What particular type of team or enterprise do you thrive in?
The area that Bill Kite has always thrived in is like this fastest moving tech companies of the world.
Like we've been disproportionately successful in that small niche, the kind of Shopify class, Uber class, you know, Open AI class of folks that have this key problem around iterating really, really fast.
And, you know, the thing about all of those folks is they all have.
subtly different needs, subtly different problems.
And so we've tended historically towards building
like really well-engineered Lego blocks
that scale like orders of magnitude more than what
our nearest competitor does.
So I think that that puts our system in this tension
where you've got to spend some time assembling
those building blocks, those Lego blocks,
to get the thing that you want.
But the end result is far and away more performant
and scalable.
and the experience is better than what you get from something that's off the shelf.
So I think we've started from a position of really well-engineered logo blocks
and then are kind of working backwards towards kind of creating the thing that scales down to
a startup that starts with one person and ten agents next week.
Well, friends, go to buildkite.com.
That's buildkitekite.com.
You deserve better CI.
Engineer for the frontier we are all facing, trusted by the teams,
setting the pace. Again, buildkite.com. Once again, buildkite.com. So the way you're,
if I understand correctly what you just said that, the mechanics of how you're making this change,
the change, we understand what the change is influenced by. But then on the how,
you're saying to internally fork, and in your case, your commercial open source company.
And so you've had all of your code out there. Your open source has been licensed one way.
But if you go a certain way, there's certain features that were always available.
and open and open source, source available, that you can see.
You're saying that you're changing that so that all of that codebase will remain there.
The license of free and open source will remain the same, but internally your mechanism is to fork it and rewrite the areas, the surface areas that are at risk or at most risk.
Yeah, correct.
And we also obviously point the production URL to the private repository, right?
So like, because, you know, what you see on GitHub today is what we've run on the website.
That's just how open source works, right?
That was the whole point.
Like, you see the code that runs my service.
That was the whole spiel.
So that spiel is no longer safe enough to be valuable for your customers.
Like, it's an unnecessary attack vector.
So that doesn't mean we're no longer open source.
We are still open source.
It's just that we have.
internal fork the same way other many companies like WordPress.com is an is an internal fork of
WordPress.org. I get still WordPress uses the same plugin system, but if you sign into
WordPress.com today, it's a different experience than if you get the open source WordPress.
So they kind of like did that change, well, probably more from a commercial point of view,
not from a security point of view, but I think they internally most definitely, most definitely,
have different things in their all system than what's out there, which I don't blame them.
But the narrative of like one code base for everyone, you know, self-hosted and production
environment just no longer makes sense.
It's just, it's, it's, it's, it's, it's, it's, it's, it's, it, it went from,
wow, this is safe because we're open source too.
Is that really the smartest, safest decision you should make as a business that has customers and that you want to keep them safe, you know?
Yeah.
I guess the question might be why even remain open source at all?
And I don't mean that as like anti-open source.
I mean more from a chore standpoint.
So if you've got to fork your own code base and now you don't want your vulnerabilities out there.
So that means there's a buffer layer between what is open source and what is closed source,
i.e. the fork that you have internally, the chore it must be to keep those two code bases and even remotely in sync and not have, you know,
developer gymnastics playing around.
Like, what's the point of open source then for a commercial open source company that was, you know, has been in your shoes,
but you're not making this change.
I mean, it is, it's, it's a really, it's a really terrible situation, you know, it's like,
yeah, this, this, pick your poison.
I would argue the reason to keep an open source project.
And, and by the way, we're also rebranding it to cal.diwai.
We got that domain.
So like, do it yourself essentially like, like, it's a whole, it's, it's, there's going to be
big red letters like you use at your own risk not production ready like you can self-host this
for your whatever hobby or maybe small business um i think the benefit is if people end up self-hosting
a quote-unquote community edition it's they are not going to be the one being hacked right like it's
us it's the largest company that gets the attack the one with the most money the most reputation
your neighbor barber who self-host
CalDat DIY, like A, you need to find that server,
B, you need to know exactly who you're targeting,
who you're like, it's kind of like security by distribution, right?
Like when you're self-hosting,
you're not going to be the target unless it's like a very easy to attack
multiple nodes in a way.
Like if every node runs the same software,
then you do like this mass attack.
But it's just not comfortable.
virtually viable for hackers to hack your neighbor's barbershop.
So theoretically speaking, yes, the CalDOT DIY version will have the codebase off today, right?
The potentially, we don't even know if it's insecure.
We just know it's out there, but let's say it's slightly less secure than the private fork.
Sure.
But it gains its security by being just so irrelevant in terms of distribution, right?
like five people here, 10 people there, five people here, one person there.
So you're kind of like gaining that security back by just being more, like less of a target,
you know, less of a target on your back.
And then at the same time, we can always obviously, and I'm only strictly talking about
like off and database and middle layer, et cetera.
Like if the community builds great features, we can adopt them and credit them.
we build sick features, which we do, we push them back into the open source community edition.
So I hope to keep that relationship strong, the same way WordPress has been doing it for many
years.
So it's not like a unique idea.
Like we've always had private and public forks of open source projects.
Docker has its own enterprise edition.
That's private source.
Yeah.
But like I think, and if I'm being honest with you, all of these forks have been for commercial
reasons. Some investor has pushed you, some IPO, some bank looked at you and be like, we need
some proprietary code because of whatsoever. So it looks better in our brochure. But trust me with
my fullest heart, this is not a commercial. Like we are, we are growing like 7 to 12% month
over month. We are not in any way short on cash. We have no investors who are bullying us to go
private source. We have the most open source friendly investors on our cap table.
we had to convince them this is the right decision.
This is like a nuclear problem for commercial open source.
You know?
And so it's, I wish it was a commercial decision because then I can like say, okay, this is only affecting us.
But this is, this is affecting the entire industry.
This is like a, yeah, like the quantum computing cracks encryption type of level.
level, you know. Yeah, that quantum, what they call that quantum safe or quantum ready in terms of security and whatnot.
Exactly. Yeah, exactly. I mean, that's, that's really insane thing too. What other examples can you give? I know that you kind of give a couple, but what are some explicit examples of other commercial open source companies that think like you do or have the same problems you do? And can you enumerate their challenge in the public that's being showcased?
Well, I can, I can, I have many conversations, you know, that I really cannot make public because of security and like in, just in the risk, the inherent risk and.
What's on?
What's on X?
What do you see on X?
Yeah.
What would you retweet?
Well, I mean, well, I mean, I can definitely talk about public situations, right?
Like there's, and I also don't want to throw anyone under the bus.
But there's, you know, there's, there's tooling around logging, right?
Like lock systems that lock user.
activity.
Those products are usually open source because it's a developer package.
You need to import the SDK.
So those have been hacked by AI, which is really bad because now that attacker has access
to all your users' actions, that makes sense, like the events that they send.
For them, they are really screwed because they have to be open source for the sake of
being a developer kit, right?
So I would say that's two companies that are directly affected that I know of.
