<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" encoding="UTF-8" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" xmlns:admin="http://webns.net/mvcb/" xmlns:atom="http://www.w3.org/2005/Atom/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:googleplay="http://www.google.com/schemas/play-podcasts/1.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:fireside="http://fireside.fm/modules/rss/fireside">
  <channel>
    <fireside:hostname>web01.fireside.fm</fireside:hostname>
    <fireside:genDate>Sat, 18 Apr 2026 16:46:08 -0500</fireside:genDate>
    <generator>Fireside (https://fireside.fm)</generator>
    <title>Linux Action News - Episodes Tagged with “Openssf”</title>
    <link>https://linuxactionnews.com/tags/openssf</link>
    <pubDate>Thu, 05 Jan 2023 08:15:00 -0800</pubDate>
    <description>Weekly Linux news and analysis by Chris and Wes. The show every week we hope you'll go to when you want to hear an informed discussion about what’s happening.
</description>
    <language>en-us</language>
    <itunes:type>episodic</itunes:type>
    <itunes:subtitle>Our weekly take on the free and open source world.</itunes:subtitle>
    <itunes:author>Jupiter Broadcasting</itunes:author>
    <itunes:summary>Weekly Linux news and analysis by Chris and Wes. The show every week we hope you'll go to when you want to hear an informed discussion about what’s happening.
</itunes:summary>
    <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/d/dec90738-e640-45e5-b375-4573052f4bf4/cover.jpg?v=6"/>
    <itunes:explicit>no</itunes:explicit>
    <itunes:owner>
      <itunes:name>Jupiter Broadcasting</itunes:name>
      <itunes:email>chris@jupiterbroadcasting.com</itunes:email>
    </itunes:owner>
<itunes:category text="Technology"/>
<itunes:category text="News">
  <itunes:category text="Tech News"/>
</itunes:category>
<item>
  <title>Linux Action News 274</title>
  <link>https://linuxactionnews.com/274</link>
  <guid isPermaLink="false">265a70d2-c9ab-4dc8-8aea-e83fa23860f3</guid>
  <pubDate>Thu, 05 Jan 2023 08:15:00 -0800</pubDate>
  <author>Jupiter Broadcasting</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/dec90738-e640-45e5-b375-4573052f4bf4/265a70d2-c9ab-4dc8-8aea-e83fa23860f3.mp3" length="14308071" type="audio/mp3"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>Jupiter Broadcasting</itunes:author>
  <itunes:subtitle>Android is getting RISC-Y, the handy new Google tool going open source, the next nail in the coffin for ZFS on Ubuntu, and why you were right about smart speakers all along.</itunes:subtitle>
  <itunes:duration>17:01</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/d/dec90738-e640-45e5-b375-4573052f4bf4/cover.jpg?v=6"/>
  <description>Android is getting RISC-Y, the handy new Google tool going open source, the next nail in the coffin for ZFS on Ubuntu, and why you were right about smart speakers all along. 
</description>
  <itunes:keywords>Linux News Podcast, Linux Action News, Google, Android, RISC-V, Arm, Linux, tooling, 64-bit, Apache Licensed, open source vulnerability database, OpenSSF, OSV format, commit hashes, dependencies, manifests, software bill of materials (SBOMs), Rust, Javascript, PHP, Ruby, Go, Elixir, Python, Flutter, Java, Gradle, Debian packages, docker container, OpensSSF Scorecard, vulnerability prevention, OSV-Scanner, OpenSSF Scorecard's Vulnerabilities check, OSV project, OSV schema, vulnerability databases, OSV database, supply chain practices, open-source projects,Ubuntu, installer, Lunar Lobster, UI, ZFS, Btrfs, Subiquity, Flutter, darktheme, lighttheme, HDR, Linux, SteamPlay, gamescope, Valve, RedHat, Nvidia, Collabora, GNOME, Mutter, VKD3D-Proton, Linode, Kolide, Google Home, bug, Matt Kunze, smartspeaker, IoT, smart home,  backdoor, mic, vulnerability</itunes:keywords>
  <content:encoded>
