It would probably be better to use a survey of vulnerabilities plus Heartbleed instead of just repeating Heartbleed. It can be dismissed as an outlier: "That's just one project everyone was freeloading on." I know, it's a security-critical project that should've gotten many eyeballs. I just prefer to show how pervasive the problem is when debunking this stuff.
The other thing I noted on a Heartbleed-related thread was that FOSS never produced high-assurance security despite its labor advantage. Proprietary sector, either industry or CompSci teams, beat them about every time.
https://www.schneier.com/blog/archives/2014/04/reverse_heart...
I elaborate more in replies to DB. It comes down to them not caring enough to apply the level of QA necessary. You have to pay people to do that. You also have to find the right people that can do it since even the knowledge of it isn't widespread. They'll know 100 frameworks and such but not the basic activities for assurance past unit/acceptance testing and review. They'll probably have never heard of Ada/SPARK or SPIN when they tell you about Rust. So on and so forth.
Raymond's claim is utter bullshit. If you want best security, you're better off buying a 3rd-party-evaluated product from high-assurance proprietary. If you want good security that's cheap, it's a small number of proprietary and FOSS projects whose stakeholders put time in for thorough review and analysis. The rest is shit waiting to happen or (looks at CVE list) happening all the time.