There is a CMS, which is open source, which is really struggling because when you're a CMS,
you simply cannot expose your internal systems to the world.
I mean, just think about how much knowledge is locked up in a CMS or the risk of somebody,
I don't know
imagine you get right access
to someone's CMS and you're publishing
something on Nike.com, you know?
Like that's just not great.
So there's
a lot of commercial open source businesses
out there that have
to be open source in order to run.
In that regard, we're almost
somewhat lucky that we don't
depend as much as others
to be self-hostable.
Again, 99
9% of our revenue comes from our SaaS, you know, app.com. It's not like we sell a code snippet that people inject in their business.
So, yeah, it's, and then there's a couple of payment providers that, that, like, call themselves the open source version of Stripe.
Obviously, anything that touches payments is hypercritical, you know, that's always tricky.
I don't even want to talk about crypto, because I really don't like crypto, but all of these crypto projects are being cracked open.
that open source
um
it's a wild rest out there.
And so you're you're if you were a doctor,
Dr.
Pierre. Yeah.
Uh, your,
your, your prescription for these commercial open source companies in these
high impact areas is to rethink their model and follow you in terms of
forking internally creating a new relationship with your open source version.
If you even keep it in your case,
you're keeping it, you know,
Cal.
DIY or DIY, which I think is super cool.
I had a little case of,
of dyslexia there for a moment there.
But nonetheless, cow.
dot DIY.
I did it again.
DIY.
DIY.
DIY.
Cow.
DIY.
Do it yourself.
Come on Adam.
Well, on the bright side, on the bright side,
on the bright side and maybe on the bad side,
like what's open source stays open source, right?
Like we're not disappearing.
tomorrow.
Like the rope is.
Yeah.
Right.
Shifting.
More like cleaning the rock and making.
Okay.
Vacuuming.
We're vacuuming the rug.
We're vacuuming the rock and closing the door to access it.
You can look at it.
It's beautiful.
It's a beautiful rock, but you can no longer step on it.
No, because like, look, there's like so many folks out there.
Calacom is not going anywhere.
Like we can legally not, no, we can physically not get
of the code.
What we can do is move forward gracefully
and make sure that the most vulnerable pieces
of any piece of software is not public.
I think that's a very fair statement to say
because back in the days you would have those public
because it's just really hard to hack them.
Now it's easy to hack,
thereby I need to take these things private.
And by the way, having private code
does not protect you from being hacked.
Nobody thinks that that's the golden solution.
But if a security researcher, if many security researchers say it's five to ten times easier to hack you when you're open source, you have to listen to the security experts.
If you don't listen to them, you're literally, well, probably you could use that as a way to even go to jail if you get hacked.
I don't know.
I'm not a lawyer, but like if you ignore multiple warnings from experts, you should probably rethink why you're even the co-phone of the business, right?
So my recommendation, my medicine is, first, don't freak out.
There's a high chance you're not compromised.
Most likely you run a really small project.
You're not a big target.
Second is to run many of these AI scanning tools
and just see what the blast radius is today.
Most likely it is quite high.
Like every single project I've talked to was experiencing an uptake of reports by these AI tools by like 10fold.
Like it's just messy.
It's really bad.
Turns out humans are really bad at coding for many years, including everything before AI.
So chances are you just have vulnerabilities.
That's just a fact.
And then my recommendation would be to at least temporarily go private and work on all these vulnerabilities.
Because here's another problem.
And this really, my brain, right?
When there's a hacker who actually wants to compromise your project,
they are also running code scans against your own pull requests, right?
So they, today, probably, if, let's say you really want to screw someone, right?
You would run code scans against their own pull requests.
And if you detect a pull request that fixes a previously known vulnerability that you potentially found already, or maybe not, right?
Like an AI can understand whether a pull request is a feature or a fix of a vulnerability, right?
Like you give an AI just random code and ask it like, what is this PR about?
And it will tell you this is fixing a vulnerability.
So they're using that.
I mean, whatever is technically possible will happen, right?
I'm not making this up.
I don't know personally any hackers, but that's what I would do if I was evil.
You would scan that PR.
You would identify this PR's fixing the vulnerability.
And in that second, I would abuse that vulnerability and sent them an extortion letter, right?
That's just the, that's just the scary part, right?
That's the legally, right?
Right?
That's, I should, I should not become a Marvel.
Marvel super villain.
But anyway, again, everything that's technically possible is out there and it's happening.
So I'm not giving you the playbook.
That's literally what's probably discussed in these dark web forums.
And so your best shot today is to take the repo private, fix all of these things in private,
and then merge it back into one, you know, chunk.
That's just your best like.
Yeah, squash that commit.
Don't give them a path to the change.
Don't feed the machine.
Don't feed the machine that's going to extort you for Bitcoin, you know?
Well, if I don't know you were talking about this when you came on this podcast,
I'd probably not to invite you.
You got me down over here, man.
Maybe we should not publish.
I mean, this is good stuff.
I think this is truthful.
I mean, this is where my head's been at as well.
Yeah.
And you're bringing some new light to some things with me.
I'm going to go back to, if you don't mind, not so much to fully back.
track, but I want to go back to your pull request tab and not specifically just yours, but the
pull request tab.
The tab.
Yeah.
And the reason why, I mean, so you're seeing what you're seeing about commercial open source
companies.
I don't think open source is dying.
I do think poor requests may be changing and are becoming not irrelevant, but just frop
with a lot of slop that people don't want to deal with.
So even projects like Ghostie, they're not taking on poor requests like they were before.
a lot of folks that, you know, like ghosty is a great terminal and for a lot of reasons it needs to be and wants to be open source for the for the true nature of what open source is, but they're being open source not open to contribution. So I want to I want to pose this thought experiment here. How does this change GitHub? Is it is GitHub a jeopardy in any way as a business? Maybe not because a lot of their commercial features are on top of things that aren't there. But like if a lot of us are on GitHub because that's what we're.
open source is. And if the relationship we have with open source changes or open source changes
enough, you know, is GitHub in a risky scenario? Because I mean, they're banking almost
everything on co-pilot, right? I mean, that's a large majority of their other infrastructure,
even NPM. I know they have some changes coming out. And I'd love to talk to whomever's
working at GitHub behind the scenes or in front of the scenes. If there is any on NPM, I'm not
saying anything negative about those folks at all. I just know that they're just know that they're
there's neglect.
There's neglect there around NPM.
So even one of the things that is the largest package manager
and registry known demand on planet Earth is NBM.
It's so important.
I mean,
that's where the Axios hack just happened.
And we know how that went down, right?
Yeah.
You know,
what is the picture of GitHub if all this changes?
What are your thoughts on that?
Well, I mean, it's not, it's not bright for commercial open source.
I can tell you that.
if you obviously run packages,
et cetera,
freemium open source,
you're probably more okayish,
or you build a new React alternative
or stealth kit,
whatever,
tailwind alternatives.
