From open source hits to OpenAI (Interview) artwork

From open source hits to OpenAI (Interview)

The Changelog: Software Development, Open Source

June 5, 2026

This week I'm talking with Max Stoiber, currently working on ChatGPT's plugin directory and app platform at OpenAI.
Speakers: Adam Stacoviak, Nicky Pike, Max Stoiber, Michael Greenwich
**Adam Stacoviak** (0:01)
What's up, welcome back. This is The Changelog. I'm Adam Stacoviak, and today I'm joined by Max Stoiber talking about the long road from Open Source to OpenAI. Max has shipped a ton of Open Source. He helped build Spectrum with the spec.fm crew, sold a GraphQL CDN after realizing he captured almost the entire market. He helped Shopify ship Horizon in six months, and now he works on the ChatGPT plugin directory and the app platform. A massive thank you to our friends and our partners at fly.io. That is the home of changelog.com. Learn more at fly.io.
Okay, let's do this.
Well, friends, this episode is brought to you by our friends at coder.com, Secure Environments where developers and agents work in parallel. And I'm joined by Nicky Pike, Field CTO for Coder. Nicky, what is a field CTO?

**Nicky Pike** (1:08)
So I get that question a lot, and it's, you know, half the people understand it, half the people don't. So a field CTO, I describe it very simply as we're dev rel for the C-suite. So we provide a bridge between the customer voice, between the C-suite and the managers and the leadership teams of our customers, back into our product, and then we go through and we help enable our teams to have the same message to make sure that the message is correct and that we're building on something that people actually want, not just something that we think they want.

**Adam Stacoviak** (1:35)
Okay, so we're taking the laptop away from the developer. Not really, though, we're putting them in a cloud development environment, a secure environment where they can work with their agents in parallel. These are blessed environments. What's wrong with the laptop?

**Nicky Pike** (1:47)
The laptop is the trap here. And not only because the fact that it could be stolen, you could lose it, it breaks and you're out of work and you're waiting for a new one, but there's also just the consistency that you got there. We all know developers. Developers are going to be looking for some of the latest and greatest. And if you're not really controlling how they get out there, that's where you get this. It works on my machine. It doesn't work in production. It doesn't work anywhere else because you don't have that consistency. You don't have that ability to really standardize what that environment looks like. And this is a problem not only for new people coming in. You know, the onboarding statement is average, I think, is like four to five weeks for a new employee to really get their local laptop set up and ready to start doing their first time of code. And you know, the time to first commit is a metric that almost everybody knows. And the reason they can't do that is because there's a lot of tribal knowledge out there. They got to go talk to other developers. What are we using? Where do we get our dependencies? Are we getting them from public? Are we getting them from private repositories? But there's also the security and the supply chain aspect of this. When you have local machines out there, look at like the Chi Halud, you know, that virus that went out not long ago. This was a compromise of the MPM public repositories. They went and downloaded things, MPM did what it did, next thing you know, you're compromised. But when you use something like what we're doing with cloud development environments, then you can mandate and you can put restrictions on there to say, hey, you can only go get your packages from our private repo. Those packages are expected to have been thoroughly vetted. We know that they're clean. Now, does this stop everything like Chi Halud? No, if that compromised package gets into your private repo, you can still have that, but it really reduces the surface area of the attack and it also reduces the blast area of the compromise should it happen because if your laptop gets compromised and you have to kill the laptop for whatever reason, that's weeks out of work while you're either fixing that or you're getting a new laptop in. The cloud development environments allows you to kill that, start back up fresh and you're back and running in five minutes. You don't have to wait all that time.

**Adam Stacoviak** (3:40)
Well, friends, the first step is to go to coder.com, install Coder, self-hosted environments for your teams to enjoy, to standardize around, and it's open source, so you can try it out today. Once again, coder.com.
My friends, we're here with Max Stoiber. Been a fan for many, many years, Max, back in the Spectrum days, back in the Wayback days, when you sort of reinvented what has now become GitHub Discussions. How does it feel to have such an impact on, I guess, daily developer lives like you have?

99 more minutes of transcript below

Feed this to your agent

Try it now — copy, paste, done:

curl -H "x-api-key: pt_demo" \
  https://spoken.md/transcripts/1000651996090

Works with Claude, ChatGPT, Cursor, and any agent that makes HTTP calls.

From $0.10 per transcript. No subscription. Credits never expire.

Using your own key:

curl -H "x-api-key: YOUR_KEY" \
  https://spoken.md/transcripts/1000771390867