Forking Cal.com to closed source (Interview)

3 Sep 2026 · 1 h 55 min · 40 chapters

Ask about this episode

Ask anything about it. ChatGPT or Claude reads this page and answers with the times it was said.

Connect VO and ask about every podcast you hear, including the moments you saved. Add to ChatGPT · Add to Claude

In short

The episode argues that AI has “flattened the knowledge graph,” making open-source repositories easier to compromise at scale. It focuses on Cal.com’s decision to fork its code and keep sensitive parts private, plus how AI-generated “slop” overwhelms open-source review and security reporting culture.

Guests and backgrounds

  1. Peer Richelsen, co-founder of Cow.com (and a small check investor in Cal.com). He discusses commercial open-source security and how AI changes both attacker capability and maintainer workload.
  2. Nikki Pike, Field CTO for Coder.com. She explains why Coder uses secure cloud development environments instead of developers’ local laptops, citing supply-chain and consistency risks.

Key claims

  • Open-source is no longer reliably “more secure” because AI tools generate most vulnerability reports, many of which are hallucinated or non-reproducible.
  • Autonomous/AI-assisted attackers can find and exploit vulnerabilities faster; open source reveals internals (“black box” vs “see the backend”).
  • AI-generated pull requests look confident but can include hallucinated tests and hardcoded behavior, making review effectively impossible at human scale.
  • Commercial open-source companies with customer data should consider private forks; Cal.com is doing this.

Notable examples

  • Mentioned AI-discovered vulnerabilities: Firefox (12 P0), React, Next.js.
  • Supply-chain compromise example: “Light LLM” (malicious execution and key/pipeline compromise).
  • NPM compromise referenced as “Shai Halud” (public repo compromise).

Written by AI. May contain mistakes. Listen to the episode to check what was said.

Chapters

Tap a time to open that second in VO

Revisiting Cal.com

1:30 to 4:11

Discussion about the journey and updates related to Cal.com.

“And I'm joined by Nikki Pike, Field CTO for Coder.”

Revisiting Cal.com

4:44 to 7:27

Discussion about the journey and updates related to Cal.com.

“When I say we, I mean the organization ChangeLog and Calendly has been around for a while, but they had changed.”

The State of Open Source and AI

7:27 to 11:23

Exploring the challenges and changes in open source due to AI.

“I think I don't think there's a single person who can predict what the outcome is going to be.”

The Future of AI in Open Source

11:23 to 14:00

Discussing the implications of AI on open source contributions.

“to distill what should be merged into the project and whatnot.”

The Challenges of Open Source Maintenance

14:00 to 17:40

Explore the complexities and challenges of maintaining open source projects in the age of AI.

“I mean, that's kind of like the AI companies are already giving open source companies tons of free tokens, which is, you know, great.”

Pull Request Overload and Community Impact

17:40 to 22:36

Discuss the overwhelming number of pull requests and its effect on open source communities.

“As you're speaking about your concerns and challenges, I'm looking at Cal.com's open source repository, github.com slash calcom slash cal.com.”

Security in Open Source vs. Closed Source

22:36 to 24:48

Analyze the shift in security perceptions between open and closed source software.

“write the the initial prompt that that starts the journey i agree so um it's there are clearly um There's multiple reasons and benefits to be open source, right?”

The Ease of Exploitation in Today's Environment

24:48 to 28:00

Examine how advancements in technology have made exploiting open source repositories easier.

“And then at the same time, the autonomous attacking tools have gotten so good that the amount of knowledge needed to attack a repository is basically, can you run a shell command in your terminal, right?”

Democratization of Technology and Security Risks

28:00 to 29:14

Explore how democratized access to technology raises security concerns with the rise of vibe coding and hacking.

“The execution layer is so much more efficient, yeah.”

The Dangers of Open Source in Commercial Settings

29:14 to 30:56

Discuss the risks commercial open source projects face in terms of customer data and potential extortion.

“So yeah, as you said correctly, the access to technology also means that malicious hackers have – they are so happy about all of this.”
Show all 40 chapters

Shifting to Closed Source: A Strategic Decision

30:56 to 32:27

Learn about Cal.com's shift to a private code base for commercial products to enhance security.

“a library that, I don't know, helps you work with time zones, like you're fine, like stay open source.”

The Growing Threat Landscape for Open Source

32:27 to 36:15

Examine the increased vulnerabilities of open source software due to advancements in hacking tools.

“change is predicated on, but is it because the visibility into the flaws are more visible now because the tool is better and faster?”

The Growing Threat Landscape for Open Source

36:20 to 38:38

Examine the increased vulnerabilities of open source software due to advancements in hacking tools.

“And one of the most challenging problems of modern era software development is continuous integration and continuous delivery.”

The Growing Threat Landscape for Open Source

38:42 to 38:55

Examine the increased vulnerabilities of open source software due to advancements in hacking tools.

“Engineer for the frontier we are all facing, trusted by the teams setting the pace.”

Balancing Open Source and Security Needs

38:55 to 42:01

Discuss the challenges of maintaining an open source project while ensuring security in a commercial environment.

“And so you've had all of your code out there.”

The Challenges of Open Source Security

42:01 to 45:24

Discusses the security implications and considerations of maintaining open-source projects.

“and not have developer gymnastics playing around.”

Examples of Vulnerabilities in Open Source

45:25 to 47:54

Explores real-world examples of vulnerabilities in commercial open source projects.

“We have no investors who are bullying us to go private source.”

Navigating the Future of Open Source

47:55 to 50:34

Discusses the future and evolution of open source projects and their models.

“So there's a lot of commercial open source businesses out there that have to be open source in order to run.”

The Role of GitHub in Open Source

50:35 to 56:00

Analyzes how changes in open source might impact GitHub's business model.

“I think that's a very fair statement to say because back in the days you would have those public because it's just really hard to hack them.”

The State of GitHub and NPM

56:00 to 1:02:04

Discussion about the current issues with GitHub and NPM, including security and community concerns.

“Because, I mean, they're banking almost everything on Copilot, right?”

The State of GitHub and NPM

1:02:09 to 1:02:21

Discussion about the current issues with GitHub and NPM, including security and community concerns.

Mitchell Hashimoto's GitHub Recommendations

1:02:21 to 1:10:03

Recap of recommendations from Mitchell Hashimoto regarding GitHub's future and operational improvements.

“Did you catch that post from Mitchell Hashimoto, Bonnie Chance on X?”

Exploring User Intent with AI Agents

1:10:03 to 1:14:16

Discussion on how AI agents interpret user intent and the implications of autonomous decisions in programming.

“I mean, it's no different than search, right?”

The Ethics of AI in Open Source Contributions

1:14:16 to 1:16:35

Examination of the ethical considerations surrounding AI-generated pull requests and their implications for software projects.

“And then the two steps removed is, you know, figuring out which ones have issues and correcting them or finding a correction in somebody's PR.”

Growth and Success of Cal.com

1:16:35 to 1:17:42

Insights into the growth and success metrics of Cal.com as an open-source company.

“give me as a, maybe a seed investor, give me a, give me a glimpse behind the scene of the success that is happening or has been happening.”

Business Models in the AI Startup Space

1:17:42 to 1:20:20

Discussion on the unsustainable practices of many AI startups and the challenges they face in profitability.

“We're reaching, I'd say, like the milestones we set for us.”

The Competitive Landscape of Coding AI

1:20:20 to 1:23:35

Analysis of the competitive nature of coding AI and how companies can thrive without unsustainable practices.

“In my eyes, it's not a great business, but for some it works.”

Building AI In-House vs. Outsourcing

1:24:00 to 1:25:17

Learn about the advantages and challenges of building your own AI infrastructure.

“You're purchasing man hours to produce and to sustain and hardware itself and managing that hardware's uptime, literally hardware infrastructure, like real hardware, bare metal, as they say.”

The Role of Community in AI Development

1:25:17 to 1:26:28

Discover how community funding impacts AI projects and product ownership.

“I mean yeah Telecom we don't sell tokens.”

Product Management Insights

1:26:28 to 1:28:01

Explore the daily responsibilities and challenges faced in product management.

“Like where is the innovation happening that contributes to growth?”

Addressing Scheduling Challenges

1:28:01 to 1:30:03

Understand the complexities and solutions for scheduling in SaaS applications.

“Would you want to take an issue live on the air for me?”

Growth Metrics and Future Goals

1:30:03 to 1:32:47

Learn about the company's growth metrics and aspirations for the future.

“And I think today is the time where I finally get to ship that.”

SaaS Challenges in the Current Market

1:32:47 to 1:35:50

Discuss the current challenges facing the SaaS industry and how to navigate them.

“We have a company retreat in Japan, which we're really excited about.”

Self-Hosting and Its Implications

1:35:50 to 1:38:02

Examine the reasons for self-hosting SaaS products and the business implications.

“And while$30 a month is not dramatic, what control can I get over self-hosting Cal.com?”

Self-Hosting and User Support

1:38:02 to 1:41:04

Discover the value and user experience of self-hosting Cal.com and the company's support model.

“And they, Newsflash, also pay us because they want to and they need support and they need feedback and help and developer office hours.”

The Shift Towards Closed Source

1:41:05 to 1:45:59

Explore the decision-making process behind the potential shift from open source to closed source for Cal.com.

“So you might have an experimenter who's trying to figure it out.”

Commercial Open Source Landscape

1:46:00 to 1:50:18

Understand the challenges and future of commercial open source in a changing landscape.

“That's really just in a TLDR, not TLDraw, but TLDR.”

Reflection on Cal.com's Journey

1:50:19 to 1:52:04

Hear about the evolution of Cal.com and the impact of user feedback on its development.

“And I hope one day we get back to where we can be even more forthcoming with details.”

Reflections on Recent Developments

1:52:04 to 1:52:42

The hosts discuss recent updates in their projects and share personal insights.

“and i i just got a notification from my coding agent who shipped your pr to override hosts get out of here yeah so during the pod during my life and i didn't do that's the world we're in Amazing.”

Anticipation for Upcoming Events

1:52:46 to 1:53:58

The hosts talk about their excitement for upcoming events and community engagement.

“Well, friends, a lot is changing out there.”
Hear the part that matters, and keep it.Open this episode in VO. Double tap your headphones to save a moment as you listen.
Get VO free

Transcript

Automatic transcript. May contain errors.

0:00Jerod Santo:What's up, friends? Welcome back. This is the changelog. What if the majority of open source repos out there, they're already compromised and we just don't know it yet? That is the unsettling theory Peer Richelsen, co-founder of Cow.com, brings to this podcast this week. We dig into how AI has flattened the knowledge graph so a 16-year-old can vibe hack a power station as easily as their mom can vibe code an iOS app. Why the reporting culture that has kept open source safe and secure all these years is collapsing under the AI generated noise, slop, whatever you want to call it. Cal.com's move to fork its own code base and take the sensitive parts private.

0:46Jerod Santo:And the eye-opening reality that shipping$1 of AI tokens for pennies on a dollar, that is now a common startup business model. Lots going on. Lots changing. A massive thank you to our friends and our partners at Fly.io. Your agents, they need computers. My agents, they need computers. We host everything we do on Fly.io, and you should too. Check them out at Fly.io. Okay, let's do this.

