Evidence Over Certificates: John Ellis on the Eclipse Trustable Software Framework
What does it mean to trust software? For this RedMonk Conversation, Kate Holterhoff sits down with John Ellis, President of Codethink and the contributor to the Eclipse Trustable Software Framework, to pull that question apart. Ellis leans on an old image: the bridge builders who once slept under their own bridges to prove the work was sound. Modern software rarely faces that kind of test, even when it steers a car or flies a plane. He explains where trust tends to break, especially the integration step where hidden dependencies finally show themselves, and points out that a safety certificate almost never uses the word "safe." Rather than pass-or-fail box-ticking, the framework asks teams to state their confidence and back it with evidence that others can inspect and challenge. They also dig into AI-written code, the EU Cyber Resilience Act, and why rising software recalls suggest current habits fall short.This RedMonk video is sponsored by the Eclipse Foundation.Show notes: https://redmonk.com/videos/john-ellis/Chapters00:04 Introduction to the Eclipse Trustable Software Framework02:57 Understanding Trust in Software05:59 The Integration Moment of Truth08:54 Challenges in Software Development Lifecycle11:25 The Role of the Eclipse Trustable Software Framework14:39 Managing Change in Software Development17:20 Versioning and Continuous Improvement20:01 Risk Analysis and Trustworthiness in Software24:39 Automating Testing and Confidence in Software25:23 Bridging the Gap with Regulators27:15 The Complexity of Software and Safety Standards29:18 Understanding Certification and Safety Claims31:12 The Need for a Shift in Mindset32:16 The Role of the Eclipse Trustable Software Framework34:18 Navigating the EU Cyber Resilience Act37:41 The Journey of Compliance and Awareness39:16 AI's Impact on Software Provenance43:34 Future Directions for the Eclipse Trustable Software Framework