<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" encoding="UTF-8" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" xmlns:admin="http://webns.net/mvcb/" xmlns:atom="http://www.w3.org/2005/Atom/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:googleplay="http://www.google.com/schemas/play-podcasts/1.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:fireside="http://fireside.fm/modules/rss/fireside">
  <channel>
    <fireside:hostname>web01.fireside.fm</fireside:hostname>
    <fireside:genDate>Fri, 12 Jun 2026 20:38:45 -0500</fireside:genDate>
    <generator>Fireside (https://fireside.fm)</generator>
    <title>Sudo Show - Episodes Tagged with “Openssf”</title>
    <link>https://sudo.show/tags/openssf</link>
    <pubDate>Thu, 30 Sep 2021 05:00:00 -0600</pubDate>
    <description>The Sudo Show covers topics ranging from Open Source in business to deep dives into complex technology.</description>
    <language>en-us</language>
    <itunes:type>episodic</itunes:type>
    <itunes:subtitle>Where Business Meets Open Source</itunes:subtitle>
    <itunes:author>Sudo Show</itunes:author>
    <itunes:summary>The Sudo Show covers topics ranging from Open Source in business to deep dives into complex technology.</itunes:summary>
    <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/f/f84fed1f-7827-41bf-92fa-5917ca1b716d/cover.jpg?v=8"/>
    <itunes:explicit>no</itunes:explicit>
    <itunes:keywords>devops, it, cloud native, technology, sudo, linux, open source, work from home, productivity, red hat, FOSS, information technology</itunes:keywords>
    <itunes:owner>
      <itunes:name>Sudo Show</itunes:name>
      <itunes:email>podcast@sudo.show</itunes:email>
    </itunes:owner>
<itunes:category text="Technology"/>
<itunes:category text="Education"/>
<itunes:category text="Education">
  <itunes:category text="Self-Improvement"/>
</itunes:category>
<item>
  <title>35: Busting Open Source Security Myths</title>
  <link>https://sudo.show/35</link>
  <guid isPermaLink="false">b4775469-1cf0-4c40-830a-ff80a83b5f2e</guid>
  <pubDate>Thu, 30 Sep 2021 05:00:00 -0600</pubDate>
  <author>Sudo Show</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/f84fed1f-7827-41bf-92fa-5917ca1b716d/b4775469-1cf0-4c40-830a-ff80a83b5f2e.mp3" length="33214434" type="audio/mpeg"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>Sudo Show</itunes:author>
  <itunes:subtitle>Eric and Brandon sit down and look into some of the biggest security myths around Open Source software and one by one debunk them right on the show!</itunes:subtitle>
  <itunes:duration>34:11</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/f/f84fed1f-7827-41bf-92fa-5917ca1b716d/episodes/b/b4775469-1cf0-4c40-830a-ff80a83b5f2e/cover.jpg?v=2"/>
  <description>&lt;p&gt;Eric and Brandon sit down and look into some of the biggest security myths around Open Source software and one by one debunk them right on the show!&lt;/p&gt;