But GitHub obviously has to rethink its own,
like,
I wouldn't call it economic model,
but like,
placed in the world with AI where,
and this,
I would even say this goes beyond security,
way beyond security.
Because like,
Look, if somebody like Peter doesn't read its own diffs and the neighbor who vibe codes its iOS app,
do people really care about the source code?
Do you want to see the source code?
Like, there are probably already projects out there where the community has looked at more of your code than you, yourself,
who published that repository, right?
simply, I mean, yeah, totally.
I mean, that's going to happen, right?
Where the maintainers have seen less of the code base than the community combined.
Usually it's like the maintainer who writes the code, knows the code.
But now it's like I can prompt any project and publish it on GitHub.
And then chances I, I barely scratched the surface of the code that I've published.
Right?
It's like, as long as it works and it looks good, why would I read the code?
you know and it's safe safe so obviously distributing code almost feels like distributing binary at some point
and GitHub wouldn't work if people just publish their binaries you know I mean it still works
but like who's going to read that or like you just put the the bike code the assembly code whatever
the binary code up there you know zero zero one zero zero one that's great cool so if source code as
sad as it sounds, listen, like, I'm not a fan of this, but if source code becomes
unreadable, because nobody knows what the thing is doing anyway, so if, if nobody knows
programming anymore, if new students come out of university and they don't, they can't
read source code, they don't know what a, they don't know what a if statement is, they
don't know what a, you know, what, what point has GitHub besides being a CDN to share zip files
if Zip even is around that time or, you know, or DMG files.
Like you're basically turning into a mega upload where people just throw up all their garbage.
So, yeah, they 100% have to rethink everything about like what is the meaning of code in 2027, 2030.
What is the meaning of code in 2030, you know?
Yeah.
And then obviously it's not in any way AI first.
I mean, the fact that, you know, what I just did.
explain anyone can open pull requests for anyone, you know, there should be guardrails,
there should be rules who can contribute.
Like we're using these third party GitHub actions that like auto-close pull requests from
people who are not verified.
That's all just hacks, you know, that should be first party coming from GitHub.
Why do I have to install different third-party plugins to make sure only legitimate people
are opening pull requests?
That should be your job.
GitHub, you know.
Well, friends, I'm back with a good friend of mine, Michael Grinich.
Michael, I know that I love WorkOS.
Our audience may not know about WorkOS, but what are the challenges developers face
starting a new project?
Choosing the right tools, choosing right database, choosing right off.
Take me there.
When a developer starts a new project, the decisions that they make at the very beginning
end up having long lasting consequences.
What language you build in, what platform you build on top of, what database you choose.
These are things that are very hard to change later on.
So they have like major consequences.
And especially if they limit your ability to grow and scale, at some point, as the product
starts to take off, you're going to have to stop developing new product features and go
rearchitect to rebuild your system.
And that might be a killing blow right at the moment you need to accelerate.
So these decisions early on are really, really important.
And I think that's why developers gravitate towards solutions that are mature, things that
they know that will scale, even things that are open source.
You're going to pick, you know, something like planet scale.
for your database provider, not because it's the cheapest or because it's the most fun to use,
but because you know it's going to be a durable provider that you can scale on for years.
And WorkOS is like that for off.
You know, at the earliest, earliest days, if you look across all these different services,
they kind of look very similar.
But at day 1,000 or day 2000 or day 2,000 or day 10,000,
you're going to want to have made sure that you picked a platform that could scale with you.
And today, WorkOS is powering off and identity and security and permissions for all of these AI companies,
literally the fastest growing companies in the world, like opening eye and anthropic and cursor,
perplexity. WorkOS is under the hood there. So I think when people pick WorkOS early on,
really what they're doing is trying to pick the defaults to allow them to grow in rapidly scale.
And there's no platform other than us that's done that at that same level.
Well, friends, the next step is to go to workOS.com. Sign up today. Check it out.
Free for a million active users. Try it today. There's no excuse not to. It is.
your default. You should choose it. So do so. Workos.com. Once again, workos.com.
Did you catch that post from Mitchell Hashimoto by any chance on X?
Can you give a recap? Probably. I'll give you a recap. I see so many tweets.
It wasn't long ago. It was March 25th of this year. And he starts it off by saying,
here's what I would do if I was in charge of GitHub in this order. And he says,
established North Star around being critical infrastructure because there's been a lot of downtime.
Yes.
And you know, they got the double nine's back with the eight in front.
Yeah, he talks about coming back, establishing a north store around being critical infrastructure
for agent code lif cycles and determine a set of ways to measure that.
Number two was whatever that way is fire everyone who works on or advocates for co-pilot and shut it down.
It's not about the people.
he's trying to be kind here.
I'm sure there's many talents.
Acquire cursor.
Acquire cursor.
Right.
Pay whatever money is possible.
He says by Pierre,
which is peer to computer.
We've talked about it on the pod before.
You may be aware of it as well here.
Buy Pierre and launch agentic repo hosting
as the first agentic product.
And I can paraphrase more of it if I needed to,
but then the last one was re-evaluate all product lines
and initiatives against the new North Star,
which is really predicated on being critical infrastructure.
I gave him back those nines, of course.
And he says,
I suspect 50% get cut to make room for the different ones.
And so,
I mean,
I'm not sure if he's accurate,
wrong,
or right,
but there's a lot of folks who are upset
at the uptime and downtimeist ability to GitHub.
I mentioned before there,
I know they make a lot of money off of GitHub enterprise as well,
but I think,
they're really banking on get-up copilot.
And I just had Burke Holland on the podcast.
He's one of the developer advocates on the get-up co-pilot team.
So he's largely aware of what's going on there.
It's funny.
I know more co-pilot advocates than co-pilot users.
You know, I'm not a get-up copilot user.
I'm also not a hater.
You know, I'm not a hater, really.
I mean neither.
It's just, you know, I don't think you're trying to be.
I also don't hate polar bears.
I just don't see that on a day basis.
Sure.
I love polar bears.
What I think is interesting, if we look back,
because I've also had a podcast with Amelia Wattenberger.
And if you recall, do you know Amelia Wattenberger by any chance that name or go bell to you?
She works on the GitHub next team, which is where GitHub co-pilot came out of.
Oh, I see.
pilot was already in place and in motion before she got there, but she was a role, she played a role in GitHub next, which was sort of an offshoot of the office to the CTO at GitHub.
So it became this area to innovate.
And that office of the CTO is predicated on Jason Warner.
Jason Warner's idea was GitHub actions.
Getup actions is largely why GitHub got acquired by Microsoft.
I'm compressing a lot of the history here just for the dovetail.
And so this get up next area was this laboratory where a lot of the.
the innovation came from.
That's where GitHub co-pilot came from.
And a lot of the race and current status of the race of where we're at was,
was,
you know,
around get-up co-pilot being tab completion.
They were the first.
They were the first wild factor.
And here they are the late runner,
not the front runner of this.
Yeah.
How did they lose that?
Yeah.
Yeah.
It's just kind of wild to see the picture kind of come full,
full pendulum there on that.
