3 ms·
> We should treat things like operating systems do: have collaborative security assessments for each package BEFORE it is published. This would not work for sm
by serial_dev 4y ago
> We should treat things like operating systems do: have collaborative security assessments for each package BEFORE it is published.
This would not work for small open source projects, and every successful open source project starts out as a small project that nobody vetted yet.
I have smaller, but popular open source packages that I know are used by many people,and most of those projects (even now, after a year being public) get zero actual contributions. If my most popular packages don't receive pull requests, how would I find a trustworthy expert committee to judge all my other silly little packages for free?
Also, why would I make the projects I work for fun and for free purposefully a painful, sluggish, bureaucratic experience for everyone involved?
- EGreg 4y agoIt's a matter of scale, as I said :) At some point, projects have to bring in more "adult supervision"