    <![CDATA[<p>Android is getting RISC-Y, the handy new Google tool going open source, the next nail in the coffin for ZFS on Ubuntu, and why you were right about smart speakers all along.</p><p>Sponsored By:</p><ul><li><a rel="nofollow" href="https://l.kolide.co/3klbWzr">Kolide</a>: <a rel="nofollow" href="https://l.kolide.co/3klbWzr">Kolide can help you nail third-party audits and internal compliance goals with endpoint security for your entire fleet. </a></li><li><a rel="nofollow" href="http://linode.com/lan">Linode</a>: <a rel="nofollow" href="http://linode.com/lan">Sign up using the link on this page and receive a $100 60-day credit towards your new account. </a></li></ul><p><a rel="payment" href="https://www.jupiter.party/">Support Linux Action News</a></p><p>Links:</p><ul><li><a title="Android Gets RISC-Y" rel="nofollow" href="https://arstechnica.com/gadgets/2023/01/google-announces-official-android-support-for-risc-v/">Android Gets RISC-Y</a> &mdash; Google's keynote at the RISC-V Summit promises official, polished support. </li><li><a title="Keynote: The Android Open Source Project and RISC-V - Lars Bergstrom, Google Director of Engineering" rel="nofollow" href="https://www.youtube.com/watch?v=70O_RmTWP58">Keynote: The Android Open Source Project and RISC-V - Lars Bergstrom, Google Director of Engineering</a></li><li><a title="New Google Tool Goes Open" rel="nofollow" href="https://www.infoq.com/news/2022/12/google-osv-scanner/">New Google Tool Goes Open</a> &mdash; The OSV database is a distributed, open-source database that stores vulnerability information in the OSV format. The OSV-Scanner assesses a project's dependencies against the OSV database showing all vulnerabilities relating to the project.</li><li><a title="Ubuntu’s New Installer Milestone" rel="nofollow" href="https://www.phoronix.com/news/Ubuntu-23.04-New-Installer-Jan">Ubuntu’s New Installer Milestone</a> &mdash; With Ubuntu 23.04 "Lunar Lobster" in April that new desktop installer is poised to finally be used by default. </li><li><a title="HDR Beginning To Work For Linux Gaming" rel="nofollow" href="https://www.phoronix.com/news/Valve-HDR-Linux-Gaming-Begins">HDR Beginning To Work For Linux Gaming</a> &mdash; "New Linux gaming milestone: with the latest work from Josh Ashton, HDR can now be enabled for real games! Tested it tonight on my AMD desktop with Halo Infinite, Deep Rock Galactic, DEATH STRANDING DC. Very early and will still need some time to bake to be useful to most."</li><li><a title="Red Hat Planning HDR Hackfest" rel="nofollow" href="https://wiki.gnome.org/Hackfests/ShellDisplayNext2023">Red Hat Planning HDR Hackfest</a></li><li><a title="GNOME Shell + Mutter 43 Alpha Released" rel="nofollow" href="https://www.phoronix.com/news/GNOME-Shell-Mutter-43-Alpha">GNOME Shell + Mutter 43 Alpha Released</a></li><li><a title="VKD3D-Proton 2.7 Released With Eight Months Worth Of Changes" rel="nofollow" href="https://www.phoronix.com/news/VKD3D-Proton-2.7-Released">VKD3D-Proton 2.7 Released With Eight Months Worth Of Changes</a></li><li><a title="Google Home speakers allowed hackers to snoop on conversations" rel="nofollow" href="https://www.bleepingcomputer.com/news/security/google-home-speakers-allowed-hackers-to-snoop-on-conversations/">Google Home speakers allowed hackers to snoop on conversations</a> &mdash; A bug in Google Home smart speaker allowed installing a backdoor account that could be used to control it remotely and to turn it into a snooping device by accessing the microphone feed.</li></ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p>Android is getting RISC-Y, the handy new Google tool going open source, the next nail in the coffin for ZFS on Ubuntu, and why you were right about smart speakers all along.