And, you know, I don't know.
This Microsoft, this Microsoft has any race in the coding industry right now besides, just copilot, right?
I mean, is that the story around copilot is so, you know, the primogen.
We have cursor.
We have codex from chatypg, and we have clot or clot code, which is primarily terminal, obviously.
And then we have what's the called wind surf, I believe.
and...
I believe Windsorff turned into Carson, didn't it?
No, Windsor got acquired, but was it acquired by Microsoft?
I remember Google.
There's a lot of change there.
And then there's anti-gravity.
Anyway, and Replic.
And Replet. Yeah, true.
Yeah, and then Replet's actually doing some pretty cool stuff.
I haven't used their stuff yet, but I know some people who are.
And, you know, there is a landscape.
There is a landscape.
It's not only true, but I think what I really find,
sad about Microsoft is that I think they have the head screwed in the right place, but they just
don't have the execution, right?
Like they, they came up with co-pilot.
They were the first investors in OpenAI, the first big ones that they made it big.
They fully banged on it.
And now they seem like they profit the least of it.
I'm not really sure.
But I just.
think it is kind of while to look back at,
you know, we were all enamored with
GitHub co-pilot, tab completion,
function completion, things like that.
And
now it's not really
the major player in the race,
but it seems like GitHub is banking big
on that. But as a
team and individuals like you are
and we are that have
have, we're not
sure of the future of GitHub.
And I don't know either. I just
don't know. But I know that they're
They seem to be largely focused on co-pilot.
And their uptime has been down dramatically.
You know, Morton Woodward, who's a developer advocate for, you know, the dev team there,
he's come out and talked about it.
Ryan Daigle, C.O.
not CEO, because there is no CEO of GitHub anymore.
Came out of the woodwork and started talking on Twitter about slash X around these things.
And it's cool.
Please talk about it.
But there's something going on there.
there's something changing there.
And there's Codeberg now, which I'm not even sure who's moving to Codeberg.
I think a lot of it might be potentially self-hosted.
So what keeps you at GitHub these days?
If you're not open source, you know, if you, Cal.com is open source more dramatically open source like you were before.
What keeps you, what keeps GitHub your epicenter?
It's not really much of your episode.
I know.
And look, what happens if the user base of GitHub is agents?
It's not really a nice business.
Yeah, you know, the whole beauty, the whole beauty.
Because the reason why I struggle with that one, and I want to maybe, and maybe you can draw this line too, is largely agents, but is largely agents there on behalf of a human.
So that's where I draw the line because I've got agents and I'm a human being.
And so I have intent, right?
And those agents are acting on my behalf.
And so bots versus agents may be a little bit different.
And I'm not sure.
How do you draw the one there?
Well, how much is it a human intent if you ask a lot, like research the top 10 frameworks
and then of those repositories pick the most popular issue and open a PR for it?
Is that really your intent?
I mean, it's no different than search, right?
And search would still be, you would still say it's the top search results, right?
It's just a new way of search.
you're skipping a lot of intention that's what I'm saying like your agent makes a lot of assumptions
and decisions that detach you from it um I would say yeah that line will continue to be examined
and blurred uh in my opinion I think I sit on the side that if I were making that search to say
hey go out and find me the top 10 repositories and help me learn how to commit a PR
I think that's still user intent.
I would probably still draw that back to user intent.
I think that's cool.
And I think everybody should do that.
But if that AI makes that decision for you and just makes it for you, the PR and everything,
you no longer have any emotional connection to that.
You might not even know which repository you're agent committed to.
Yeah.
I suppose if it's fully autonomous and there's no awareness and the intent is very thin,
then it does get thinner, obviously.
I think, and that's more like an AI agent only.
I think this whole agent thing, well, first thing's first agent is a horrible name
because agent theoretically means there is a persona that has its own objectives
and autonomous decisions, right?
Everything else to me is like a human scaled with AI, right?
Like tab completions are different to autonomous coding, right?
Like you are still writing.
codes, but you have auto completion. We've had auto
completion for words since 15
years. Like,
that's just not that
crazy. But I think
the innovation came for coding
that it was actually working and not just
like
brambling weird shit.
But to the
autonomous
future that a lot of people are
imagining is what I just said,
that you have this coding
agent who wakes up at 8 a.m.
well, doesn't sleep, doesn't need to.
And grinds GitHub bounties,
searches the web for whomever,
probably the most profitable agents
will be hacker agents,
you know, that try to extort you
on a bounty versus extortion metric.
But let's say you were a white hack,
a white hat hacker agent,
you would probably
autonomously serve the web.
You would find interesting repositories.
Maybe you are looking for repositories
that your company is depending on.
You try to maybe put your own company policy
into that fringe
premium open source project
or you want to, maybe you're trying to improve
a certain library that your company depends on.
I mean, even today already,
Cloud code could analyze your code base today, and it could find a potential vulnerable open source
dependency you depend on, and it could autonomously visit that repository project and open a PR itself
on that project trying to get your fix into. That is not impossible today. I'm not sure if it's
happening at scale. It's probably happening in installation. But theoretically speaking, your agent could
hit a wall and then autonomously raise a PR in that dependencies repository, right?
That's no longer your decision.
Your decision was to improve your product, but the agent made the autonomous decision to go
out and hunt and open a PR in someone else's repository.
Yeah.
That to me is very detached from tap completion.
You, Adam, wants to improve my product.
Yeah.
So are you for that or against that then?
That particular, I mean, that seems altruistic.
Like while it may not, it's, you know, one step or two steps removed from my original intent.
Original intent is to learn about the security of my dependency graph.
And then the two steps removed is, you know, figuring out which ones have issues and correcting them or finding a correction and somebody will PR.
Are you for that or against that?
Well, I think us as this, the tech community, we need to find, you know,
We need to find peace with the fact that, like, even though this GitHub user has a human avatar,
this GitHub user has not written a single word of that PR.
Right?
Because that's just a reality, right?
So we need to be, first, we need to be okay with that.
And then the second thing we need to make peace is, did that person even think about my project when they opened this PR?
Like, are they aware of it?
Do they know me?
Do they like me?
Do they have the same ethics?
What is their altruistic intent?
Is it to improve their own dependency?
Or is it to find a job because they ask Cloud Code like, hey, I'm unemployed,
like find the best 20 repositories and get my name out there?
Or is it even trying to build it backdoor or a break of feature or change a button
that was previously most clicked?
And now it's, you know, you can also, you don't have to be a hacker to,
It's not illegal to raise a PR against Cal.com that makes our product worse.
That's not illegal, right?
No.
Highly unethical, but you don't go to prison for that.
If you ask Claudeco to make Calutcom worse, it'd be like, okay dokey.
Sure.
Let me remove the login button.
Jobs done, you know?
Let's dovetail hardcore to the right, if you don't mind.
And let's talk about the success that you've had.
I mentioned the top of the show.
Seed investor, a very small check, of course,
but I was very happy to do that because, you know,
I was using Cowanley.