1:25Jerod Santo:Well, friends, this episode is brought to you by our friends at Coder.com, secure environments where developers and agents work in parallel. And I'm joined by Nikki Pike, Field CTO for Coder. Nikki, what is a Field CTO? So I get that question a lot and it's, you know, half the people understand it, half the people don't. So a field CTO, I describe it very simply as we're DevRel for the C-suite. So we provide a bridge between the customer voice, between the C-suite and the managers and the leadership teams of our customers back into our product. And then we go through and we help enable our teams to have the same message to make sure that the message is correct and that we're building on something that people actually want, not just something that we think they want.

2:05Jerod Santo:Okay, so we're taking the laptop away from the developer. Not really, though. We're putting them in a cloud development environment, a secure environment where they can work with their agents in parallel. These are blessed environments. What's wrong with the laptop? The laptop is the trap here. And not only because the fact that it could be stolen, you could lose it, it breaks, and you're out of work while you're waiting for a new one. But there's also just the consistency that you got there. We all know developers. Developers are going to be looking for some of the latest and greatest. And if you're not really controlling how they get out there, that's where you get this.

2:35It works on my machine. It doesn't work in production. It doesn't work anywhere else because you don't have that consistency. You don't have that ability to really standardize what that environment looks like. And this is a problem not only for new people coming in, you know, the onboarding statement is average, I think, is like four to five weeks for a new employee to really get their local laptop set up and ready to start doing their first time of code. And, you know, the time to first commit is a metric that almost everybody knows. And the reason they can't do that is because there's a lot of tribal knowledge out there.

3:02They got to go talk to other developers. What are we using? Where do we get our dependencies? Are we getting them from public? Are we getting them from private repositories? But there's also the security and the supply chain aspect of this. When you have local machines out there, look at like the Shai Halud, you know, that virus that went out not long ago. This was a compromise of the NPM public repositories. They went and downloaded things. NPM did what it did. Next thing you know, you're compromised. But when you use something like what we're doing with cloud development environments, then you can mandate and you can put restrictions on there to say, hey, you can only go get your packages from our private repo.

3:36Those packages are expected to have been thoroughly vetted. We know that they're clean. Now, does this stop everything like Shai Halud? No. If that compromised package gets into your private repo, you can still have that. But it really reduces the surface area of the attack. And it also reduces the blast area of the compromise should it happen. Because if your laptop gets compromised and you have to kill the laptop for whatever reason, that's weeks out of work while you're either fixing that or you're getting a new laptop in. the cloud development environments allows you to kill that start back up fresh and you're back and running in five minutes.

4:09You don't have to wait all that time.

4:10Jerod Santo:Well, friends, the first step is to go to coder.com, install Coder, self-hosted environments for your teams to enjoy, to standardize around, and it's open source. So you can try it out today. Once again, coder.com.

4:43Jerod Santo:well friends i'm here with an old friend it's been a while it's uh it's been too long here wait a co-founder of one of my favorite companies out there i use you daily cal is how we scheduled this thank you very much for being the backbone of all my scheduling uh it is about time since we've gotten back on the pod. Yes, the pun was intended. Thank you so much. I think actually our first pod was really about how it was about time where the initial conversation sort of began with this era where Cal.com, I'm not even sure if you had Cal.com at the very moment we did that podcast or not, but it was, we were users of Calendly.

5:20Jerod Santo:When I say we, I mean the organization ChangeLog and Calendly has been around for a while, but they had changed. They weren't working. I mean, a lot of different stuff, which I'm sure you're aware of, but one of the things, one of the undercurrents, the themes of that podcast was it is about time. And so, you know, this very well because you probably live, eat and breathe all the things around time being one of the co-founders of cow.com. But thank you for coming back on. And yes, it is about time. Thank you so much. It's been, it's been time and we need to make more time um i i think it was right around the time when we bought cal.com which may or may not be four years ago or three years ago i i um time is a weird concept so um yeah thank you for having me again i'm excited and uh i guess slight full disclosure uh i am a very small check investor in cal uh a very small seed investor through i think your angel list stuff that you had way back and that's how much I believed in it because I was like okay I think even then if I'm recalling correctly because I'm trying to go back in my own memory open source was core to your mission uh you know you've been open source for a very long time your commercial product is probably licensed differently which I'm not familiar with exactly which license you chose and how that sliced out I know things are changing even too this year around open source I'm sure you have thoughts on that.

6:51Jerod Santo:So I'm happy to go wherever you want to, but yeah, big fan of cow.com user daily of cow.com and it's been too long to catch up. And I'm sure that this new era of, of cows can be different. I suppose in this next era of agents where you probably have a lot of folks using agents to act on their behalf, to maybe create events, manage their availability, even book time with someone. What is it like in this world that we're in with agents running amok or maybe not amok in this era for you? I think all the cards have been shuffled and nobody knows what's coming next. I think I don't think there's a single person who can predict what the outcome is going to be.

7:39It's like predicting how a certain stock goes, like that person is a liar. You can never really say what's going to happen. But one thing for sure is that I think a lot of things are happening that we could not predict as easily as before. Like usually you start a SaaS company, you have a playbook, you get from zero to one million, from one to 10 million, from 10 to 100 million. There's certain pattern matching and playbooks, et cetera. I don't think any of that works anymore. And even when it comes to how to, you know, build in public or how to build open source, how to build, you know, the safest software or the fastest growing software, like everything has been reshuffled.

8:25I think about seven months ago, we joked that Dario said like in six months from now, everybody will be using AI agents to write code. I have not written a line of code like in weeks. And same goes to our entire engineering team. it's all code called gen and AI agent assistant and so it's like that prediction was so whack seven months ago and everybody was laughing at it and now it's just like it's the technologies here right and so the question is like what else will change in terms of and I can only focus on startups I don't want to touch broader society aspects of like how what's the meaning of jobs and work like i'm not i don't want to touch that but like i think for startups like uh it's a really weird time right now like some like time that you could never really predict before i mean startups are always a weird journey um but now it feels like extra volatile i'd say and and and and i think to to get to your point to open source and i think open source multiplies that by like a factor of 10 like you're basically drinking from the firehalls because you know when you're when you have a private source a closed source business you're the only one committing to it there's no such thing as a public uh repository where people can like look inside and contribute etc etc for open source businesses and i strictly focus on commercial open source um you just have so much noise and like back in the days it was like if somebody opens a pull request you would immediately know okay it's black and white either it's a well thought out pull request and you can with tests and everything and well you know thought out structure or it's whack and if it's whack you close it and it's like anyone can look at it and be like okay yeah this is worth closing that one's worth reviewing and then you you know you you build on top of that and you engage with the author nowadays everything looks the same like you get a pull request and it's always written by by cloud by cloud code or by maybe codex or maybe if you're lucky by some other coding assistant right but it's like back in the days you had a thousand open source uh contributors and you would have a thousand opinions right and one person would do something and then the other person would like reject that idea and now you just have a thousand people using two different coding assistants right and so it's like the this whole notion of um like the best idea wins it's like the best large language model wins but you only have or maybe the best prompt given to that large language model wins because there's still some variation among prompts right but like um it's really really hard to distill what should be merged into the project and whatnot.

11:28And then what's even worse is that like the confidence of that pull request is so high because the large language model is like, here's the best thing delivered to you on a golden plate. And then you start to peel off the layers of the on-end and you're like, wow, even these tests are like hallucinated. Like none of this makes sense. Like it looks so real, right? Like it's, wow, this is like the best thing ever. And then you start to run it and you're like, wait, why is that thing hard coded? Like, you know, like so many question marks. And it's like, you're like, why am I even reviewing this?

12:02And so imagine being a commercial open source company. There's so many tweets out there. We don't even need to reference one. There's so many. Just search for like open source and AI. And they're like shutting down external pull requests and having this like vouch system where only like really close people who went through like multiple rounds of interviews are able to commit to the repository because it's just so much AI slop, like literally AI coded slop being thrown at your repository. So that's problem number one. That's why I'm saying like drinking from the fire hose. Imagine you have one cracked engineer on Cloud Code like spamming your private repository.

12:41Okay, now have a hundred of those who just, and some of these pull requests are literally just like, hey Claude can you fix this github issue for me and then they open a pull request and i'm like okay but like thanks but i could have done that you know like where's your uh well added knowledge come you know there's no no added knowledge and you're just essentially adding more slop to the code base so it's really hard um that's problem number one i'm happy to go over many more problems.

13:14Jerod Santo:I was talking to a friend of mine, a friend of mine, Adam Jacob. Did you know Adam Jacob by any chance? Is he a name you know? Adam Jacob. He's famous for being the founder of Chef and maybe infamously being the founder of Chef. If he was here, you'd probably be laughing at this moment, but he created a company called System Initiative. Yes, I can't. and they had begun to rethink ci no sorry not ci but they began to rethink infrastructure it was very visual very innovative but they focus focus on this visual layer and this is pre-ai and obviously not how things have played out and so they've sort of failed product market fit but a lot of the ideas were still really good and they parlayed a lot of that good stuff into what's now called swamp.club and they are uh agpl v3 open sourced yep same but but very specifically they are open source but not open to contributions they do issue-based contributions now is this is this where you're thinking of like hey you can file an issue you can file a bug you can file your your concerns but we'll never accept your pull request ever that's fine i mean i i think so So here's my current issue with everything open source.

14:44We're clearly training AI. That's okay. I mean, that's kind of like the AI companies are already giving open source companies tons of free tokens, which is, you know, great. Like I have a free thought max. I have a free codex. I'm very grateful for that. I understand that we are producing the code that they are training the next large language model on. And that's, I think, is fine. I mean, it's still violating the license, I guess, but I think the problem is that when entire open source repositories, as it is right now, gets overwhelmed with slop, it just destroys code quality. I mean, look, it's still our job to, as maintainers, to review and approve and merge and change poor requests.

15:38So it's still our job to make sure the quality is high. But it's just so much more work now to differentiate between bad PR and good PR that it's simply not possible, like humanly possible. and I know Peter from OpenClaw said he's not reading his own diffs anymore like his own codex PRs. I don't think necessarily that that's the solution that we just like close our eyes and hope for the best and like have tests etc. Because there's this graphic that was like the moment you introduced Slop to your code base now the coding agent looks at your existing project and then adopts bad practices. And it's kind of like a recursive loop of poo, right?

16:28Like it just gets worse and worse over time. Same thing happens with large language models, right? The worse quality of an open source repository, the worse AI will be in the future learning from that bad code, right? And so that's another issue I have with open source where if you cannot get the resources in place to actually have really, really high quality. And bear in mind, that means you need to end up hiring really like IC5, IC7 level people who know what they're doing. Because you hire a generic IC1, IC2, IC3, chances are they will be using cloud code and they're incentivized to use cloud code because that's just how the whole industry works today.