</p><p>Sponsored By:</p><ul><li><a rel="nofollow" href="https://l.kolide.co/3klbWzr">Kolide</a>: <a rel="nofollow" href="https://l.kolide.co/3klbWzr">Kolide can help you nail third-party audits and internal compliance goals with endpoint security for your entire fleet. </a></li><li><a rel="nofollow" href="http://linode.com/lan">Linode</a>: <a rel="nofollow" href="http://linode.com/lan">Sign up using the link on this page and receive a $100 60-day credit towards your new account. </a></li></ul><p><a rel="payment" href="https://www.jupiter.party/">Support Linux Action News</a></p><p>Links:</p><ul><li><a title="Android Gets RISC-Y" rel="nofollow" href="https://arstechnica.com/gadgets/2023/01/google-announces-official-android-support-for-risc-v/">Android Gets RISC-Y</a> &mdash; Google's keynote at the RISC-V Summit promises official, polished support. </li><li><a title="Keynote: The Android Open Source Project and RISC-V - Lars Bergstrom, Google Director of Engineering" rel="nofollow" href="https://www.youtube.com/watch?v=70O_RmTWP58">Keynote: The Android Open Source Project and RISC-V - Lars Bergstrom, Google Director of Engineering</a></li><li><a title="New Google Tool Goes Open" rel="nofollow" href="https://www.infoq.com/news/2022/12/google-osv-scanner/">New Google Tool Goes Open</a> &mdash; The OSV database is a distributed, open-source database that stores vulnerability information in the OSV format. The OSV-Scanner assesses a project's dependencies against the OSV database showing all vulnerabilities relating to the project.</li><li><a title="Ubuntu’s New Installer Milestone" rel="nofollow" href="https://www.phoronix.com/news/Ubuntu-23.04-New-Installer-Jan">Ubuntu’s New Installer Milestone</a> &mdash; With Ubuntu 23.04 "Lunar Lobster" in April that new desktop installer is poised to finally be used by default. </li><li><a title="HDR Beginning To Work For Linux Gaming" rel="nofollow" href="https://www.phoronix.com/news/Valve-HDR-Linux-Gaming-Begins">HDR Beginning To Work For Linux Gaming</a> &mdash; "New Linux gaming milestone: with the latest work from Josh Ashton, HDR can now be enabled for real games! Tested it tonight on my AMD desktop with Halo Infinite, Deep Rock Galactic, DEATH STRANDING DC. Very early and will still need some time to bake to be useful to most."</li><li><a title="Red Hat Planning HDR Hackfest" rel="nofollow" href="https://wiki.gnome.org/Hackfests/ShellDisplayNext2023">Red Hat Planning HDR Hackfest</a></li><li><a title="GNOME Shell + Mutter 43 Alpha Released" rel="nofollow" href="https://www.phoronix.com/news/GNOME-Shell-Mutter-43-Alpha">GNOME Shell + Mutter 43 Alpha Released</a></li><li><a title="VKD3D-Proton 2.7 Released With Eight Months Worth Of Changes" rel="nofollow" href="https://www.phoronix.com/news/VKD3D-Proton-2.7-Released">VKD3D-Proton 2.7 Released With Eight Months Worth Of Changes</a></li><li><a title="Google Home speakers allowed hackers to snoop on conversations" rel="nofollow" href="https://www.bleepingcomputer.com/news/security/google-home-speakers-allowed-hackers-to-snoop-on-conversations/">Google Home speakers allowed hackers to snoop on conversations</a> &mdash; A bug in Google Home smart speaker allowed installing a backdoor account that could be used to control it remotely and to turn it into a snooping device by accessing the microphone feed.</li></ul>]]>
  </itunes:summary>
</item>
<item>
  <title>Linux Action News 241</title>
  <link>https://linuxactionnews.com/241</link>
  <guid isPermaLink="false">0e5fc28b-b096-4813-be6d-394a14feb81d</guid>
  <pubDate>Thu, 19 May 2022 11:30:00 -0700</pubDate>
  <author>Jupiter Broadcasting</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/dec90738-e640-45e5-b375-4573052f4bf4/0e5fc28b-b096-4813-be6d-394a14feb81d.mp3" length="17829534" type="audio/mp3"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>Jupiter Broadcasting</itunes:author>
  <itunes:subtitle>Why Google's new open-source security effort might fall a bit short, the Arch snag this week, a big win for Right to Repair, and why you might soon have a new favorite filesystem.</itunes:subtitle>
  <itunes:duration>21:13</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/d/dec90738-e640-45e5-b375-4573052f4bf4/cover.jpg?v=6"/>
  <description>Why Google's new open-source security effort might fall a bit short, the Arch snag this week, a big win for Right to Repair, and why you might soon have a new favorite filesystem. 
