3 ms·
I think people should take a step back here, and meditate a bit on what "disclaimer of warranty" means. All of the popular open source licenses, GPL, MIT and B
by PreInternet01 2y ago
I think people should take a step back here, and meditate a bit on what "disclaimer of warranty" means.
All of the popular open source licenses, GPL, MIT and BSD, quite plainly state that, to the extent permissible by law, there is no warranty about anything, whatsoever.
There was a time when Linux users (in general) understood this. You want free? You pick any distribution you like. You want a warranty? You pick RedHat.
But over time, it seems we've gotten to a point where "I imported your package, so that means you're obliged not to break my precious CI" has somehow become the norm.
This is bad for open source, and, frankly, bad for everyone, and I think it's high time that people start taking responsibility for their dependencies, either by paying for support, or by maintaining their own bugfix branches...
- m3047 2y agoCI pipelines are worse than that. When a CI pipeline flags a vuln in a dependency it typically goes to the dev couched as a "defect" they need to remedy as part of their unrelated PR. Left entirely out of the consciousness horizon is the realization that the code is almost certainly <<running in production right now>>. Where is the check that it hasn't been exploited, or concerning what the attack surface is in the product (or even if continuing to embrace the dependency is worth the hassle)? Where is SecOps?