17:13And that's okay. I'm not saying that's bad. But you still need these studied computer scientists who know what ON is. And a lot of them don't. And so, yeah, it's not a great outlook if slop gets multiplied. So I think the whole training aspect and the code and public aspect is really becoming an issue. Yeah.

17:42Jerod Santo:As you're speaking about your concerns and challenges, I'm looking at Cal.com's open source repository, github.com slash calcom slash cal.com. And I'm on the pull requests tab and you can probably see there's just an immense, I mean, more than you would probably ever want to or be able to. no there's no chance there's there's no chance we will get to the bottom of this it's just so it's um well and and this also hurts the community right like people expect to get the same level of treatment for like a one-line hey claude please fix issue 115 then someone who's investing deep knowledge and and time and resources into making something better that they feel deserves to be merged so it's like it's almost like um how would you describe this best like the best way it's it's like it's like mass propaganda where you where you where you just post so much misinformation that it's just impossible to know what's the truth and what's not because you're just drowning in the sea of everything's fake and then the reality just gets murky right and the same with poll requests like you just don't know what's good anymore when everything looks equally good and then there's like a stellar pr and then the rest is just uh two line prompts from claude you know so it's like it's really tough like i it's it's i i don't envy any i don't even envy freemium open source maintainers who back in the days would be happy you would be happy for every pull request that would come in you would be heck yeah like somebody's just messed up they think something i could change it yeah let's do it when when when we first had a conversation we probably had 20 open pull requests and then when you had like suddenly you had five more you'd be like whoa where did they come from and and you would like reach out to these people and be like individually like oh my god thank you so much for you know contributing this has been blast etc etc so it's like yeah it's um and it's and it pains me because also there's um this is another problem that um people are facing that they think they are more likely to get hired if they can show open source contributions so now they their entire pipeline is let me find the top 10 repositories let me orchestrate 12 different agents and they're all trying to find different issues like basically the the clawed instruction is find the most upvoted issue and then submit a pr and these five it's almost like you're spamming your your cv which is also really terrible strategy by the way into like hundreds of companies and trying to hope one of them sticks and then your ai agent comes back with like oh i've opened 20 different poll requests and these and these and these different repositories does that make you more likely to get hired i don't know so it's weird it's a really weird time i'm i'm not saying there's a this is it's it's weird i i it's weird we're really struggling we're really struggling yeah well i mean so let me i didn't say the number so you've got 358 pull requests yes no sorry 356 yes um and that's still a lot Even 358 is – I mean it's two more.

21:09Jerod Santo:It's a lot of pull requests. Not a big dramatic difference there between 356 and 358, but that's a dramatic amount of pull requests. If that were my pull request inbox, I would just say inbox zero it and just cancel it, right? I mean – Nuke it. or just literally cancel the PR tab altogether, which I think is kind of what I was mentioning before. Adam Jacob, his philosophy was swamp.club, and that is the URL, swamp.club. It's the coolest thing ever, and you guys check it out. They're just like, forget it. We're not going to do it. And I don't think their problem was the amount of port requests or even the port requests that would be or likely be a slop.

21:53Jerod Santo:It was more like we know what we're building. We know what we want to build. We're happy to take your ideas. We just don't want your code. We want code that we would write that matches our style of code that our engineers can curate, whether it's with an agent or not. It matches our style. It matches our lingo. It goes at our pace. It fixes our problems that we think are worth fixing. we're happy to hear your ideas we want you to use swamp but it's issue-based co-contributions and you'll give us the problem or the challenge or the solution in in prose and they may even bring that into context behind the scenes and they may even write a prompt and they may even write the the initial prompt that that starts the journey i agree so um it's there are clearly um There's multiple reasons and benefits to be open source, right?

22:46Like some things simply have to be open source. React.js has to be open source. JavaScript has to be open source. Python has to be open source just to run the thing. Cloud.com necessarily doesn't have to be open source, right? So we've been open source for many different reasons, but in order to run it, that's not why we're open source, right? We're not a JavaScript framework. We're not a UI library. So for us, the pitch and the idea was always like build in public, build trust, build them. And then another thing, build the most secure code base, because I would say up until January 26, I would say open source is always more secure than closed source.

23:37Like I would stand by that statement. And that's the problem. Today, I no longer think that. So the pendulum has swung. This is very safe, open source, because bear in mind, when you were open source, you had security researchers making really good PRs, fixing the holes, fixing vulnerabilities, reporting vulnerabilities. There was a reporting culture. The reporting culture no longer exists. 99 % of the reportings we get are AI generated. like we have an inbox security at cal.com that people send vulnerabilities and 99 of them are ai generated like including that email that sends it because people are spamming repositories and and half of those vulnerabilities are also hallucinated like they just simply don't exist um you reproduce it and it's not there or it it got something wrong and it's using the wrong API endpoint.

24:37So the culture of open source makes you more secure because you have actual human beings who know what they're doing, checking your code base, has kind of fallen behind. And then at the same time, so that's gone. And then at the same time, the autonomous attacking tools have gotten so good that the amount of knowledge needed to attack a repository is basically, can you run a shell command in your terminal, right? So like we went from patent testing requires crazy amounts of tooling and knowledge and reverse engineering of APIs and a man in the middle attacks and yada, yada, yada. Like so much work had to go in into basically finding and abusing vulnerability.

25:29Let's say you're a black hat hacker, right? Like, let's say you are an evil person, you want to extort people. It was really hard. You had to be really good. These are really smart people who would execute those attacks. Nowadays, maybe not with Cloud because of all the security features, but there are large language models out there that are so good at pen testing and, well, Cloud security, to be honest, of their product, that it's really easy to find dormant vulnerabilities. Like Firefox had like 12 P0 vulnerabilities reported by AI. React had vulnerabilities found by AI. Next.js had its own fair shares of vulnerabilities reported by AI.

26:15So it's like we're really in trouble because I'm not saying our engineering team is flawless from pre-AI. Like, obviously, this is not a AI versus pre-AI code, but the amount of money, resources and talent to find and abuse vulnerabilities has like 100x in terms of ease of use. Right. And so you're giving basically evil people a single prompt in their terminal to find and abuse open source repositories. so the whole pendulum of like oh we're open source, we're more secure has completely swung in the other direction where it's like wow this is so easy to hack any open source repository my theory is that the majority of open source repositories are compromised right now we just don't know yet like Firefox has 12 if Firefox has 12 P0 vulnerabilities what do you think your open source repository is looking like you know yeah that's funny it's not it's really grim so yeah we just had that um you know one of the more

27:28Jerod Santo:recent ones was light llm it was compromised by supply chain attack i mean that was even more unique one it was malicious in how it executed it but how they got there was really interesting you know the social engineering behind it or even just getting the keys and stuff like that and Using the blessed pipeline to get the thing in the PyPy, that was really interesting. And we're seeing that more and more and more because there's always been holes, right? I think what you're trying to say too is there's always been holes. And it's not a then versus now kind of thing. No. It's that now the holes.

28:03The execution layer is so much more efficient, yeah.

28:06Jerod Santo:Right. Well, the tool is now more evenly distributed. So the knowledge graph has kind of come down to every human being that is in some sort of first world scenario that can afford 20 bucks a month, maybe even the free version of it has the same access to the same tool that the world's greatest engineers at some of the biggest companies are using. right there we're all using a version of the similar and same tool and so the knowledge graph has kind of flattened dramatically and you're right the bad actors now have the same thing and not only do they have the same thing it's a faster tool than we've ever been able to script before we've always been able to script bash has always been there and sure it's always been fast on any given cpu but now the ability to write it and infiltrate and to just pen test secure Security research is called this vibe hacking because you're no longer knowing what you're doing.

29:01Like you're literally just instructing the agent the same way you have vibe coding. And now like everyone's everyone's neighbor is vibe coding their iOS apps, which, by the way, is great. Like democratizing access to technology, big fan. But what happens when the mother is Vibe coding an iOS app and then the 16-year-old son is Vibe hacking the power station nearby? That's not great. So yeah, as you said correctly, the access to technology also means that malicious hackers have – they are so happy about all of this. It's like a birthday present. Like, what do you mean? I no longer need to, you know, spend 16 hours studying the code base.

29:48I can just have an AI, find all the holes for me. That's awesome. Here's my Bitcoin address. Pay me money. Otherwise, I publish your data on the dark web. Like, yoo-hoo. Yay. That's great. And even that is probably fully autonomously executed, including sending the email and opening the wallet and checking whether the funds got received. and it's a great situation we're in here.

30:14Jerod Santo:You seem very grim and not very excited about the future of open source. Would you agree with that? Do you think things are just in jeopardy or what? I think I would probably summarize this like if you run a commercial open source business, you have a huge target on your head because you are a business and the business means you have customers and the customers mean you have sensitive data and it can potentially be extorted. If you run an open source free GitHub project, even if you run OpenClaw, like OpenClaw does not have an enterprise edition that they sell to Fortune 500 that runs on the same code base.

30:52Even if they had to, they would probably not publish it on the same GitHub repo. So it's like if you run a UI framework, a library that, I don't know, helps you work with time zones, like you're fine, like stay open source. Well, unless you accidentally import an NPM package that completely compromises your project, which will happen. So that's another attack vector, obviously. But any business today that has an open source, let's call it this way, any open source project that eventually makes a database call, you are in trouble. And I'm saying this after five years of being open source and 15 years in the industry, you should probably take your project private and rewrite everything that touches off database and encryption, which is what we're doing now as Cal.com.

31:48This has been a big change. We've been doing this under the hood for quite some time. But basically starting 15th of April, we're taking the commercial version private. So we still have the community version, fully open source. You can use it at your own risk. You can self-host it. You can run it on your own infrastructure, ideally behind many firewalls. but the same code base that runs on app.cal.com will no longer be publicly accessible because it's just it's too risky for us like we have we have a commitment to open source but we also have a commitment to every single of our customers and given this like pendulum swing we just that the risk reward ratio just really sucks yeah is this um is the the change i understand what the

32:37Jerod Santo:change is predicated on, but is it because the visibility into the flaws are more visible now because the tool is better and faster? Is that one of the kind of core reasons to change? So the security researchers we spoke to, right, we have a couple of those. And obviously, there's also the good people helping you with providing tools to find vulnerabilities before the black hackers. But everybody says, if you have an open source repo, you're like five to 10 times easier to to hack than a closed source repository right so think about it five to ten times it's not like 10 15 percent it's like five to ten times that's a big delta and so the reason it's so much easier is it's called black box hacking like you basically need to guess and reverse engineer like you you call an api endpoint you try to guess them at like what does it do how could I attack this?

33:35With open source, you literally see the backnet. You see the function call. You see, is this an ID or R or whatever? Is there something else that I can, like, you know, is there a way I can inject a script or whatsoever? And again, pre-AI, you would need to spend 8, 16, 20 hours to research and study every single function call and find these things, you know, manually. And that's what good security researchers would do and they would get a bounty for. And that's what black hat hackers would do. And typically speaking, sorry to say this, the smart ethical hackers are faster and better than the script kitties who just want to extort you some Bitcoin.