&lt;p&gt;&lt;a href="https://destinationlinux.network" rel="nofollow noopener"&gt;Destination Linux Network&lt;/a&gt;&lt;br&gt;
&lt;a href="https://sudo.show" rel="nofollow noopener"&gt;Sudo Show Website&lt;/a&gt;&lt;br&gt;
&lt;a href="https://bitwarden.com/dln" rel="nofollow noopener"&gt;Sponsor: Bitwarden&lt;/a&gt;&lt;br&gt;
&lt;a href="https://do.co/dln-mongo" rel="nofollow noopener"&gt;Sponsor: Digital Ocean&lt;/a&gt;&lt;br&gt;
&lt;a href="https://sudo.show/swag" rel="nofollow noopener"&gt;Sudo Show Swag&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Contact Us:&lt;br&gt;
&lt;a href="https://sudo.show/discuss" rel="nofollow noopener"&gt;DLN Discourse&lt;/a&gt;&lt;br&gt;
&lt;a href="mailto:contact@sudo.show" rel="nofollow noopener"&gt;Email Us!&lt;/a&gt;&lt;br&gt;
&lt;a href="https://sudo.show/matrix" rel="nofollow noopener"&gt;Sudo Matrix Room&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;a href="https://heartbleed.com" rel="nofollow noopener"&gt;Heartbleed&lt;/a&gt;&lt;br&gt;
&lt;a href="https://nakedsecurity.sophos.com/2015/05/14/the-venom-virtual-machine-escape-bug-what-you-need-to-know" rel="nofollow noopener"&gt;Sophos: Venom Virtual Machine Escape Bug&lt;/a&gt;&lt;br&gt;
&lt;a href="https://blog.tidelift.com/finding-5-more-than-half-of-maintainers-have-quit-or-considered-quitting-and-heres-why" rel="nofollow noopener"&gt;Tidelift Blog: More than Half of Maintainers Have Quit or Considered Quitting, and Here’s Why&lt;/a&gt;&lt;br&gt;
&lt;a href="https://www.jaegertracing.io/" rel="nofollow noopener"&gt;Jaeger Tracing&lt;/a&gt;&lt;br&gt;
&lt;a href="https://www.linux.com/news/measuring-the-health-of-open-source-communities" rel="nofollow noopener"&gt;Article: Measure the Health of Open Source Communities&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;a href="https://openssf.org" rel="nofollow noopener"&gt;Open Source Security Foundation (OpenSSF)&lt;/a&gt;&lt;br&gt;
&lt;a href="https://www.zdnet.com/google-amp/article/google-releases-new-open-source-security-software-program-scorecards" rel="nofollow noopener"&gt;Article: Google Releases New Open Source Seucirty Software Program Scorecards&lt;/a&gt;&lt;br&gt;
&lt;a href="https://github.com/ossf/scorecard" rel="nofollow noopener"&gt;GitHub: OSSF Scorecard&lt;/a&gt;&lt;br&gt;
&lt;a href="https://insights.lfx.linuxfoundation.org/projects" rel="nofollow noopener"&gt;LFX Insights&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;a href="https://tidelift.com" rel="nofollow noopener"&gt;Tidelift&lt;/a&gt;&lt;br&gt;
&lt;a href="https://opencollective.com" rel="nofollow noopener"&gt;Open Collective&lt;/a&gt;&lt;/p&gt;

&lt;h2&gt;Chapters&lt;/h2&gt;

&lt;p&gt;00:00  Intro&lt;br&gt;
00:42  Welcome&lt;br&gt;
01:14  Sponsor - Bitwarden&lt;br&gt;
02:40  Sponsor - Digital Ocean&lt;br&gt;
03:42  OSS Has Vulnerabilities&lt;br&gt;
07:45  Free means cheap&lt;br&gt;
14:53  Heartbleed Bug&lt;br&gt;
20:25  Open Source is Amature&lt;br&gt;
24:29  OpenSSF Scorecard&lt;br&gt;
33:07  Wrap Up &lt;/p&gt;
</description>
  <itunes:keywords>it, devops, cloud, enterprise, open source, itguyeric, sudo show, career, technology, red hat, brandon johnson, open-tech, myth, hearbleed, openssf</itunes:keywords>
  <content:encoded>
    <![CDATA[<p>Eric and Brandon sit down and look into some of the biggest security myths around Open Source software and one by one debunk them right on the show!</p>

<p><a href="https://destinationlinux.network" rel="nofollow noopener">Destination Linux Network</a><br>
<a href="https://sudo.show" rel="nofollow noopener">Sudo Show Website</a><br>
<a href="https://bitwarden.com/dln" rel="nofollow noopener">Sponsor: Bitwarden</a><br>
<a href="https://do.co/dln-mongo" rel="nofollow noopener">Sponsor: Digital Ocean</a><br>
<a href="https://sudo.show/swag" rel="nofollow noopener">Sudo Show Swag</a></p>

<p>Contact Us:<br>
<a href="https://sudo.show/discuss" rel="nofollow noopener">DLN Discourse</a><br>
<a href="mailto:contact@sudo.show" rel="nofollow noopener">Email Us!</a><br>
<a href="https://sudo.show/matrix" rel="nofollow noopener">Sudo Matrix Room</a></p>