I liked to count a lot better.
I liked your mission.
We had you on the podcast.
I liked your mission.
I liked, you know, this was a lot of the rage at the time to come out as a
commercially open source company.
We both know JJ.
I think you were part of OSS Capital in terms of your initial raise and support there.
So there's some history there.
but tell me about, give me as a maybe a seed investor,
give me a glimpse behind the scene of the success
that is happening or has been happening.
Yeah, look, I mean, we are blessed in terms of timing
and the renaissance of open source.
I believe that might even been the topic of our first conversation,
like where do all these commercial open source startups come from?
And they're all doing great from what I've seen,
the people that I'm trying to be close to open,
source was almost like a what do you call it like um wish that for way too long and it was still
striving think now it's getting harder again but i think my vintage of open source companies
has been pretty successful with what they're doing there's many good outcomes um and and and and and and
and and and and and and and and and and and and and and and and and and and i love open source i i wish we would not be
under this threat which
you just can't close your eyes to it.
So, no, Calacom has been growing fantastically.
We're very happy.
The teams, I'm happy.
We're reaching, I'd say, like, the milestones we set for us.
Very low churn, high growth, you know, sales, high margin sales.
We don't have a single AI product that's catching on,
which also means we're not burning any AI tokens,
which means our margins are great, still great.
it's quite funny when I talk to founders.
So like, oh, my God, we're doing $5 million in ARR now.
And I'm like, okay, and how much, what's the bottom line?
And like, oh, I mean, we're burning 10 million.
So it's like, okay.
Wow. Fantastic.
So it's like, I mean, look, every business is great.
If you're selling like a dollar worth of AI credits for 10 cents, you know, like that every business is fantastic.
that's your business model, right?
Like if you,
and then you've seen this on Twitter,
you know,
like all of these coding assistants
are like adding rate limits
and reducing usage and
trying to upgrade you into $200 plans.
And, you know,
like the economics don't make sense in the AI space.
They don't make sense yet.
Maybe they will,
but it's a,
it's an Uber type thing.
It's like,
how is this Uber so cheap?
Well,
duh.
somebody's paying for it.
You know, $15 from SF airport to the city.
Yeah, right.
Yeah, that doesn't happen anymore.
But it did.
It did.
It was fun.
Fantastic times.
I was loving it.
That was great.
That was for good time.
See, now it's like, oh, gosh, 80 bucks for that ride?
Wow.
One dollar delivery door dash?
Yeah.
Right.
That was good.
I saw something recently.
They said, we'll eat.
I can't recall what a one.
but I was so surprised by it.
They literally said in their marketing,
we'll eat the fees.
And I'm like,
that's great for marketing
because your market is like sweet.
You know,
this is a great carrot.
Let's get some people attracted.
But you're literally telling the market,
we're going to lose money.
We're spending this money to get you.
We're taking the fee.
You're basically saying,
do not invest in this business unless you like to lose money.
Yeah.
I thought it was kind of funny.
I told my wife,
I'm like,
babe, that basically says, we're just going to lose money here to get this business.
We're going to subsidize it as marketing.
Adam, if you want to have the fastest growing startup in history, you could launch a landing page
and you say, get a cloud API key that works for half the price.
We pay 50% of it.
But still pay me, right?
So you're going to have, you post this on Hacker News and you're going to make like,
a hundred million in the first year
and you're going to burn 200 million
because that's the amount
you pay 50% of it
but you're going to be a startup making 100 million
in the first year
and you can go to every podcast
and say this is how we made
100 million in the first year
without saying you burned 200 million
but that is essentially
what sadly a lot of startups
are doing right now. They add some flavor
some prompts, some system prompts,
some UI, some sidebars, some orchestration
and drag and drop.
But a lot of these startups are simply doing that, not with a 50-50 split, but maybe a 5% to 95 or 10% split.
In my eyes, it's not a great business, but for some it works.
If you can raise billions of dollars, you can do that for quite some time.
You know, the one agent that hasn't done that and hasn't done it, hasn't done it to the degree, what am I trying to say there?
they haven't they famously come out and said we're not going to sell it for less than it should it's actually expensive and we're charging appropriately is our friends over at AMP code now they're wrapping open the eyes APIs they're wrapping Anthropics APIs they're giving you versions of GPT 5.4 codex etc they're giving you versions of Opus 4.5 at all the different
variations of it and they're sprinkling their own abilities on top of that and the amp is i don't
know if it's source graph because that's where its roots came from but um what makes it so good
i'd love to like learn what makes it so good but amp i have you play with amp by any chance here i have
not no well after this podcast go and play with amp ampcode dot com i believe it was so successful
for them that they spun this out of source graph.
So AMP was a subproduct of source graph,
which was already largely popular and very successful.
And they built their own agent called AMP,
and it was so successful,
they had to spin it to its own company.
So now it's AMP code Inc or AMP Inc,
one of the two, I'm not sure.
And if I have a really hard problem,
I just know I want to get right,
I've got to use AMP.
And they have a free model,
which is paid for,
buy ads and now that's changed too that it's like 10 bucks per day you get and they basically said
it wasn't successful it was they actually put a 10 million dollar per year business in ad sales
on that and they close it down but like by and large they're not subsidizing the tokens they're
charging appropriately and profiting on it well not another business that never did that i think they're
not growing everybody else is but it's still growing quite well yeah well another business yeah i mean
Exactly.
It's like how aggressive do you want to grow?
I mean, again, you can add your flavor on an AI and wrap it and make a good UI and resell it and make money without losing money.
Like, it's perfectly fine.
It's just the, I'd say the coding space is just so competitive that like nobody is really in it for the UI.
It's just like, where can I get the most compute for the least money?
But, I mean, companies that have not done this also,
like mid-journey, you know, like they've always been profitable, it's a bootstrap business.
They never raised funding.
And I don't know what revenue mid-journey is today, but they found a way to profitably sell
subscriptions and rate limit accordingly.
I mean, they pretty early built, I mean, they always built their own AI, right?
I feel like they've never bought other AI.
So maybe the margins make more sense for them because you're your own supplier.
You don't need to buy tokens.
you just need to buy
just buy infrastructure.
You have to have that inference and the infrastructure
and the cost to maintain infrastructure.
Yeah.
Keep it up.
Supply.
But you're cutting out one middleman for sure.
Yeah.
The one with your own markup.
It is a big mess there.
I think with,
I mean,
it's a big mess to manage,
but it is you're sort of in charge of your own mess.
Yeah.
So your cost center is different.
You're not buying tokens.
You're purchasing man hours to produce.
And,
to sustain and hardware itself
and managing that hardware's uptime
literally hardware infrastructure
like real hardware, bare metal
as they say.
Oh wow. Mid Journey
calls itself
first community funded AI research lab.
That's hilarious.
I like that alone.
We are lean, self-funded
team, always hiring.
Mid Journey has no investors.
We are funded by our own community.
That sounds like the community
has ownership, which they do not.