Read the full transcript

34:21That's just facts. That's always been facts, right? Like an honorable security researcher who's a white hat hacker who gives you bounties is always more intelligent than some dumbass sitting in some random kitchen hacking your software, right? That's just always facts. But now, again, with AI, it doesn't matter because both are just putting the same prompt, find a vulnerability in this and this and that repository and run the same prompt. And guess what? The black hat hacker is usually fast because they have an incentive, right? They have an immediate extortion incentive to hack and blackmail.

34:57Um, that's a big problem, right? So, um, yeah, I would be really cautious if you have a repository that has a database that has customers in that database to run that out in public. And that doesn't mean you should, um, you should like close your open source. We're not shutting down our repository. I mean, heck, it's, it's an amazing piece of software that we've published, but it just means that you need to internally fork your existing code and just make sure that you just rewrite every single function call that is vulnerable like that is you know hackable you know don't care about some random front-end library that's fine like a drag and drop component keep that but like the way you do auth the way you do database calls the way maybe even rewrite your your entire um middle layer and the prisma calls everything Like probably like start today or start yesterday and take all of that private.

36:01It's just not worth the risk until that whole pendulum swings back into security, which, you know, could happen. Could also not happen. It's just, it's, yeah, we don't know. We really don't know.

36:19Jerod Santo:Well, friends, I'm here with the CTO of Buildkite. And one of the most challenging problems of modern era software development is continuous integration and continuous delivery. And so Lachlan Donald, Buildkite CTO, what are you thinking about today's teams? The challenges they face, the speeds at which they're developing new features, new code. It is just overwhelming. How do you all think about that? Such a good question. It's the question everyone's asking right now. All of our big customers are asking us at the minute, like, you know, if we 5 or 10x our throughput this year or 1 ,000x it, what breaks and when?

36:57And, you know, my answer is kind of same as it's been for the past 20 years, which is that the bottleneck is still trying to integrate those code changes in and then deploy them and check they work and then keep them working as you keep throwing more and more code at it. I think a lot of the fundamentals are the same, but we're just a thousand X-ing the speed of it. And, you know, that changes nearly every variable.

37:20Jerod Santo:Yeah, for sure. OK, so where does BuildKite thrive? What particular type of team or enterprise do you thrive in? The area that BuildKite has always thrived in is like this like fastest moving tech companies of the world. Like we've been disproportionately successful in that small niche. the kind of Shopify class, Uber class, you know, open AI class of folks that have this key problem around iterating really, really fast. And, you know, the thing about all of those folks is they all have subtly different needs, subtly different problems. And so we've tended historically towards building like really well engineered Lego blocks that scale like orders of magnitude more than what our nearest competitor does.

38:06So, you know, I think that that puts our system in this tension where, you know, you've got to spend some time assembling those building blocks, those Lego blocks to get the thing that you want. But the end result is far and away more performant and scalable and the experience is better than what you get from something that's off the shelf. So I think we've started from a position of really well-engineered Lego blocks and then are kind of working backwards towards kind of creating the thing that scales down to a startup that starts with one person and 10 agents next week.

38:38Jerod Santo:Well, friends go to buildkite.com. That's buildkite.com. You deserve better CI. Engineer for the frontier we are all facing, trusted by the teams setting the pace. Again, buildkite.com. Once again, buildkite.com.

39:02Jerod Santo:So the way you're, if I understand correctly what you just said, that the mechanics of how you're making this change, the change, we understand what the change is influenced by, but then on the how you're saying to internally fork, and in your case, your commercial open source company. And so you've had all of your code out there. Your open source has been licensed one way, but if you go a certain way, there are certain features that were always available, open and open source, source available that you can see. You're saying that you're changing that so that all of that code base will remain there.

39:35Jerod Santo:The license of free and open source will remain the same, but internally your mechanism is to fork it and rewrite the areas, the surface areas that are at risk or at most risk. Yeah, correct. And we also obviously point the production URL to the private repository, right? So like, because, you know, what you see on GitHub today is what we've run on the website. That's just how open source works, right? That was the whole point. Like you see the code that runs my service. That was the whole spiel. So that spiel is no longer safe enough to be valuable for your customers. Like it's an unnecessary attack vector.

40:16So that doesn't mean we're no longer open source. We are still open source. It's just that we have an internal fork the same way other many companies like WordPress.com is an internal fork of WordPress.org. It's still WordPress, uses the same plugin system. But if you sign into WordPress.com today, it's a different experience than if you get the open source WordPress. So they kind of like did that change. Well, probably more from a commercial point of view, not from a security point of view. But I think they internally most definitely have different things in their off system than what's out there, which I don't blame them.

40:59But the narrative of like one code base for everyone, you know, self-hosting and production environment just no longer makes sense. It's just, from a security point of view, it went from, wow, this is safe because we're open source, to is that really the smartest, safest decision you should make as a business that has customers and that you want to keep them safe, you know? Yeah.

41:30Jerod Santo:I guess the question might be, why even remain open source at all? and I don't mean that as like anti-open source. I mean it more from a chore standpoint. So if you've got to fork your own code base and now you don't want your vulnerabilities out there, so that means there's a buffer layer between what is open source and what is closed source, i.e. the fork that you have internally, the chore must be to keep those two code bases either remotely in sync and not have developer gymnastics playing around. Like what's the point of open source then for a commercial open source company that was, you know, has been in your shoes, but you're not making this change?

42:15I mean, it is, it's, it's a really, it's a really terrible situation. You know, it's like, yeah, pick your poison. I would argue the reason to keep an open source project. And by the way, we're also rebranding it to cal.diy. We've got that domain. And so like do it yourself, essentially, like it's a whole it's there's going to be big red letters like use at your own risk, not production ready. Like you can self host this for your whatever hobby or maybe small business. I think the benefit is if people end up self hosting a quote unquote community edition, it's they are not going to be the one being hacked.

43:03right like it's us it's the largest company that gets the attack the one with the most money the the most reputation your neighbor barber who self-hosts cal.diy like a you need to find that server b you need to know exactly who you're targeting who you're like it's it's kind of like security by distribution right like when you're self-hosting you're not going to be the target unless it's like a very easy to attack multiple nodes in a way. Like if every node runs the same software, then you do like this mass attack. But it's just not commercially viable for hackers to hack your neighbor's barbershop.

43:45So theoretically speaking, yes, the Cal.DIY version will have the code base off today, right? Potentially, we don't even know if it's insecure. We just know it's out there. But let's say it's slightly less secure than the private fork. Sure. But it gains its security by being just so irrelevant in terms of distribution, right? Like five people here, 10 people there, five people here, one person there. So you're kind of like gaining that security back by just being more like less of a target, you know, less of a target on your back. and then at the same time we can always obviously and I'm only strictly talking about like auth and database and middle layer etc like if the community builds great features we can adopt them and credit them if we build sick features which we do we push them back into the open source community edition so I hope to keep that relationship strong the same way WordPress has been doing it for many years so it's not like a unique idea like we've always had private and public forks of open source projects docker has its own enterprise edition that's private source yeah but like i think and if i'm being honest with you all of these forks have been for commercial reasons some investor has pushed you some ipo some bank looked at you and be like we need some proprietary code because of whatsoever so it looks better in our brochure.

45:18But trust me with my fullest heart, this is not a commercial. Like we are growing like 7 % to 12 % month over month. We are not in any way short on cash. We have no investors who are bullying us to go private source. We have the most open source friendly investors on our cap table. We had to convince them this is the right decision. This is like a nuclear problem for commercial open source, you know? And so it's, I wish it was a commercial decision because then I can like say, okay, this is only affecting us. But this is affecting the entire industry. This is like, yeah, like the quantum computing cracks encryption type of level, you know?

46:07Jerod Santo:Yeah, that quantum, what do they call that? Quantum safe or quantum ready in terms of security and whatnot. Exactly. I mean, that's a really insane thing too. What other examples can you give? I know that you kind of give a couple, but what are some explicit examples of other commercial open source companies that think like you do or have the same problems you do? And can you enumerate their challenge in the public that's being showcased? Well, I have many conversations that I really cannot make public because of security and just the inherent risk. What's on X? What do you see on X? What would you retweet?

46:51I mean, well, I can definitely talk about public situations, right? Like there's, and I also don't want to throw anyone under the bus, but there's, you know, there's tooling around logging, right? Like log systems that log user activity. Those products are usually open source because it's a developer package. You need to like, you need to import the SDK. So those have been hacked by AI, which is really bad because now that attacker has access to all your users' actions, if that makes sense, like the events that they send. For them, they are really screwed because they have to be open source for the sake of being a developer kid, right?

47:36So I would say that's two companies that are directly affected and I know of. There's a CMS, which is open source, which is really struggling because when you're a CMS, you simply cannot expose your internal systems to the world. I mean, just think about how much knowledge is locked up in a CMS or the risk of somebody, I don't know, like imagine you get right access to someone's CMS and you're publishing something on Nike.com, you know, like that's just not great. So there's a lot of commercial open source businesses out there that have to be open source in order to run. In that regard, we're almost somewhat lucky that we don't depend as much as others to be self-hostable.

48:30Again, 99 % of our revenue comes from our SaaS, app.cal.com. It's not like we sell a code snippet that people inject in their business. so yeah it's and then there's a couple payment providers that that like call themselves the open source version of stripe obviously anything that touches payments is hypercritical you know that's that's always tricky I don't even want to talk about crypto because I really don't like crypto but all of these crypto projects are being cracked open that open source

49:06it's it's a wild west out there

49:09Jerod Santo:and so you're if you were a doctor, Dr. Peer yeah your prescription for these commercial open source companies in these high impact areas is to rethink their model and follow you in terms of forking internally creating a new relationship with your open source version if you even keep it, in your case You're keeping it, you know, cow.dyi or DIY, which I think is super cool. I had a little case of dyslexia there for a moment there. But nonetheless, cow.dyi. I did it again. DIY. DIY. Cow.dyi. Do it yourself. Come on, Adam. Well, on the bright side, on the bright side. What's your prescription? Yeah, on the bright side and maybe on the bad side, like what's open source stays open source, right?

49:59Like we, we, we're not disappearing tomorrow. Yeah. More like cleaning the rock and making, okay. Vacuuming the rug. Vacuuming the, we're vacuuming the rock and, and closing the door to access it too. You can look at it. It's beautiful. It's a beautiful rug, but you can no longer step on it. Um, no, because like, look, there's like so many folks out there. Kellogg's not going anywhere. Like we can legally not, No, we can physically not get rid of the code. What we can do is move forward gracefully and make sure that the most vulnerable pieces of any piece of software is not public. I think that's a very fair statement to say because back in the days you would have those public because it's just really hard to hack them.

50:50Now it's easy to hack. Thereby, I need to take these things private. it. And by the way, having private code does not protect you from being hacked. I don't, nobody thinks that that's the golden solution. But if a security researcher, if many security researchers say it's five to 10 times easier to hack you when you open source, you have to listen to the security experts. If you don't listen to them, you're literally, well, probably you could use that as a way to even go to jail if you get hacked. I don't know. I don't, I'm not a lawyer, But like if you ignore multiple warnings from experts, you should probably rethink why you're even the co-founder of the business.