<p><a href="https://heartbleed.com" rel="nofollow noopener">Heartbleed</a><br>
<a href="https://nakedsecurity.sophos.com/2015/05/14/the-venom-virtual-machine-escape-bug-what-you-need-to-know" rel="nofollow noopener">Sophos: Venom Virtual Machine Escape Bug</a><br>
<a href="https://blog.tidelift.com/finding-5-more-than-half-of-maintainers-have-quit-or-considered-quitting-and-heres-why" rel="nofollow noopener">Tidelift Blog: More than Half of Maintainers Have Quit or Considered Quitting, and Here’s Why</a><br>
<a href="https://www.jaegertracing.io/" rel="nofollow noopener">Jaeger Tracing</a><br>
<a href="https://www.linux.com/news/measuring-the-health-of-open-source-communities" rel="nofollow noopener">Article: Measure the Health of Open Source Communities</a></p>

<p><a href="https://openssf.org" rel="nofollow noopener">Open Source Security Foundation (OpenSSF)</a><br>
<a href="https://www.zdnet.com/google-amp/article/google-releases-new-open-source-security-software-program-scorecards" rel="nofollow noopener">Article: Google Releases New Open Source Seucirty Software Program Scorecards</a><br>
<a href="https://github.com/ossf/scorecard" rel="nofollow noopener">GitHub: OSSF Scorecard</a><br>
<a href="https://insights.lfx.linuxfoundation.org/projects" rel="nofollow noopener">LFX Insights</a></p>

<p><a href="https://tidelift.com" rel="nofollow noopener">Tidelift</a><br>
<a href="https://opencollective.com" rel="nofollow noopener">Open Collective</a></p>

<h2>Chapters</h2>

<p>00:00  Intro<br>
00:42  Welcome<br>
01:14  Sponsor - Bitwarden<br>
02:40  Sponsor - Digital Ocean<br>
03:42  OSS Has Vulnerabilities<br>
07:45  Free means cheap<br>
14:53  Heartbleed Bug<br>
20:25  Open Source is Amature<br>
24:29  OpenSSF Scorecard<br>
33:07  Wrap Up</p><p>Sponsored By:</p><ul><li><a rel="nofollow" href="https://bitwarden.com/dln">Bitwarden</a></li><li><a rel="nofollow" href="https://do.co/dln-mongo">Digital Ocean</a>: <a rel="nofollow" href="https://do.co/dln-mongo">The Sudo Show is sponsored by our friends over at Digital Ocean. DigitalOcean recently announced their new Managed MongoDB service, which is a fully managed, database as a service.
With Managed MongoDB, you can focus more on building scalable high performance apps, and less on maintaining the database. DigitalOcean built this service in partnership with MongoDB Inc. and together they have ensured that you will get access to all the latest releases of the Mongo database as they become available.

As a listener of the Sudo Show podcast and a member of the DLN Community you can get started for FREE! Actually, better than free because DigitalOcean is giving you a $100 Credit when you go to <a href="https://do.co/dln-mongo" target="_blank" rel="nofollow noopener">https://do.co/dln-mongo</a>. Need more than just a database? You can use your $100 credit to try out all the amazing services Digital Ocean has to offer.
Again, go to <a href="https://do.co/dln-mongo" target="_blank" rel="nofollow noopener">https://do.co/dln-mongo</a> to get started with your $100 Free Credit on DigitalOcean’s new Managed MongoDB and thank you to Digital Ocean for sponsoring the Sudo Show and the entire Destination Linux Network!
</a></li></ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p>Eric and Brandon sit down and look into some of the biggest security myths around Open Source software and one by one debunk them right on the show!</p>

<p><a href="https://destinationlinux.network" rel="nofollow noopener">Destination Linux Network</a><br>
<a href="https://sudo.show" rel="nofollow noopener">Sudo Show Website</a><br>
<a href="https://bitwarden.com/dln" rel="nofollow noopener">Sponsor: Bitwarden</a><br>
<a href="https://do.co/dln-mongo" rel="nofollow noopener">Sponsor: Digital Ocean</a><br>
<a href="https://sudo.show/swag" rel="nofollow noopener">Sudo Show Swag</a></p>

