
The MonkCast
Evidence Over Certificates: John Ellis on the Eclipse Trustable Software Framework
What does it mean to trust software? For this RedMonk Conversation, Kate Holterhoff sits down with John Ellis, President of Codethink and the contributor to the Eclipse Trustable Software Framework, to pull that question apart. Ellis leans on an old image: the bridge builders who once slept under their own bridges to prove the work was sound. Modern software rarely faces that kind of test, even when it steers a car or flies a plane. He explains where trust tends to break, especially the integration step where hidden dependencies finally show themselves, and points out that a safety certificate almost never uses the word "safe." Rather than pass-or-fail box-ticking, the framework asks teams to state their confidence and back it with evidence that others can inspect and challenge. They also dig into AI-written code, the EU Cyber Resilience Act, and why rising software recalls suggest current habits fall short. This RedMonk video is sponsored by the Eclipse Foundation. Show notes: https://redmonk.com/videos/john-ellis/ Chapters 00:04 Introduction to the Eclipse Trustable Software Framework 02:57 Understanding Trust in Software 05:59 The Integration Moment of Truth 08:54 Challenges in Software Development Lifecycle 11:25 The Role of the Eclipse Trustable Software Framework 14:39 Managing Change in Software Development 17:20 Versioning and Continuous Improvement 20:01 Risk Analysis and Trustworthiness in Software 24:39 Automating Testing and Confidence in Software 25:23 Bridging the Gap with Regulators 27:15 The Complexity of Software and Safety Standards 29:18 Understanding Certification and Safety Claims 31:12 The Need for a Shift in Mindset 32:16 The Role of the Eclipse Trustable Software Framework 34:18 Navigating the EU Cyber Resilience Act 37:41 The Journey of Compliance and Awareness 39:16 AI's Impact on Software Provenance 43:34 Future Directions for the Eclipse Trustable Software Framework