51:29Right. So my recommendation, my medicine is first, don't freak out. There's a high chance you're not compromised. Most likely you run a really small project. You're not a big target. second is to run many of these ai scanning tools and and and just see what the blast radius is today most likely it is quite high like every single project i've talked to was experiencing an uptick of reports by these ai tools by like tenfold like it's just messy it's really bad But turns out humans are really bad at coding for many years, including everything before AI. So chances are you just have vulnerabilities.

52:19That's just a fact. And then my recommendation would be to at least temporarily go private and work on all these vulnerabilities. Because here's another problem. And this really is my brain, right? When there's a hacker who actually wants to compromise your project, they are also running code scans against your own pull requests. Wow, yeah. So they, today, probably, if, let's say you really want to screw someone, right? You would run code scans against their own pull requests. And if you detect a pull request that fixes a previously known vulnerability that you potentially found already, or maybe not, right?

53:06Like an AI can understand whether a pull request is a feature or a fix of a vulnerability, right? Like you give an AI just random code and ask it like, what is this PR about? And it will tell you this is fixing a vulnerability. So they're using that. I mean, whatever is technically possible will happen, right? I'm not making this up. I don't know personally any hackers, but that's what I would do if I was evil. You would scan that PR. You would identify this PR is fixing the vulnerability. And in that second, I would abuse that vulnerability and send them an extortion letter, right? That's just the scary part, right?

53:46Now you think, Pierre. Right? I should not become a Marvel evil, Marvel super villain. But anyway, again, everything that's technically possible is out there and is happening. So I'm not giving you the playbook. That's literally what's probably discussed in these dark web forums. And so your best shot today is to take the repo private, fix all of these things in private, and then merge it back into one chunk. that's just your best like yeah squash that commit don't give them a exactly don't give change don't don't feed don't feed the machine don't feed the machine that's gonna extort you for bitcoin you know well if i don't know you were talking about this when you came on this podcast i'd probably not invite you you got me down over here man maybe we should not maybe we

54:40Jerod Santo:should not publish this is i mean this is good stuff i think this is this is truthful i mean And this is where my head's been at as well. Yeah. And you're bringing some new light to some things with me. I want to go back to, if you don't mind, not so much to fully backtrack, but I want to go back to your pull request tab. And not specifically just yours, but the pull request tab. The tab, yeah. And the reason why, I mean, so you're seeing what you're seeing about commercial open source companies. I don't think open source is dying. I do think pull requests may be changing and are becoming not irrelevant, but just fraught with a lot of slop that people don't want to deal with.

55:16So even projects like Ghosty,

55:19Jerod Santo:they're not taking on pull requests like they were before. A lot of folks that, you know, like Ghosty is a great terminal. And for a lot of reasons, it needs to be and wants to be open source for the, for the true nature of what open source is, but they're being open source, not open to contribution. So I want to, I want to pose this thought experiment here. How does this change GitHub? Is GitHub at jeopardy in any way as a business? Maybe not because a lot of their commercial features are on top of things that aren't there. But like if a lot of us are on GitHub because that's where open source is.

55:53Jerod Santo:And if the relationship we have with open source changes or open source changes enough, you know, is GitHub in a risky scenario? Because, I mean, they're banking almost everything on Copilot, right? I mean, that's a large majority of their infrastructure, even NPM. I know they have some changes coming out, and I'd love to talk to whomever's working at GitHub behind the scenes or in front of the scenes if there is any on NPM. I'm not saying anything negative about those folks at all. I just know that there's neglect. There's neglect there around NPM. So even one of the things that is the largest package manager and registry known to man on planet Earth is NPM.

56:35Jerod Santo:It's so important. I mean, that's where the Axios hack just happened, and we know how that went down, right? You know, what is the picture of GitHub if all this changes? What are your thoughts on that? Well, I mean, it's not bright for commercial open source, I can tell you that. So, like, if you obviously run packages, et cetera, freemium open source, you're probably more okay-ish or you build a new React alternative or self-kit, whatever, tailwind alternatives. but GitHub obviously has to rethink its own like I wouldn't call it economic model but like place in the world with AI where and this I would even say this goes beyond way beyond security because like look if somebody like Peter doesn't read its own diffs and the neighbor who Vibe codes its iOS app do people really care about the source code?

57:35Do you want to see the source code? There are probably already projects out there where the community has looked at more of your code than you yourself who published that repository. Simply, I mean, yeah, totally. I mean, that's going to happen, right? Where the maintainers have seen less of the code base than the community combined. Usually it's like the maintainer who writes the code knows the code. But now it's like I can prompt any project and publish it on GitHub. And then chances are I barely scratched the surface of the code that I've published. It's like as long as it works and it looks good, why would I read the code?

58:17And it's safe, safe. So obviously distributing code almost feels like distributing binary at some point. And GitHub wouldn't work if people just published their binaries. You know? I mean, it still works. But, like, who's going to read that? Or, like, you just put the bytecode, the assemblycode, whatever, the binary code up there, you know, 001001. That's great. Cool. So if source code, as sad as it sounds, listen, like, I'm not a fan of this, but if source code becomes unreadable, because nobody knows what the f*** is doing anyway. So if nobody knows programming anymore, if new students come out of university and they can't read source code, they don't know what an if statement is, they don't know what a, you know, what point has GitHub besides being a CDN to share zip files, if zip even is around that time, or, you know, or DMG files?

59:18Like you're basically turning into a mega upload where people just throw up all their garbage. So, yeah, they 100 % have to rethink everything about like what is the meaning of code in 2027, 2030. What is the meaning of code in 2030, you know? Yeah. And then obviously it's not in any way AI first. I mean, the fact that, you know, what I just explained, anyone can open pull requests for anyone. You know, there should be guardrails, there should be rules who can contribute. Like we're using these third party GitHub actions that like auto close pull requests from people who are not verified. That's all just hacks.

1:00:00You know, that should be first party coming from GitHub. Why do I have to install different third party plugins to make sure only legitimate people are opening pull requests? That should be your job, GitHub, you know.

1:00:19Jerod Santo:Well, friends, I'm back with a good friend of mine, Michael Greenwich. Michael, I know that I love WorkOS. Our audience may not know about WorkOS, but what are the challenges developers face starting a new project? Choosing the right tools, choosing the right database, choosing the right auth. Take me there. When a developer starts a new project, the decisions that they make at the very beginning end up having long-lasting consequences. What language you build in, what platform you build on top of, what database you choose, These are things that are very hard to change later on. So they have like major consequences.

1:00:49And especially if they limit your ability to grow and scale, at some point, as the product starts to take off, you're going to have to stop developing new product features and go re-architect or rebuild your system. And that might be a killing blow right at the moment you need to accelerate. So these decisions early on are really, really important. And I think that's why developers gravitate towards solutions that are mature, things that they know that will scale, even things that are open source. You're going to pick something like PlanetScale for your database provider, not because it's the cheapest or because it's the most fun to use, but because you know it's going to be a durable provider that you can scale on for years.

1:01:27And WorkOS is like that for auth. At the earliest, earliest days, if you look across all these different services, they kind of look very similar. But at day 1 ,000 or day 2 ,000 or day 10 ,000, you're going to want to have made sure that you picked a platform that could scale with you. And today, WorkOS is powering auth and identity and security and permissions for all these AI companies, literally the fastest growing companies in the world, like OpenAI and Anthropic and Cursor and Perplexity. WorkOS is under the hood there. So I think when people pick WorkOS early on, really what they're doing is trying to pick the defaults to allow them to grow and rapidly scale.

1:02:01And there's no platform other than us that's done that at that same level.

1:02:04Jerod Santo:Well, friends, the next step is to go to WorkOS.com. Sign up today. Check it out. Free for a million active users. Try it today. There's no excuse not to. It is your default. You should choose it. So do so. WorkOS.com. Once again, WorkOS.com.

1:02:30Jerod Santo:Did you catch that post from Mitchell Hashimoto, Bonnie Chance on X? Can you give a recap? I'll give you a recap. I see so many tweets. It wasn't long ago. It was March 25th of this year, and he started off by saying, here's what I would do if I was in charge of GitHub in this order. And he says establish North Star around being critical infrastructure because there's been a lot of downtime. Yes. They got a double nines back with the eight in front. yeah he talks about coming back uh establishing north star realm being critical infrastructure for agent code life cycles and determine a set of ways to measure that number two was whatever that fire everyone who works on or advocates for co-pilot and shut it down it's not about the people he's trying to be kind here uh i'm sure there's many talented Acquire Corsa.

1:03:24Acquire Corsa.

1:03:26Jerod Santo:Right. Pay whatever money is possible. And he says, buy Pierre, which is Pierre.computer. We've talked about that on the pod before. You may be aware of it as well. Pierre. Buy Pierre and launch agentic repo hosting as the first agentic product. And I can paraphrase more of it if I needed to. But then the last one was reevaluate all product lines and initiatives against the new North Star, which is really predicated on being critical infrastructure. Again, back to those nines, of course. And he says, I suspect 50 % get cut to make room for the different ones. And so, I mean, I'm not sure if he's accurate, wrong, or right, but there's a lot of folks who are upset at the uptime and downtime of stability at GitHub.

1:04:13Jerod Santo:I mentioned before, I know they make a lot of money off GitHub Enterprise as well, but I think they're really banking on GitHub Copilot. And I just had Burke Holland on the podcast. He's one of the developer advocates on the GitHub Copilot team, so he's largely aware of what's going on there. I know more Copilot advocates than Copilot users. You know, I'm not a GitHub Copilot user. I'm also not a hater. I'm not a hater, really. Me neither. I don't think you're trying to be either. I also don't hate polar bears. I just don't see them on a daily basis. Sure. I love polar bears. What I think is interesting, if we look back, because I've also had a podcast with Amelia Wattenberger.

1:05:07Jerod Santo:and if you recall do you know Amelia Wattenberg of any chance the name ring a bell to you she works on the GitHub Next team which is where GitHub Copilot came out of GitHub Copilot was already in place and in motion before she got there but she was a role she played a role in GitHub Next which was sort of an offshoot of the office to the CTO at GitHub so it became this area to innovate and that office of the CTO is predicated on Jason Warner Jason Warner's idea was GitHub Actions. GitHub Actions is largely why GitHub got acquired by Microsoft. I'm compressing a lot of the history here just for the dovetail.

1:05:46Jerod Santo:And so this GitHub Next area was this laboratory where a lot of the innovation came from. That's where GitHub Copilot came from. And a lot of the race and current status of the race of where we're at was around GitHub Copilot being tab completion. They were the first They were the first wow factor And here they are the late runner Not the front runner Of this AI race It's just kind of wild to see the picture Kind of come full pendulum There on that Does Microsoft Has any race in the coding Industry Right now besides Just co-pilot right I mean The story around co-pilot is so We have Cursor, we have Codex from ChatGPG, and we have Cloud Code, which is primarily terminal, obviously.