So I break it to you, but.
That's like saying my customers are my investors, which does that makes sense.
Well, I mean, yeah, non-dilutive capital means I own the ship.
Anyway, but I mean, look, it works.
Right.
I mean, look, it works for them.
And I think that's something like incredible that you can build AI businesses
without burning credits, burning a whole.
Anyway, how do we get there?
I mean, yeah, Calicom, we don't sell tokens.
You still don't have any AI.
I was going to come back to say, if you don't have any AI, where's your growth coming from?
Yeah.
We would have thought people still use SaaS.
SaaS is not that.
No, I mean, it's, yeah, it's, I think we just continue to do a good job and build a good product that people love and pay money for.
It's not everything has to be AI.
Surprise.
Surprise.
is. Where
are you
again, another pun here
but not on purpose,
where are you spending your time in terms of product?
Like where is the innovation happening
that contributes to growth?
What is making that happen?
I personally, I spend
every day at work
looking at product
related topics. So pretty much
every major product decision goes over my desk
or comes from my desk,
which means not only, you know,
larger new initiatives,
whether it's like an iOS app or a browser extension,
but also looking at existing features
that we need to sharpen the edges,
not sharpen the edges, soften the edges,
sharpen, that'll be sweet.
Border radius zero.
And, yeah, like fix tons of bugs,
make sure to, you know, get enough buy-in in the company and assign resources.
So I would say I'm mostly responsible for the product quality today.
So if there's something inherently broken, please send it to me.
I recently started to do sales again just because I enjoy doing it, not because it's, like,
not because we're short stuff, but because I really just want to have this conversation with
customers and learn from them and understand what they go through.
It's more like a product exploration than necessarily closing the money.
That's how I spend most of my time with really just talking to customers and then trying to
bring that to life.
You want to take a, I wouldn't call it a bug, a bug fix, maybe an issue.
Let's call it an issue.
You want to take an issue live on the air for me?
Oh, for sure, yeah.
For sure.
As an investor and a user.
I'll spin up my clot code and.
submit to PR.
So we reschedule a lot.
We have in the past.
We either as change log,
we use cow.com to schedule all of our podcasts,
our entire workflow for creating any new event that is podcast related.
And I do as well in sales.
So all my sales calls,
I do a lot of conversations with founders,
CEOs,
key product leaders in companies that advertise with us.
We have them on the podcast via,
voice and so we showcase who they are.
It's not just me reading an ad.
It's very unique and informative and our audience loves that.
So I do a lot of scheduling for all the surface area of what we do here.
And so rescheduling is at the core of the crux of what we do.
Scheduling and also rescheduling because not everybody can show up and we even have to reschedule.
You and I did.
And so the challenge that I face, one of the challenge I face with rescheduling is one, it works
great. And the only part that doesn't work great is that if I want to reschedule and my availability
dictates how I can reschedule, I can't break that unless I go into the admin and create an override.
Like, I know my schedule and I want to reschedule it and I want to be able to pick whatever time
I want on my own schedule, not have to go jack with my availability to then have it open
and create an override. I feel like that could be a little smoother. And that's been a multi-
a year challenge because it's never been changed.
And I've never told you.
I just worked around it.
Tell me.
So here we are on the podcast.
How do you,
how do you feel about that,
that kind of change?
Have you experienced that yourself?
What do you think about that?
You know what?
I think I have this on my never ending list of tickets for like at least a month.
And I think today is the time where I finally get to ship that.
I've experienced this myself.
I'm always annoyed.
always talk about it with the team and then
some it hits the fan and it gets deprioritized
but I do have to fix this and I do agree it's very annoying
and we will the UX has to be spotless
maybe this week keep it in the same UI that you do
like a normal user would don't take me back to admin do it in the same
reschedule yeah and I'm not sure I would give that ability
to the invited no do it to the inviting
one who's control of the calendar
one who's in charge, yeah.
Yeah, because we've even had to reschedule a podcast and we largely record our podcast at 2 o'clock p.m.
And that's been a standard for us for a long time.
It's where we mentally block off our own day to even be present in our podcasts.
But at the same time, it may be somebody who's in Europe or maybe even Australia or New Zealand or, you know, South Africa or somewhere in the region where the time is far ahead,
15, you know, 12 to 15 hours in advance of my time here in Austin, Texas, which is central standard time.
You know, we'll want to reschedule to weigh other than a morning.
Same day, same concept, but I can't even do that in an easy way.
What I will tell folks is go ahead and put it on the calendar and I'll manually change it in my own calendar.
And that's been fine with that.
But I would say, you know, keep it in the same UI because this is a great UI.
It functions well, but recognize I'm an accurate.
admin and give me a little bit more ability and maybe even warm me like hey you know I don't know
figure it out here figured out but that's where it should happen yeah you know what I I just wrote this
in my coding agent so um maybe we get a PR in the next two minutes man that be so awesome that'd be so
awesome kick that off yeah I agree this good product is is what you're trying to say yeah that's
exactly exactly what we were just doing you know you tell me
something that's really frustrating.
I agree.
It's really frustrating.
And then it's my job to make that not so frustrating anymore.
I know you tweet about this.
And then you just do that over and over again until people really, really like your product.
Yeah.
Make them happy.
Make them happy.
Right.
I know you just tweeted about this on March 25th.
Just hit six.
Oh, no.
Seven million A.R.
And I think you mentioned in the pre-call.
that number's north of that number by a little bit because your growth rate is 10, 12%
per month you said? It was the, what of the breakdown? I mean, every month is different between
five and 10, you know, good months and bad months. But yeah, on average, we're hoping to
3x per year. That's kind of like always been the agenda and the milestone we want to go for,
which is, yeah. So we are looking now at, well, soon to 8 million, hopefully soon to correct the 10
and open some champagne and go to bed at 1230 instead of 10.
3 in the morning.
Will you have a party?
And can I be invited?
I'd love to come.
I'd love to celebrate.
Hopefully.
Yeah, we should.
Yeah.
We have a company retreat in Japan, which we're really excited about.
So maybe that would be sick if that overlaps with the 10 million miles down.
That would be really sweet.
It would be.
That would be in June.
So April, May, June.
Yeah, maybe.
June of this year.
Okay, so you're thinking by June of 2026,
potentially 10 mil.
Probably not.
Probably not.
Potentially.
I would say it's in the realm of possibilities.
Yeah.
Okay.
What would make you grow more and what would change your growth?
Like, what are the things that keep you up at night in terms of positivity and negativity?
And negative.
I know open source was one of them and a threat there.
and we've talked about that,
but what are the positive sides
and potentially some of the negative sides
that keep you up
when it comes to Kahn.com?
We do have large customers, right?
Like we have a lot of grassroots,
but we also have large customers.
And I think there's a bit of a,
like a SaaS shock going through the industry
where like a lot of companies
are really deeply looking at their vendor list
and try to cut corners
and cut costs and come with the argument like,
oh, but like we're paying you too much.
We can vibe code you in a weekend.
