4 ms·
It is interesting seeing the evolution of open source maintenance in the light of new (or increasing) supply chain attacks and acts of political protest. There
by ctur 4y ago
It is interesting seeing the evolution of open source maintenance in the light of new (or increasing) supply chain attacks and acts of political protest. There always has been a "what is your obligation to quickly respond to a security issue?" expectation around the code and now similar obligatory expectation questions arise on the maintenance process itself.
We also see what seems like rather balkanized approaches (npm, pypi, cargo, ...). It would be great if broader consensus arose on what the ideal standard should be for package management and distribution that then those projects could adhere to. Similar about commit access to repos and what the requirements there should be.
It's also peculiar how much stronger the guarantees you get from your operating system vendor are w.r.t. signatures on packages vs what the underlying projects themselves have. OSs have had this pretty well handled for decades, but no common best practices like 2fa, signatures, etc seem to have emerged.
- mistrial9 4y agobut then you get self-appointed guys, it seems near finance centers, auto-vacuuming up huge sets of OSS and re-selling it with security assurances. MSFT sells a copy of The Github itself to those with enough money and connections, as I understand, likely via the 60+ countries with MSFT datacenters now
- nicoburns 4y ago> auto-vacuuming up huge sets of OSS and re-selling it with security assurances Seems like something like this, but which employed/funded the maintainers might be ideal.
- jjoonathan 4y agoRedhat?
- wmf 4y agoYeah, basically the Red Hat model but with native language packages instead of RPMs.
- ChrisMarshallNY 4y agoReselling free services is a time-honored business model (hundreds of years old, probably). It seems a bit “dodgy,” but lots of people are willing to pay for it.
- bregma 4y agoI believe the word is "pimping".