1:06:43And then we have what's it called? Windsurf, I believe. I believe Windsurf turned into Cursor, didn't it? No, Windsurf got acquired, but was it acquired by Microsoft? I don't remember. Google, I think. There's a lot of change there. Oh, and then there's Antigravity. anyway and everything is vs code and replet yeah true yeah and then yeah replet's actually doing

1:07:06Jerod Santo:some pretty cool stuff i haven't used their stuff yet but i know some people who are and you know there is a landscape there is a landscape it's not only true but but i think um what i what i really find sad about microsoft is that i think they have the head screwed in the right place but they just don't have the execution right like yeah they they came up with co-pilot they were the first investors in open ai the first big ones that they made it big they fully banked on it and now they seem like they profit the least of it i'm not really sure but uh i just think it is kind of wild to look back at you know we were all enamored with GitHub Copilot, tab completion, function completion, things like that.

1:07:57Jerod Santo:And now it's not really the major player in the race, but it seems like GitHub is banking big on that. But as a team and individuals like you are and we are that have, we're not sure of the future of GitHub. And I don't know either. I just don't know. But I know that they seem to be largely focused on Copilot, and their uptime has been down dramatically. Now, Martin Woodward, who's a developer advocate for the dev team there, he's come out and talked about it. Ryan Daigle, COO, not CEO, because there is no CEO of GitHub anymore, came out of the woodwork and started talking on Twitter about slash X around these things.

1:08:43Jerod Santo:and it's cool. Please talk about it. But there's something going on there and there's something changing there. And there's Codeberg now, which I'm not even sure who's moving to Codeberg. I think a lot of it might be potentially self-hosted. So what keeps you at GitHub these days? If you're not open source, if you, Cal.com, is open source and more dramatically open source like you were before, what keeps GitHub your epicenter? It's not really much of your epicenter. I know. and look what happens if the user base of GitHub is agents it's not really a nice business you know I struggle with that one because the reason why I struggle with that one and I want to maybe and maybe you can draw this line too is largely agents but is largely agents there on behalf of a human so that's where I draw the line because I've got agents and I'm a human being And so I have intent, right?

1:09:40Jerod Santo:And those agents are acting on my behalf. And so bots versus agents may be a little bit different. And I'm not sure. How do you draw the line there? Well, how much is it a human intent if you ask Claude, like research the top 10 frameworks and then of those repositories, pick the most popular issue and open a PR for it? Is that really your intent? I mean, it's no different than search, right? And search would still be – you would still say it's a top search result, right? It's just a new way to search. You're skipping a lot of intention. That's what I'm saying. Like your agent makes a lot of assumptions and decisions that detach you from it, I would say.

1:10:27Jerod Santo:Yeah. That line will continue to be examined and blurred in my opinion. I think I sit on the side that if I were making that search and say, hey, go out and find me the top 10 repositories and help me learn how to commit a PR. I think that's still user intent. I would probably still draw that back to user intent. I think that's cool. And I think everybody should do that. But if that AI makes that decision for you and just makes it for you, the PR and everything, you no longer have any emotional connection to that. you might not even know which repository your agent committed to yeah i suppose if it's fully autonomous and there's no awareness and the intent is very thin then it does get thinner obviously i think it's more like an ai agent only i think this whole agent thing well first things first agent is a horrible name because agent theoretically means there is a persona that has its own objectives and autonomous decisions, right?

1:11:33Everything else to me is like a human scaled with AI, right? Like tap completion is very different to autonomous coding, right? Like you are still writing codes, but you have auto-completion. We've had auto-completion for words since 15 years. Like that's just not that crazy, but, but I think the innovation came for coding that it was actually working and not just like brambling weird shit, but to the autonomous future that a lot of people are imagining is what I just said, that you have this coding agent who wakes up at 8am, well, doesn't sleep, doesn't need to. And, and grinds GitHub bounties, searches the web for whomever probably, probably the most profitable agents will be hacker agents you know that try to extort you on a bounty versus extortion metric but let's say you are a white hat hacker agent you would probably autonomously serve the web you would find interesting repositories maybe you are looking for repositories that your company is depending on you try to maybe put your own company policy into that fringe freemium open source project, or you want to, maybe you're trying to improve a certain library that your company depends on.

1:13:07I mean, even today already, Cloud Code could analyze your code base today, and it could find a potential vulnerable open source dependency you depend on, and it would then, it could autonomously visit that repository's project and open a PR itself on that project trying to get your fix into like that is not impossible today that's i'm not sure if it's happening at scale it's probably happening in installation but theoretically speaking your agent could hit a wall and then autonomously raise a PR in that dependencies repository right that's not no longer your decision your decision was to improve your product but the agent made the autonomous decision to go out and hunt and open a PR in someone else's repository.

1:13:55Yeah. That to me is very detached from tap completion. You, Adam, wants to improve my product.

1:14:02Jerod Santo:Yeah. So are you for that or against that then? I mean, that seems altruistic. Like while it may not, it's, you know, one step or two steps removed from my original intent. Original intent is to learn about the security of my dependency graph. And then the two steps removed is, you know, figuring out which ones have issues and correcting them or finding a correction in somebody's PR. Are you for that or against that? Well, I think us as the tech community, we need to find peace with the fact that even though this GitHub user has a human avatar, this GitHub user has not written a single word of that PR.

1:14:51Because that's just the reality. So first, we need to be okay with that. And then the second thing we need to make peace is, did that person even think about my project when they opened this PR? Like, are they aware of it? Do they know me? Do they like me? Do they have the same ethics? What is their altruistic intent? Is it to improve their own dependency? Or is it to find a job because they ask Cloud Code like, hey, I'm unemployed, like find the best 20 repositories and get my name out there? or is it even trying to build a backdoor or break a feature or change a button that was previously most clicked and now it's, you know, you can also, you don't have to be a hacker to, it's not illegal to raise a PR against Cal.com that makes our product worse.

1:15:41That's not illegal, right?

1:15:43Jerod Santo:No. Highly unethical, but you don't go to prison for that. If you ask CloudCo to make Cal.com worse, it'd be like okie dokie sure let me remove the login button job's done you know let's dovetail hardcore to the right if you don't mind and let's talk about the success that you've had I mentioned at the top of the show seed investor very small check of course but I was very happy to do that because you know I was using Calendly I liked Calendly a lot better I liked your mission We had you on the podcast. I liked your mission. I liked, you know, this was a lot of the rage at the time to come out as a commercially open source company.

1:16:27Jerod Santo:We both know JJ. I think you were part of OSS Capital in terms of your initial raise and support there. So there's some history there, but tell me about, give me as a, maybe a seed investor, give me a, give me a glimpse behind the scene of the success that is happening or has been happening. Yeah. Look, I mean, we, we, we are blessed in terms of timing. and the renaissance of open source. I believe that might even been the topic of our first conversation, like where do all these commercial open source startups come from? And they're all doing great from what I've seen, the people that I'm trying to be close to.

1:17:03Open source was almost like a, what do you call it, like a wish dad for way too long and it was still striving. I think now it's getting harder again. But I think my vintage of open source companies has been pretty successful with what they're doing. There's many good outcomes. And look, open source is awesome. I love open source. I wish we would not be under this threat, which you just can't close your eyes to. So, no, Calicom has been growing fantastically. We're very happy. The team's happy. We're reaching, I'd say, like the milestones we set for us. Very low churn, high growth, you know, SaaS, high margin SaaS.

1:17:54We don't have a single AI product that's catching on, which also means we're not burning any AI tokens, which means our margins are great, still great. It's quite funny when I talk to founders, we're like, oh, my God, we're doing five million in AR now. and I'm like, okay, and how much, what's the bottom line? And like, oh, I mean, we're burning 10 million. So it's like, okay, fantastic. So it's like, I mean, look, every business is great if you're selling like a dollar worth of AI credits for 10 cents, you know, like that every business is fantastic if that's your business model, right? Like if you, and then you've seen this on Twitter, all of these coding assistants are adding rate limits and reducing usage and trying to upgrade you into $200 plans the economics don't make sense in the AI space they don't make sense yet maybe they will but it's an Uber type thing where it's like how is this Uber so cheap?

1:19:02well duh, somebody's paying for it

1:19:07$15 $1 ,000 from SF Airport to the city. Yeah, right.

1:19:11Jerod Santo:That doesn't happen anymore, but it did. It did. It was fun. Fantastic times. I was loving it. That was great. That was a good time. See, now it's like, oh, gosh, 80 bucks for that ride? Wow. $1 delivery DoorDash? Yeah. Right. That was good. I saw something recently. They said, I can't recall what it was, but I was so surprised by it. They literally said in their marketing, we'll eat the fees. And I'm like, that's great for marketing because your market is like sweet. This is a great carrot. Let's get some people attracted. But you're literally telling the market, we're going to lose money. We're spending this money to get you.

1:19:53Jerod Santo:We're taking the fee. You're basically saying do not invest in this business unless you like to lose money. Yeah. I thought it was kind of funny. I told my wife, I'm like, babe, that basically says we're just going to lose money here to get this business. we're going to subsidize it as marketing adam if you want to have the fastest growing startup in history you could launch a landing page and you say get a clodd api key that works for half the price we pay 50 of it but still pay me right so so you're gonna have you post this on hacker news and you're gonna make like a hundred million in the first year and you're going to burn 200 million because that's the mile you know you pay 50 of it but you've got to be a startup making 100 million in the first year and you can go to every podcast and and and say this is how we made 100 million in the first year without saying you burned 200 million yeah but that is essentially what sadly a lot of startups are doing right now they add some flavor some prompts some system prompts some ui some sidebar some orchestration and and drag and drop but a lot of these startups are simply doing that, not with a 50-50 split, but maybe a 5 % to 95 % or 10 % split.

1:21:14In my eyes, it's not a great business, but for some it works. If you can raise billions of dollars, you can do that for quite some time.

1:21:20Jerod Santo:The one agent that hasn't done that and hasn't done it to the degree, what am I trying to say there? they haven't they famously come out and and said we're not going to sell it for less than it should it's actually expensive and we're charging appropriately is our friends over at amp code now they're wrapping uh open the eyes apis they're wrapping anthropics apis they're giving you versions of gpt 5.4 codex etc they're giving you versions opus 4.5 at all the different variations of it and they're sprinkling their own abilities on top of that and amp is i don't know if it's sourcecraft because that's where its roots came from but um what makes it so good i'd love to like learn what makes it so good but amp i have you play with amp by any chance here i have not no well after this podcast go and play with amp ampcode.com I believe it was so successful for them that they spun this out of source graph.

1:22:27Jerod Santo:So amp was a sub product of source graph, which was already largely popular and very successful. And they built their own agent called amp and it was so successful. They had to like spin it to its own company. So now it's amp code Inc or amp Inc. One of the two, I'm not sure. And if I have a really hard problem, I just know I want to get right. I've got to use amp. and they have a free model, which is paid for by ads. And now that's changed too. It's like$10 per day you get. And they basically said it wasn't successful. They actually put a$10 million per year business in ad sales on that, and they close it down.