You don't have to vibe code Calicom.
We literally open source, just fork us.
It saves you money and tokens.
Like if you think that's the cost cutting approach,
like just self-hosted, for favor, like that's much easier.
But yeah, that's still a thing, right?
So like I would say the entire SaaS industry is experiencing some sort of cell shock,
SaaS shock where, you know, just under more due diligence than in the golden days of 21 where, you know, the pockets were a bit deeper and the money was flowing like champagne.
But, I mean, that's just not something that I only look at.
That's pretty much everyone's looking at budgets and allocations and what to bring in house.
Scheduling up to this day is still really freaking hard.
Like it's not something you can just one shot.
like some other SaaS companies.
Like, we have internally stopped using certain products
because it was a weekend of cloud code to get to 70, 80% of that functionality.
Yeah.
Sketching is just, like, even the first 20% is just still really, really hard.
So I think AGI has achieved the moment you can one-shot cal.com without forking.
That's my benchmark.
Yeah, I bet it is.
That's pretty funny.
Uh, yeah, I guess, you know, even as an investor, uh, in Cal and as a user of Cal,
because like anybody, I've thought about where do we spend our money.
Now, I don't think we spend a lot of money.
I think it might be like 30, maybe 60 bucks a month.
I don't know what the number is.
I want to say it's at least 30 bucks though.
Yeah.
Um, for Cal and yeah, even though we're an investor, we're paying user.
That does make sense because why would you not?
Um, but I think in any case, I'm like, maybe I can sell.
I love the self-host. I'm a home labber.
I'm like, well, maybe I can actually just go a different angle to Cal and not so much save the 30 bucks.
That was not my concern.
It was like, how much change can I actually influence in my bottom line?
And while 30 bucks a month is not dramatic, you know, what control can I get over self-hosting cow.com?
You offered open source for a reason.
You even bless the Docker image I can run.
And so you make it super easy, barely inconvenient,
to self-hosts cow if I want to.
It's definitely crossed my mind.
I didn't execute on it.
It was in my to-do list to look into it,
but only as an exercise of could I,
not so much should I.
And I think that's an interesting place to be in around SaaS.
Do you, have you felt, because you're growing,
but have you felt a retraction and has it been that?
Has it been self-hosters going and doing it?
I don't think that's going to be a case,
but no one's going to self-host count unless they really, really,
want to. Well, there's, I think there's two reasons people self-hose, as you correctly identify,
one of them is I want to tinker with it and play around with it and make changes. And the other one
is security and like putting it behind your own firewall. Those people have always existed. We,
we do have governments and healthcare that self-hosts, right? And they, Newsflash, also pay us because
they want to and they need support and they need feedback and help and developer office hours
and compliance help and set up and they pay us well so we do have a really small amount of people
who self-host and pay us now they're most certainly in our docker file i haven't checked at it
in a long time calcom has um how many pulls has over a
a million installations.
So take it or leave it,
that's a really big number.
We're not...
In totality or by a certain measure?
Whatever Docker Hub
tells me, I don't know that.
The analytics of Docker Hub are really
opaque, but
it's been pulled a million times.
Now, is that a million customers? No,
but it's also not 10.
Yeah. So anywhere between 10
and a million people are using
the self-hosts that
file container.
So it's a big number.
It's not,
it's not nothing.
It's,
it's obviously not a billion people,
but it's,
you know,
it's a million polls.
But we don't charge them.
That's okay.
They would probably be on a free tier.
You know,
if these are individuals,
they would be on a free plan.
Our free plan is as liberal as the open source version.
We always wanted to be like,
you don't have to be self-hosting.
in order to get the product for free, right?
You can be on a SaaS tier and be for free, right?
I think where the revenue is coming from is just people want to move fast,
companies want to move fast, self-hosting takes time,
it puts the burden on you to keep it safe and updated and maintained.
And a lot of people just simply don't want to do that.
I mean, why is renting popular?
It sucks.
It's just sometimes you just.
want to rent and pay people money.
And then when the sink is broken, it's being replaced, you know.
Yeah, limit your liabilities, limit your responsibilities.
Yeah.
Limit your accountability.
Limit, limit, limit as, uh, I like to do that.
I mean, I don't rent person.
I'm a homeowner, but I do like to limit my liabilities.
Who doesn't?
That's just exposure, right?
Lease a car.
Yeah.
Yeah.
I mean, even that, I own my own cars too.
Like, I don't lease, I lease services and things.
but not really like those kind of large items.
And I know people that have said,
oh, this is wiser, this is not wiser,
or this can be, you know,
this goes from a CAPX to a, you know, whatever X.
I mean, I like to own things.
Yeah.
Yeah.
I mean, you can go either way.
So I imagine this shift from how you're forking your own code base.
I imagine you've thought to some degree,
maybe you haven't.
Have you considered just literally going closed source completely
and going like the TL draw route where they have TL draw license.
It is literally not open source.
It's not even using a source available license.
It's just source available.
And issuing out a license key and being very, I guess, smooth with how you might license
something.
So you might have an experimenter who's trying to figure it out.
Maybe you've got a home laber who,
literally wants to HomeLab and host, self-host it, and you just give an instant license
key.
Have you ever examined that, that world at all when it comes to closed source, source available,
and the only way you can really use it is literally with a license key.
Otherwise, it's in like a demo mode.
I have never seen the Tio Draw license.
And they actually made it up themselves.
That's so interesting.
Yeah, it's, I had him on the podcast a little while ago.
It was a really good conversation.
I'll give you a T.
A TLDR of this.
Yeah, I'm looking at it right now.
It was very interesting.
The TLDR of their success, they largely sell an SDK.
So they don't even sell you finished software.
We came with the analogy during the podcast.
It's like orange juice concentrate that you put in your freezer.
You add the water, right?
It's not even a complete product.
It's a complete SDK.
Right.
And that's what they sell.
And they sell it as closed source.
It's source available.
And there's been some talk even, you know, they were out there on X famously pulling back their test suite because you can easily replicate TL draw from the test suite.
You know, that's, I'm sure you've been down that real.
I've seen that.
The threats and stuff like that.
But I think it's because of the threat, I'm not anti-open source, but because of the threat and the desire to have a sustainable commercial company and have source available because of the reasons why source available makes sense for trust.
but have that relationship.
So what a license key lets you do in this case is literally everyone who is a user gets a license key,
and you're very liberal with how you distribute those license keys that are non-paid.
So you want to be very open with it, maybe even instant with a home lab key, for example.
But you get an email and a name and you can forge a relationship that's very different from here's our free and open source,
you know,
Cal.
DIY.
What is wrong with you today, Adam?
Cal.
DIY.
You know,
you don't have a relationship
with anybody who uses it,
really,
unless you force the relationship
or desire the relationship
or get that inbound issue
which you don't even really want.
I mean,
maybe you want the issues,
but not the poor requests.
So what do you think
about that license key world?
Have you examined this thought at all?
