# josh kurt (audio feeds) — RSS Amplifier

Recent posts from the 1 feeds in the RSS Amplifier directory that cover josh kurt.

Page: <https://rssamplifier.com/topics/josh-kurt/audio>  
Feed: <https://rssamplifier.com/topics/josh-kurt/audio.md>

---

## [Maintaining EOL Open Source with Commonhaus and HeroDevs](https://opensourcesecuritypodcast.libsyn.com/maintaining-eol-open-source-with-commonhaus-and-herodevs)

_2026-08-17 · Open Source Security_

Josh chats with Erin Schnabel and Rob Nalen about a new effort from Commonhaus and HeroDevs for maintaining end of life open source. This project, the Open Source Sustainability Initiative is a clever way to bring corporations and projects together for maintenance of new and old versions of open source projects. This is pretty new territory for everyone, this project is worth keeping an eye on…

[Listen](https://traffic.libsyn.com/secure/opensourcesecuritypodcast/2026-08-commonhaus-herodevs.mp3?dest-id=542864)

## [Cleanup, Speedup, Levelup open source at e18e](https://opensourcesecuritypodcast.libsyn.com/cleanup-speedup-levelup-open-source-at-e181)

_2026-08-10 · Open Source Security_

Josh chats with James from e18e. This is a project that is working on improving Javascript packages by cleaning up, speeding up, and leveling up the dependencies. The way the e18e project handles this work is very human open source. It's all about building up connections and trust with the package communities, which is no small effort. James fills us in on what they're doing as well as how we can…

[Listen](https://traffic.libsyn.com/secure/opensourcesecuritypodcast/2026-08-e18e-james.mp3?dest-id=542864)

## [VulnCheck's State of Exploitation Report with Patrick Garrity](https://opensourcesecuritypodcast.libsyn.com/vulnchecks-state-of-exploitation-report-with-patrick-garrity)

_2026-08-03 · Open Source Security_

Josh chats with Patrick Garrity about the VulnCheck State of Exploitation 1H-2026 report. Patrick explains the current trends we are seeing around vulnerabilities right now. While the number of CVEs is way up, the number of actually exploited vulnerabilities isn't growing year over year. This tells us there is a lot of FUD and hype. We also ask where are all the vulnerabilities that project…

[Listen](https://traffic.libsyn.com/secure/opensourcesecuritypodcast/2026-08-vulncheck-state-of-exploitation.mp3?dest-id=542864)

## [Securing critical infrastructure with Josh Corman](https://opensourcesecuritypodcast.libsyn.com/securing-critical-infrastructure-with-josh-corman)

_2026-07-27 · Open Source Security_

Open Source Security welcomes Josh Corman to talk about the challenges around securing our critical infrastructure. Specifically the discussion centers around our water supplies. There are a lot of really wild things happening right now with attacks like Volt Typhoon and Salt Typhoon. Josh has an amazing ability to make these sort of discussions easy to understand without spreading FUD. Josh also…

[Listen](https://traffic.libsyn.com/secure/opensourcesecuritypodcast/2026-07-critical-infrastructure-josh-corman.mp3?dest-id=542864)

## [Abandoned open source with Josh Marpet](https://opensourcesecuritypodcast.libsyn.com/abandoned-open-source-with-josh-marpet)

_2026-07-20 · Open Source Security_

Josh welcomes Josh Marpet for a discussion about abandoned open source packages. Josh Marpet has a foundation called Value Chain Risk Institute that has a report discussion how to start measuring if an open source package might be abandoned. There's a lot of data, but not a lot of groups using that data to help make informed decisions about using open source. VCRI is one of those places that's…

[Listen](https://traffic.libsyn.com/secure/opensourcesecuritypodcast/2026-07-VCRI-josh-marpet.mp3?dest-id=542864)

## [Red Hat's Project Lightwell with Mo Duffy](https://opensourcesecuritypodcast.libsyn.com/red-hats-project-lightwell-with-mo-duffy)

_2026-07-13 · Open Source Security_

Josh welcomes Mo Duffy from Red Hat to chat about project Lightwell. The idea is to leverage the resources and understanding Red Hat has built up over the years to help deal with the deluge of vulnerability reports that are overwhelming open source projects. Mo does a really good job of explaining why this is fundamentally a people problem, not a technology problem. But it's a people problem we…

[Listen](https://traffic.libsyn.com/secure/opensourcesecuritypodcast/2026-07-lightwell-mo-duffy.mp3?dest-id=542864)

## [Rust Foundation Maintainers Fund with Lori and Niko](https://opensourcesecuritypodcast.libsyn.com/rust-foundation-maintainers-fund-with-lori-and-niko)

_2026-07-06 · Open Source Security_

Josh chats with Lori Lorusso and Niko Matsakis about the Rust Foundation Maintainers Fund. This is a new project the Rust Foundation has create to help fund Rust maintainers. It's a great discussion where Lori and Niko cover all the ways they expect to fund the maintainers which is never as easy as one initially expects. Funding open source is a huge topic right now, it sounds like the Rust…

[Listen](https://traffic.libsyn.com/secure/opensourcesecuritypodcast/2026-06-rfmf-lori-niko.mp3?dest-id=542864)

## [AIBOM, CBOM, and HBOM with Allan Friedman](https://opensourcesecuritypodcast.libsyn.com/aibom-cbom-and-hbom-with-allan-friedman)

_2026-06-29 · Open Source Security_

Josh chats with Allan Friedman about all things Bill of Materials. Allan did a ton of work to help turn SBOM into what it is today. He has many thoughts and ideas around the new types of BOMs, a concept he's calling the OmniBOM. Allan is always fun to chat with and he brings a ton of knowledge and advice. The show notes and blog post for this episode can be found at…

[Listen](https://traffic.libsyn.com/secure/opensourcesecuritypodcast/2026-06-allan-omnibom.mp3?dest-id=542864)

## [Packagist and Composer security with Jordi Boggiano](https://opensourcesecuritypodcast.libsyn.com/packagist-and-composer-security-with-jordi-boggiano)

_2026-06-22 · Open Source Security_

Josh welcomes Jordi Boggiano the lead maintainer of Composer and Packagist to explain the truckload of security features they've recently added. Packagist is the PHP package registry, Composer is the dependency manager for PHP. Recently the people behind these projects have added a number of security features that will improve the security of the entire ecosystem. Jordi explains it all to us and…

[Listen](https://traffic.libsyn.com/secure/opensourcesecuritypodcast/2026-06-packagist-security-jordi.mp3?dest-id=542864)

## [Collect Open Source Legends (Sponsored)](https://crawlproof.com/a/bPWIM02fFDyW)

_2026-06-21 · **Sponsored**_

Open-licensed art, limited foil trading packs, and optional on-chain mints.

## [Sustaining Open VSX with Mike and Thabang](https://opensourcesecuritypodcast.libsyn.com/sustaining-open-vsx-with-mike-and-thabang)

_2026-06-15 · Open Source Security_

Josh welcomes Mike Milinkovich and Thabang Mashologu from the Eclipse Foundation to talk about their new managed Open VSX registry. This is the first open source package registry to create a commercial operation for large company users to help fund the registry. We discuss how we got here, what's actually going on, and why this commercial approach is working. Everyone knew this day would come, and…

[Listen](https://traffic.libsyn.com/secure/opensourcesecuritypodcast/2026-06-openvsx-mike-thabang.mp3?dest-id=542864)