<p>Contact Us:<br>
<a href="https://sudo.show/discuss" rel="nofollow noopener">DLN Discourse</a><br>
<a href="mailto:contact@sudo.show" rel="nofollow noopener">Email Us!</a><br>
<a href="https://sudo.show/matrix" rel="nofollow noopener">Sudo Matrix Room</a></p>

<p><a href="https://heartbleed.com" rel="nofollow noopener">Heartbleed</a><br>
<a href="https://nakedsecurity.sophos.com/2015/05/14/the-venom-virtual-machine-escape-bug-what-you-need-to-know" rel="nofollow noopener">Sophos: Venom Virtual Machine Escape Bug</a><br>
<a href="https://blog.tidelift.com/finding-5-more-than-half-of-maintainers-have-quit-or-considered-quitting-and-heres-why" rel="nofollow noopener">Tidelift Blog: More than Half of Maintainers Have Quit or Considered Quitting, and Here’s Why</a><br>
<a href="https://www.jaegertracing.io/" rel="nofollow noopener">Jaeger Tracing</a><br>
<a href="https://www.linux.com/news/measuring-the-health-of-open-source-communities" rel="nofollow noopener">Article: Measure the Health of Open Source Communities</a></p>

<p><a href="https://openssf.org" rel="nofollow noopener">Open Source Security Foundation (OpenSSF)</a><br>
<a href="https://www.zdnet.com/google-amp/article/google-releases-new-open-source-security-software-program-scorecards" rel="nofollow noopener">Article: Google Releases New Open Source Seucirty Software Program Scorecards</a><br>
<a href="https://github.com/ossf/scorecard" rel="nofollow noopener">GitHub: OSSF Scorecard</a><br>
<a href="https://insights.lfx.linuxfoundation.org/projects" rel="nofollow noopener">LFX Insights</a></p>

<p><a href="https://tidelift.com" rel="nofollow noopener">Tidelift</a><br>
<a href="https://opencollective.com" rel="nofollow noopener">Open Collective</a></p>

<h2>Chapters</h2>

<p>00:00  Intro<br>
00:42  Welcome<br>
01:14  Sponsor - Bitwarden<br>
02:40  Sponsor - Digital Ocean<br>
03:42  OSS Has Vulnerabilities<br>
07:45  Free means cheap<br>
14:53  Heartbleed Bug<br>
20:25  Open Source is Amature<br>
24:29  OpenSSF Scorecard<br>
33:07  Wrap Up</p><p>Sponsored By:</p><ul><li><a rel="nofollow" href="https://bitwarden.com/dln">Bitwarden</a></li><li><a rel="nofollow" href="https://do.co/dln-mongo">Digital Ocean</a>: <a rel="nofollow" href="https://do.co/dln-mongo">The Sudo Show is sponsored by our friends over at Digital Ocean. DigitalOcean recently announced their new Managed MongoDB service, which is a fully managed, database as a service.
With Managed MongoDB, you can focus more on building scalable high performance apps, and less on maintaining the database. DigitalOcean built this service in partnership with MongoDB Inc. and together they have ensured that you will get access to all the latest releases of the Mongo database as they become available.

As a listener of the Sudo Show podcast and a member of the DLN Community you can get started for FREE! Actually, better than free because DigitalOcean is giving you a $100 Credit when you go to <a href="https://do.co/dln-mongo" target="_blank" rel="nofollow noopener">https://do.co/dln-mongo</a>. Need more than just a database? You can use your $100 credit to try out all the amazing services Digital Ocean has to offer.
Again, go to <a href="https://do.co/dln-mongo" target="_blank" rel="nofollow noopener">https://do.co/dln-mongo</a> to get started with your $100 Free Credit on DigitalOcean’s new Managed MongoDB and thank you to Digital Ocean for sponsoring the Sudo Show and the entire Destination Linux Network!
</a></li></ul>]]>
  </itunes:summary>
</item>
  </channel>
</rss>