</description>
  <itunes:keywords>Linux News Podcast, Linux Action News, Google, Google Cloud, Assured Open Source, fuzzing, oss-fuzz, OpenSSF, Software Freedom Conservancy, SFC, Vizio, GPL, copyright, copyleft, right to repair, Arch Linux, audio, PipeWire, WirePlumber, ALSA, PulseAudio, </itunes:keywords>
  <content:encoded>
    <![CDATA[<p>Why Google&#39;s new open-source security effort might fall a bit short, the Arch snag this week, a big win for Right to Repair, and why you might soon have a new favorite filesystem.</p><p>Sponsored By:</p><ul><li><a rel="nofollow" href="http://linode.com/lan">Linode</a>: <a rel="nofollow" href="http://linode.com/lan">Sign up using the link on this page and receive a $100 60-day credit towards your new account. </a></li><li><a rel="nofollow" href="https://linux.ting.com">Ting</a>: <a rel="nofollow" href="https://linux.ting.com">Save $25 off your first device, or $25 in service credit if you bring one!</a></li></ul><p><a rel="payment" href="https://www.jupiter.party/">Support Linux Action News</a></p><p>Links:</p><ul><li><a title="New from Google Cloud: Assured Open Source Software service" rel="nofollow" href="https://cloud.google.com/blog/products/identity-security/introducing-assured-open-source-software-service">New from Google Cloud: Assured Open Source Software service</a> &mdash; Assured OSS enables enterprise and public sector users of open source software to easily incorporate the same OSS packages that Google uses into their own developer workflows.</li><li><a title="OSS-Fuzz" rel="nofollow" href="https://github.com/google/oss-fuzz">OSS-Fuzz</a> &mdash; continuous fuzzing for open source software.</li><li><a title="Google will start distributing a security-vetted collection of open-source software libraries" rel="nofollow" href="https://www.theverge.com/2022/5/17/23097529/google-assured-open-source-software-security-vetted-libraries">Google will start distributing a security-vetted collection of open-source software libraries</a></li><li><a title="Shared success in building a safer open source community" rel="nofollow" href="https://blog.google/technology/safety-security/shared-success-in-building-a-safer-open-source-community/">Shared success in building a safer open source community</a></li><li><a title="White House joins OpenSSF and the Linux Foundation in securing open-source software" rel="nofollow" href="https://www.zdnet.com/article/white-house-joins-openssf-and-the-linux-foundation-in-securing-open-source-software/">White House joins OpenSSF and the Linux Foundation in securing open-source software</a></li><li><a title="Software Freedom Conservancy right-to-repair lawsuit against California TV manufacturer Vizio, Inc. remanded to California State Court - Software Freedom Conservancy" rel="nofollow" href="https://sfconservancy.org/news/2022/may/16/vizio-remand-win/">Software Freedom Conservancy right-to-repair lawsuit against California TV manufacturer Vizio, Inc. remanded to California State Court - Software Freedom Conservancy</a> &mdash; "The ruling is a watershed moment in the history of copyleft licensing. This ruling shows that the GPL agreements function both as copyright licenses and as contractual agreements" says Karen M. Sandler, executive director of Software Freedom Conservancy.</li><li><a title="Arch Linux Temporarily Steps Back From WirePlumber After Snafu" rel="nofollow" href="https://www.phoronix.com/scan.php?page=news_item&amp;px=Arch-Linux-WirePlumber-Snafu">Arch Linux Temporarily Steps Back From WirePlumber After Snafu</a> &mdash; With the recent attempt to switch to WirePlumber, that modern session manager was unconditionally taking over audio responsibilities even if the user had configured their system to use PulseAudio or ALSA directly.</li><li><a title="Arch Linux News" rel="nofollow" href="https://archlinux.org/news/undone-replacement-of-pipewire-media-session-with-wireplumber/">Arch Linux News</a> &mdash; Undone replacement of pipewire-media-session with wireplumber.</li><li><a title="Bringing bcachefs to the mainline" rel="nofollow" href="https://lwn.net/Articles/895266/">Bringing bcachefs to the mainline</a> &mdash; Bcachefs is a longstanding out-of-tree filesystem that grew out of the bcache caching layer that has been in the kernel for nearly ten years. Based on a session led by Kent Overstreet at the 2022 Linux Storage, Filesystem, Memory-management and BPF Summit (LSFMM), though, it would seem that bcachefs is likely to be heading upstream soon. He intends to start the process toward mainline inclusion over the next six months or so.