So as of today
or, well,
the current,
way the repository split is that you can
fully self-host cal.com and then there's a couple
pro features that do require a license key and that are like
under a source available license so it's pretty similar what you're
explaining the only difference moving forward is that that source
available will go private source right so
the calicom of tomorrow will strictly be an agpL v3
potentially even MIT I'm we might even change that
because it's no longer commercially used by us.
Like it's there, it's public, but it's more of a public good than a commercial asset.
So the, but the source available part will go private source because it's already commercial
and it's very sensitive parts of the product that should not be for the public eye.
That's kind of like the, I think, the decision we made.
We're not, so we would never take anything, well, first, it's not possible,
but we would never take anything private that's previously open source.
But what we do take private in a sense is that we no longer have the source available,
commercial parts also source available.
We take that private source.
And I think, but the initial question you had, just to go back to the initial,
start with why even stay open source.
I think at the end of the day,
we are forced to make a decision here,
whether it's the right or wrong one,
time will tell, the market will tell,
and the technology will tell.
We don't know.
It's just, it feels like the right one.
A lot of people in the industry agree with me
and security experts agree with me,
which is sad.
I hate it.
Like, I don't like it.
but that's just what it is.
So we do not want to give up the open source ethos.
We keep Cal.Di.
For self-hosters, for anyone who's, you know, excited to contribute and be part of this community.
It's just simply not that instance that we would be running in our production environment.
That that's really just in a TLDR, not TLDDRA, but TLDR, like, the only difference is the open source code is
now fully open source project.
We don't run it ourselves.
We give it to you. You can run it yourself if you want to.
But we have a commercial fork of that thing that can do a little bit more and is a
little bit more safer.
So in a way, it's not like we're a private source company now.
We just use our own private, like, we use our community edition as the foundation.
And then we put some locks on it.
You know, given what you share with me and what I've also been seeing myself in terms of how things are changing, I'm sad too by that, but I'm not the state is what it is, I suppose.
And I'm sad by the fact, that's the fact, but I'm okay with how it makes sense to protect the investment, the company that you have our responsibility to run wisely properly.
Right.
Like the customers, right?
Yeah, for sure.
The data we're processing is no longer fun.
Like we have really like important data we're processing, right?
Like who people are.
And where's somebody is going to be at with who they're going to meet with at a certain time.
And I know you have like abilities to charge for meetings and stuff like that.
So like even that, you know, whether they're making money.
There's a lot of things you can get from that that that you can, you know,
Cross-examble with other data.
That and connect dots.
None of this.
None of this is sadly like, look, if you run a chill open source project that, I don't know, makes a button green and glow when you hover over it, that's very different to having millions of customers who, you know, interact with each other.
Whether it's a chatbot, you know, whether it's Discord.
Imagine Discord gets broken open tomorrow and every single DM is public.
that would freaking suck
so
that would suck
so open source is not dead
but it's changing
well
would you agree with that
yeah 100%
I think
I also don't think that
commercial open source is that
you know
open source
is freemium open source
and commercial open source
you know the subcategories
if you run a framework
you're fine if you run a
package you're probably fine as long as you have
your dependent
safe and secure.
If you run a commercial open source project,
probably make sure that it's not the same
that's running on your production environment.
I think that's usually good advice.
But commercial open source is still really valid
and fun and just a fulfilling place to be in.
It's a lot of fun.
Yeah.
All righty.
Well, Pierre, thank you so much.
This situation is depressing.
It's not a happy ending yet, but I do think, you know, I think what I also hope is that people just simply understand.
I think there's always haters out there who try to read into things.
But I think my hope is just people just get it.
Like, yeah, makes sense.
It sucks, but I should say it.
Yeah, we are at a unique position in place.
for sure.
And I think there's hard choices to be made.
And I think things are definitely changing all around.
And it's TBD on where it lands in terms of that change.
I'm long open source.
Same.
Yeah.
I really am.
And I hope one day we get back to where it, you know, we can be even more forthcoming
with, with details.
But I know when you're a high value kind of property, it makes sense, obviously,
to do what you need to do.
to protect yourself and your customers.
And no one can really foul you for that.
And I certainly appreciate the non-rugpole aspect of it.
You know, I think there's a lot of folks who would just simply rugpole,
and that's not at all the case.
And then, you know, if you were starting fresh and green and brand new,
maybe you never even go open source at all.
Maybe you start literally as close source proprietary and you prove yourself in the market.
or you don't.
I think the lore to being a commercial open source company these days
is dramatically different than it was four years ago.
Totally, yeah.
And we don't even know where coding comes out in a year from now.
So, like, I think the most important skill for any founders, you know,
like you have to adapt.
And we're adapting now and you need to be okay with that change, you know.
We're no longer a buck.
We're turning into a private butterfly.
So you just need to be okay with that transition.
Yeah, yeah.
Well,
Pierre,
thank you for keeping me on time with all my time with cow.com.
Big fan,
as you know,
a big user,
as you know,
daily active user of Cal.
And I love it.
I,
when we started using it when we first invested,
never look back.
I've,
you know,
hit a couple scenarios,
but you've fixed things over time.
It's gotten smoother,
easier,
better.
Uptime has been always amazing.
And,
you know,
for me,
five stars.
I would only knock you maybe a quarter of a point on the one thing I mentioned here in this pod, but maybe after that it's back to five stars again. Who knows?
And I just got a notification from my coding agent who shipped your PR to override hosts.
Get out of here.
Yeah.
So during the pod.
Wow.
And I didn't do.
And I didn't do a single thing and it looks amazing.
Come on now.
We shall see what happened.
We shall see. Well, I look forward to using that feature. I can't wait.
Yeah, I can't wait. You'll be the first one to test. I'll send you an update.
All right, Pierre. Well, thank you again for coming on the pod. It's been good talking to you. I appreciate you.
Thanks. Thank you.
Well, friends, a lot is changing out there. I don't know about you, but every single day, I open up X with trepidation and anticipation at the same time. Like, I don't even know.
Oh, you know, can I get a reset here?
It's not about you, but I'm loving Codex personally.
I'm not really digging Claude right now.
I haven't really ventured out to other places.
Open source models are doing cool stuff, but by and large, Codex, Codex app server.
And the fun things happening in and around the Open AI Codex world, chat GPT Pro world,
has just got me lasered in, gravitational focused in, and I'm liking it.
So I'll be in San Francisco here in a few weeks, September 14th.
through September 18th. If you're in SF, I would like to say hello. I'm trying to plan an
IRL. Yes, a ChangeLog. If we can do it, fingers crossed at Planet Skills Headquarters. I'm
really hoping we can do that. If the stars align, we're making it happen. If you're not yet a member,
go to changelog.com slash community. It is free to join, get in Zulup, get notified of all the
things happening. And I'll see you there. Big thanks to the spawn
of this podcast coder.com,
WorkOS, and Buildkite.
And of course, our partners in crime, fly.io.
Okay, friends, that's it.
This show's done.
Thank you for tuning in.
We'll see you again soon.