1:23:09Jerod Santo:But by and large, they're not subsidizing the tokens. They're charging appropriately and profiting on it. And I think they're not growing the hockey stick to everybody else's, but it's still growing quite well. Yeah. Well, another business, yeah, I mean, exactly. It's like how aggressive do you want to grow? I mean, again, you can add your flavor on an AI and wrap it and make a good UI and resell it and make money without losing money. Like, it's perfectly fine. It's just, I'd say, the coding space is just so competitive that, like, nobody's really in it for the UI. It's just like, where can I get the most compute for the least money?

1:23:48but I mean companies that have not done this also is like mid-journey you know like they've always been profitable it's a bootstrap business they never raised funding and I don't know what revenue mid-journey is today but they found a way to profitably sell subscriptions and rate limit accordingly I mean they pretty early built I mean they always built their own AI right I feel like they've never bought other ai so maybe the margins make more sense for them because you you're the your own supplier you don't need to buy tokens you just need to buy well just buy infrastructure

1:24:23Jerod Santo:the inference and the infrastructure and the cost to maintain infrastructure yeah uh keep it up supply but you're cutting out one you're cutting out one middleman for sure yeah the one with your own markup yeah it is a big mess there i think with uh i mean it's a big mess to to manage but that you're sort of in charge of your own mess. So your cost center is different. You're not buying tokens. You're purchasing man hours to produce and to sustain and hardware itself and managing that hardware's uptime, literally hardware infrastructure, like real hardware, bare metal, as they say. Oh, wow. MidJourney calls itself first community-funded AI research lab.

1:25:07That's hilarious. I like that a lot. we are lean self-funded to see the team always hiring mid-journey has no investors we are funded by our own community that sounds like the community has ownership which they do not

1:25:23Jerod Santo:break it to you but that's like saying my customers are my investors which does yeah well i mean yeah non-dilutive capital means i own the ship anyway but i mean look it works I mean look it works for them and I think that's something like incredible that you can build AI businesses without burning credits, burning a hole. Anyway how do we get there? I mean yeah Telecom we don't sell tokens. You still don't have any AI I was going to come back to you. If you don't have any AI where's your growth coming from? Yeah like Who would have thought people still use SaaS? SaaS is not that no I mean And it's, yeah, I think we just continue to do a good job and build a good product that people love and pay money for.

1:26:14It's not everything has to be AI. Surprise.

1:26:17Jerod Santo:Surprise. Surprise. Where are you, again, another pun here, but not on purpose, where are you spending your time in terms of product? Like where is the innovation happening that contributes to growth? What is making that happen? I personally, I spend every day at work looking at product-related topics. So pretty much every major product decision goes over my desk or comes from my desk, which means not only, you know, larger or new initiatives, whether it's like an iOS app or a browser extension, but also looking at existing features that we need to sharpen the edges, not sharpen the edges, soften the edges, sharpen, that'll be sweet.

1:27:10Border radius zero. And yeah, like fix tons of bugs, make sure to, you know, get enough buy-in in the company and assign resources. So I would say I'm mostly responsible for the product quality today. So if there's something inherently broken, please send it to me. um i recently started to do sales again just because i enjoy doing it not because it's um like not because we're short staff but because i really just want to have this conversation with customers and learn from them and understand what they what they go through it's more like a product exploration than necessarily closing the money um that's how i spend most of my time with really just talking to customers and then trying to bring that to life.

1:28:00Jerod Santo:You want to take a, I wouldn't call it a bug, a bug fix, maybe an issue. Let's call it an issue. Would you want to take an issue live on the air for me? Oh, for sure. Yeah. For sure. As an investor and a user. I'll spin up my cloud code and submit a PR. So we reschedule a lot. We have in the past. So we either, as changelog, we use cow.com to schedule all of our podcasts, our entire workflow for creating any new event that is podcast related. And I do as well in sales. So all my sales calls, I do a lot of conversations with founders, CEOs, key product leaders in companies that advertise with us.

1:28:42Jerod Santo:We have them on the podcast via voice. And so we showcase who they are. It's not just me reading an ad is very unique and informative and our audience loves that. But so I do a lot of scheduling for all the surface area of what we do here. And so rescheduling is at the core of the crux of what we do. Scheduling and also rescheduling because not everybody can show up. And we even had a reschedule, you and I did. And so the challenge that I face, one of the challenges I face with rescheduling is, one, it works great. And the only part that doesn't work great is that if I want to reschedule and my availability dictates how I can reschedule, I can't break that unless I go into the admin and create an override.

1:29:26Jerod Santo:Like I know my schedule and I want to reschedule it and I want to be able to pick whatever time I want on my own schedule, not have to go jack with my availability to then have it open and create an override. I feel like that could be a little smoother. And that's been a multi-year challenge because it's never been changed. And I've never told you. I just worked around it. Tell me. So here we are on the podcast. How do you feel about that kind of change? Have you experienced that yourself? What do you think about that? You know what? I think I have this on my never-ending list of tickets for like at least a month.

1:30:03And I think today is the time where I finally get to ship that. I've experienced this myself. uh i i'm always annoyed i always talk about it with the team and then um some it hits the fan and it gets deprioritized but i do have to fix this and i do agree it's very annoying um and we

1:30:24Jerod Santo:will the ux has to be spotless maybe keep it keep it in the same ui that you do like a normal user would don't take me back to admin do it in the same reschedule yeah um and i'm not sure i would give that ability to the invited no do it to the inviting oh yeah one who controls the calendar the one who's in charge yeah yeah uh because we've even had to reschedule a podcast and we largely record our podcast at two o 'clock p.m and that's been a standard for us for a long time it's where we mentally block off our own day to even be present in our podcasts um but at the same time, it may be somebody who's in Europe or maybe even Australia or New Zealand or, you know, South, you know, South Africa or somewhere in the region where the time is far ahead, 15, you know, 12 to 15 hours in advance of my time here in Austin, Texas, which is Central Standard Time.

1:31:19Jerod Santo:You know, we'll want to reschedule to way out in the morning, same day, same, same concept, but I can't even do that in an easy way. What I will tell folks is go ahead and put it on the calendar, and I'll manually change it in my own calendar. And that's been okay, and I've been fine with that. But I would say keep it in the same UI because it's a great UI. It functions well, but recognize I'm an admin and give me a little bit more ability and maybe even warn me. Like, hey, I don't know. Figure it out, Pierre. Figure it out. But that's where it should happen. You know what? I just wrote this in my coding agent.

1:31:56And so maybe we get a PR in the next two minutes.

1:32:00Jerod Santo:Man, that'd be so awesome. That'd be so awesome. Kick that off. Say growth is coming from this good product is what you're trying to say. Yeah, that's exactly what we were just doing. You tell me something that's really frustrating. I agree it's really frustrating. And then it's my job to make that not so frustrating anymore. I know you tweeted about this. And then you just do that over and over again until people really, really like your product. Yeah. Make them happy. Make them happy. Right. I know you just tweeted about this on March 25th. Just hit six. Oh, no. Seven million ARR. And I think you mentioned in the pre-call that numbers north of that number by a little bit because your growth rate is 10, 12 percent per month.

1:32:47you said it was the one of the i mean every every month is different between five and ten uh you know good months and bad months but um yeah on average um we're hoping to three x per year that's kind of like always been the agenda and the milestone we want to go for which is um yeah so we we are looking now at or soon to eight million hopefully soon to crack the 10 and open some champagne and go to bed at 12.30 instead of 10.

1:33:16Jerod Santo:Three in the morning. Will you have a party? Can I be invited? I'd love to come. I'd love to celebrate. Yeah, hopefully. Yeah, we should. We have a company retreat in Japan, which we're really excited about. So maybe that would be sick if that overlaps with the 10 million milestone. That would be really sweet. That would be in June. So April, May, June. Yeah, maybe. June of this year. Okay, so you're thinking by June of 2026, potentially 10 mil ARR. Probably not. Probably not. Potentially. I would say it's in the realm of possibilities, yeah. Okay.

1:34:01Jerod Santo:What would make you grow more and what would change your growth? What are the things that keep you up at night in terms of positivity and negativity? I know open source was one of them and a threat there, and we've talked about that. But what are the positive sides and potentially some of the negative sides that keep you up when it comes to Catacom? We do have large customers, right? Like we have a lot of grassroots, but we also have large customers. and I think there's a bit of a SaaS shock going through the industry where a lot of companies are really deeply looking at their vendor list and try to cut corners and cut costs and come with the argument like, oh, but we're paying you too much.

1:34:46We can Vibecode you in a weekend. You don't have to Vibecode Calicom. We're literally open source, just fork us. It saves you money and tokens. Like if you think that's the cost cutting approach, like just self-host it, por favor, like that's much easier. But yeah, that's still a thing, right? So like I would say the entire SaaS industry is experiencing some sort of SaaS shock where, you know, just under more due diligence than in the golden days of 21 where, you know, the pockets were a bit deeper and the money was flowing like champagne. but I mean that's just not something that I only look at that's pretty much everyone's looking at budgets and allocations and what to bring in-house scheduling up to this day is still really freaking hard like it's not something you can just one shot like some other SaaS companies like we have internally stopped using certain products because it was a a weekend of cloud code to to get to 70 80 percent of that functionality yeah um sketching is just like even the first 20 percent is just still really really hard so i think agi is achieved the moment you can one shot cal.com without forking um that's my benchmark so yeah i bet it is that's pretty funny

1:36:09Jerod Santo:uh yeah i guess you know even as an investor uh in cal and as a user of cal because like anybody i've thought about where do we spend our money now i don't think we spend a lot of money i think it might be like 30 maybe 60 bucks a month i don't know what the number is i want to say it's at least 30 bucks though yeah um for cal and yeah even though we're an investor we're a paying user that does make sense because why would you not um but i think in any case i'm like maybe i can self-host i love to self-host i'm a home labber it's like well maybe i can actually just go a different angle to cal and not so much save the 30 bucks that was not my concern was like How much change can I actually influence in my bottom line?

1:36:53Jerod Santo:And while$30 a month is not dramatic, what control can I get over self-hosting Cal.com? You offered open source for a reason. You even blessed the Docker image I could run. So you make it super easy, brilliant and convenient to self-host Cal if I want to. It's definitely crossed my mind. I didn't execute on it. It was in my to-do list to look into it, but only as an exercise of could I, not so much should I. And I think that's an interesting place to be in around SaaS. Have you felt, because you're growing, but have you felt a retraction? And has it been that? Has it been self-hosters going and doing it?

1:37:32Jerod Santo:I don't think that's going to be a case, but no one's going to self-host Cal unless they really, really want to. Well, I think there's two reasons people self-host, as you correctly identified. If I want to tinker with it and play around with it and make changes. And the other one is security and like putting it behind your own firewall. Those people have always existed. We do have governments and health care that self-host, right? And they, Newsflash, also pay us because they want to and they need support and they need feedback and help and developer office hours. and compliance help and setup.

1:38:16And they pay us well. So we do have a really small amount of people who self-host and pay us. Now, they're most certainly in our Docker file. I haven't checked at it in a long time. Calcom has many polls, has over a million installations. So take it or leave it. That's a really big number.