</li><li><a title="bcachefs Principles of Operation" rel="nofollow" href="https://bcachefs.org/bcachefs-principles-of-operation.pdf">bcachefs Principles of Operation</a></li></ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p>Why Google&#39;s new open-source security effort might fall a bit short, the Arch snag this week, a big win for Right to Repair, and why you might soon have a new favorite filesystem.</p><p>Sponsored By:</p><ul><li><a rel="nofollow" href="http://linode.com/lan">Linode</a>: <a rel="nofollow" href="http://linode.com/lan">Sign up using the link on this page and receive a $100 60-day credit towards your new account. </a></li><li><a rel="nofollow" href="https://linux.ting.com">Ting</a>: <a rel="nofollow" href="https://linux.ting.com">Save $25 off your first device, or $25 in service credit if you bring one!</a></li></ul><p><a rel="payment" href="https://www.jupiter.party/">Support Linux Action News</a></p><p>Links:</p><ul><li><a title="New from Google Cloud: Assured Open Source Software service" rel="nofollow" href="https://cloud.google.com/blog/products/identity-security/introducing-assured-open-source-software-service">New from Google Cloud: Assured Open Source Software service</a> &mdash; Assured OSS enables enterprise and public sector users of open source software to easily incorporate the same OSS packages that Google uses into their own developer workflows.</li><li><a title="OSS-Fuzz" rel="nofollow" href="https://github.com/google/oss-fuzz">OSS-Fuzz</a> &mdash; continuous fuzzing for open source software.</li><li><a title="Google will start distributing a security-vetted collection of open-source software libraries" rel="nofollow" href="https://www.theverge.com/2022/5/17/23097529/google-assured-open-source-software-security-vetted-libraries">Google will start distributing a security-vetted collection of open-source software libraries</a></li><li><a title="Shared success in building a safer open source community" rel="nofollow" href="https://blog.google/technology/safety-security/shared-success-in-building-a-safer-open-source-community/">Shared success in building a safer open source community</a></li><li><a title="White House joins OpenSSF and the Linux Foundation in securing open-source software" rel="nofollow" href="https://www.zdnet.com/article/white-house-joins-openssf-and-the-linux-foundation-in-securing-open-source-software/">White House joins OpenSSF and the Linux Foundation in securing open-source software</a></li><li><a title="Software Freedom Conservancy right-to-repair lawsuit against California TV manufacturer Vizio, Inc. remanded to California State Court - Software Freedom Conservancy" rel="nofollow" href="https://sfconservancy.org/news/2022/may/16/vizio-remand-win/">Software Freedom Conservancy right-to-repair lawsuit against California TV manufacturer Vizio, Inc. remanded to California State Court - Software Freedom Conservancy</a> &mdash; "The ruling is a watershed moment in the history of copyleft licensing. This ruling shows that the GPL agreements function both as copyright licenses and as contractual agreements" says Karen M. Sandler, executive director of Software Freedom Conservancy.</li><li><a title="Arch Linux Temporarily Steps Back From WirePlumber After Snafu" rel="nofollow" href="https://www.phoronix.com/scan.php?page=news_item&amp;px=Arch-Linux-WirePlumber-Snafu">Arch Linux Temporarily Steps Back From WirePlumber After Snafu</a> &mdash; With the recent attempt to switch to WirePlumber, that modern session manager was unconditionally taking over audio responsibilities even if the user had configured their system to use PulseAudio or ALSA directly.</li><li><a title="Arch Linux News" rel="nofollow" href="https://archlinux.org/news/undone-replacement-of-pipewire-media-session-with-wireplumber/">Arch Linux News</a> &mdash; Undone replacement of pipewire-media-session with wireplumber.</li><li><a title="Bringing bcachefs to the mainline" rel="nofollow" href="https://lwn.net/Articles/895266/">Bringing bcachefs to the mainline</a> &mdash; Bcachefs is a longstanding out-of-tree filesystem that grew out of the bcache caching layer that has been in the kernel for nearly ten years. Based on a session led by Kent Overstreet at the 2022 Linux Storage, Filesystem, Memory-management and BPF Summit (LSFMM), though, it would seem that bcachefs is likely to be heading upstream soon. He intends to start the process toward mainline inclusion over the next six months or so.</li><li><a title="bcachefs Principles of Operation" rel="nofollow" href="https://bcachefs.org/bcachefs-principles-of-operation.pdf">bcachefs Principles of Operation</a></li></ul>]]>
  </itunes:summary>
</item>
  </channel>
</rss>