1:38:40Jerod Santo:we're not in totality or by a certain measure whatever docker hub tells me i i don't know the it's the analytics of docker hub are really opaque but it's been pulled a million times now is that a million customers no but it's also not 10 um yeah so anywhere between 10 and a million people are using uh the cell host that uh file uh container um so it's a big number it's not it's It's not nothing. It's obviously not a billion people, but it's a million polls. But we don't charge them. That's okay. They would probably be on a free tier. If these are individuals, they would be on a free plan. Our free plan is as liberal as the open source version.

1:39:30We always want it to be like, you don't have to be self-hosting in order to get the product for free. You can be on a SaaS tier and be for free. I think where the revenue is coming from is just people want to move fast. Companies want to move fast. Self-hosting takes time. It puts the burden on you to keep it safe and updated and maintained. And a lot of people just simply don't want to do that. I mean, why is renting popular? It sucks. Sometimes you just want to rent and pay people money. and then when the sink is broken it's being replaced you know yeah limit your liabilities

1:40:11Jerod Santo:limit your responsibilities yeah limit your accountability limit limit limit as uh i like to do that i mean i don't rent personally i'm a homeowner but i do like to limit my liabilities who doesn't that's just exposure right lease a car yeah yeah i mean even that i own my own cars too like i don't lease at least services and things maybe but not really like those kind of large items and i know people that have said oh this is wiser this is not wiser or this can be you know this goes from a capex to a you know whatever x i'm in the same boat i like to own things like um yeah yeah i mean you can go either way so i imagine this shift from how you're forking your own code base i imagine you've thought to some degree maybe you haven't have you considered just literally going closed source completely um and going like the tldraw route where they have tldraw license it is literally not open source it's not even using a source available license it's just source available and issuing out a license key and being very uh I guess, smooth with how you might license something.

1:41:29Jerod Santo:So you might have an experimenter who's trying to figure it out. Maybe you've got a home lab who literally wants to home lab and host self host it. And you just give an instant license key. Have you ever examined that, that world at all when it comes to closed source source available? And the only way you can really use it is literally with a license key. Otherwise it's in like a demo mode. I have never seen the TL draw license and they actually made it up themselves. That's so interesting. Yeah. It's, I had him on the podcast a little while ago. It was a really good conversation. I'll give you a TL, a TLDR of this.

1:42:09I'm looking at it right now.

1:42:12Jerod Santo:The TLDR of their success, they largely sell an SDK. So they don't even sell you finished software. We came up with the analogy during the podcast. It's like orange juice concentrate that you put in your freezer. you add the water right like it's not even a complete product it's a complete sdk right and that's what they sell and they sell it as closed source it's source available and there's been some talk even uh you know they were out there on x famously pulling back their test suite because you can easily replicate you'll draw from the test suite you know that's i'm sure you've been down that road i've seen that the threats and stuff like that but uh i think it's because of the threat i'm not anti-open source but because of the threat and the desire to have a sustainable commercial company and have source available because of the reasons why source available makes sense for trust but have that relationship so what a license key lets you do yeah of course in this case is literally everyone who is a user gets a license key and you're very liberal with how you distribute those license keys that are non-paid so you want to be very open with it maybe even instant with a homelab key, for example.

1:43:25Jerod Santo:But you get an email and a name and you can forge a relationship that's very different from here's our free and open source, you know, cow.diy. What is wrong with you today, Adam? Cow.diy. You know, you don't have a relationship with anybody who uses it, really, unless you force the relationship or desire the relationship or get that inbound issue, which you don't even really want. I mean, maybe you want the issues, but not the pull requests. So what do you think about that license key world? Have you examined this thought at all? So as of today, or well, the current way the repository split is that you can fully self-host Cal.com.

1:44:08And then there's a couple of pro features that do require a license key and that are like under a source available license. So it's pretty similar what you're explaining. The only difference moving forward is that that source available will go private source. So the CaliCum of tomorrow will strictly be an AGPL v3, potentially even MIT. We might even change to MIT because it's no longer commercially used by us. It's there, it's public, but it's more of a public good than a commercial asset. But the source available part will go private source because it's already commercial and it's very sensitive parts of the product that should not be for the public eye.

1:45:02That's kind of like the, I think, the decision we made. We would never take anything private that's previously open source. But what we do take private in a sense is that we no longer have the source available commercial parts also source available. We take that private source. and i think but the initial question you had just to go back to the initial start was why even stay open source i think at the end of the day um we are forced to make a decision here whether it's the right or wrong one time will tell the market will tell and the technology will tell we don't know it's just it feels like the right one a lot of people in the industry agree with me and security experts agree with me which is sad i hate it like i don't like it but that's just what it is so we do not want to give up the open source ethos we keep cal.di for self-hosters for anyone who's you know excited to contribute and be part of this community it's just simply not that instance that we would be running an art production environment, right?

1:46:23That's really just in a TLDR, not TLDraw, but TLDR. The only difference is the open source code is now fully open source project. We don't run it ourselves. We give it to you. You can run it yourself if you want to, but we have a commercial fork of that thing that can do a little bit more and is a little bit more safer. So in a way, it's not like we're a private source company now we just use our own private like we use our community edition as the foundation and then we put some locks on it you know given what you share with me and what i've also been seeing myself in terms of how things are changing i'm i'm sad too by that but i'm not the state is

1:47:14Jerod Santo:what it is, I suppose. And I'm, I'm sad by the fact that's the fact, but I'm okay with how it makes sense to protect the investment, the company that you have a responsibility to run wisely. The customers, right? Like the customers, right? Like the data we're processing is no longer a fun. Like we have really like, like, like important data we're processing, right like who people are where somebody's going to be at with who they're going to meet with at a certain time and i know you have like uh abilities to charge for meetings and stuff like that so like even that you know whether they're making money there's a lot of things you can get from that that that you can you know cross-examine with other data that none of this none of this is sadly like look if you run a a chill open source project that i don't know makes a button green and glow when you hover over it, that's very different to having millions of customers who interact with each other, whether it's a chat bot, whether it's Discord.

1:48:26Imagine Discord gets broken open tomorrow and every single DM is public. That would freaking suck.

1:48:33Jerod Santo:That would suck. So open source is not dead, but it's changing. Would you agree with that? Yeah, 100%. I also don't think that commercial open source is that. Open source is premium open source and commercial open source, the subcategories. If you run a framework, you're fine. If you run a package, you're probably fine as long as you have your dependencies safe and secure. If you run a commercial open source project, probably make sure that it's not the same that's running on your production environment. I think that's usually good advice. But commercial open source is still really valid and fun and just a fulfilling place to be in.

1:49:24It's a lot of fun.

1:49:26Jerod Santo:Yeah. All righty. Well, Pierre, thank you so much for... This situation is depressing. It's not a happy ending yet, But I do think, you know, I think what I also hope is that people just simply understand. I think there's always haters out there who try to read into things. But I think my hope is just people just get it. Like, yeah, makes sense. Sucks, but I should say it. Yeah, we are at a unique position and place for sure. and I think there's hard choices to be made and I think things are definitely changing all around and it's TBD on where it lands in terms of that change. I'm long open source.

1:50:17Same.

1:50:18Jerod Santo:I really am. And I hope one day we get back to where we can be even more forthcoming with details. I know when you're a high value kind of property, it makes sense obviously to do what you need to do to protect yourself and your customers. And no one can really foul you for that. And I certainly appreciate the non-rug pull aspect of it. You know, I think there's a lot of folks who would just simply rug pull and that's not at all the case. And then, you know, if you were starting fresh and green and brand new, maybe you never even go open source at all. Maybe you start literally as closed source proprietary and you prove yourself in the market.

1:51:02Jerod Santo:Or you don't. I think the lure to being a commercial open source company these days is dramatically different than it was four years ago. Totally, yeah. And we don't even know where coding comes out in a year from now. So I think the most important skill for any founder is you have to adapt. And we're adapting now, and you need to be okay with that change. We're no longer a buck. We're turning into a private butterfly. So you just need to be okay with that transition. Yeah. Well, Pierre, thank you for keeping me on time with all of my time with Cal.com. Big fan, as you know. Big user, as you know.

1:51:43Jerod Santo:Daily active user of Cal. And I love it. When we started using it when we first invested, never looked back. I've hit a couple scenarios, but you've fixed things over time. It's gotten smoother, easier, better. Uptime has been always amazing. and you know for me five stars well i would only i would only knock you maybe a quarter of a point on the one thing i mentioned in this pod but maybe after that it's back to five stars again who knows and i i just got a notification from my coding agent who shipped your pr to override hosts get out of here yeah so during the pod during my life and i didn't do that's the world we're in Amazing.

1:52:27Come on now. We shall see what happens. We shall see.

1:52:31Jerod Santo:Well, I look forward to using that feature. I can't wait. I can't wait. You'll be the first one to test. I'll send you an update. All right, Pierre. Well, thank you again for coming on the pod. It's been good talking to you. I appreciate you. Thank you.

1:52:46Jerod Santo:Well, friends, a lot is changing out there. I don't know about you, but every single day I open up X with trepidation and anticipation at the same time. Like, oh, I don't even know. You know, can I get a reset here? So I don't know about you, but I'm loving Codex personally. I'm not really digging cloud right now. I haven't really ventured out to other places. Open source models are doing cool stuff. but by and large Codex, Codex app server and the fun things happening in and around the open AI Codex world, ChatGPT Pro world has just got me lasered in, gravitational focused in and I'm liking it.

1:53:26Jerod Santo:So I'll be in San Francisco here in a few weeks, September 14th through September 18th. If you're in SF, I would like to say hello. I'm trying to plan an IRL. Yes, a changelog IRL. If we could do it, fingers crossed at PlanetScale's headquarters. I really hope we can do that. If the stars align, we're making it happen. If you're not yet a member, go to changelog.com slash community. It is free to join. Get in Zulip. Get notified of all the things happening. And I'll see you there. Big thanks to the sponsors of this podcast. Coder.com, WorkOS, and BuildKite. And of course, our partners in crime, fly.io okay friends that's it the show's done thank you for tuning in we'll see you again soon

1:54:24Win it.

1:54:25Jerod Santo:Win it. It really whips the. Game on. Yeah.

From the publisher

This week I'm joined by Peer Richelsen, co-founder of Cal.com. What if the majority of open source repositories are already compromised and we just don't know it yet? That's the theory Peer brings to the table this week. We dig into how AI has flattened the knowledge graph to the point that a 16-year-old can vibe hack a power station just as easily as their mom can vibe code an iOS app, why the reporting culture that has kept open source safe all these years is collapsing under AI generated noise, Cal.com's move to fork its own codebase and take the sensitive parts private, and the eye opening reality that shipping "$1 of AI tokens for pennies on the dollar" is now a common startup business model.

More from The Changelog: Software Development, Open Source

All 232 episodes
Forking Cal.com to closed source (Interview)The Changelog: Software Development, Open Source · 1 h 55 min
Listen in VO