3 ms·
Other projects get unmaintained with maintainers burnt out by a torrent of vulberability reports
by yread 2mo ago
Other projects get unmaintained with maintainers burnt out by a torrent of vulberability reports
- fsloth 2mo agoThis I don't understand. If it's not your job, then just ignore the reports. If it's actually critical, someone will put money on the table and then it's a business. And then it's about scheduling and resourcing - also should not burn anyone out. Just because many people have false sense of entitlement as soon as they get a free offering, it does not mean anyone needs to accommodate them.
- okeuro49 2mo ago> If it's not your job, then just ignore the reports. If you have a highly conscientious personality, this is easier said than done.
- pdimitar 2mo agoIt's also a great opportunity for character development. Use it for that, and not for trying to overbook yourself to 300%. You don't owe the world anything at all. If you're conscientious, then give a little -- here and there. Don't turn it into an unpaid job.
- fsloth 2mo ago" highly conscientious " Just doing what others wish is not conscientous in itself! It _may_ be depdending on situation but it can be just pathological towards the self. When it's psyhocologically hard to do things you imagine will dissapoint someone that's probably not concientousness. It's more like low self-esteem or codependency. It's very hard for someone to tell these apart themselves. Hence when this topic pops out it's good idea to remind that being super-accomodating may in fact be a personality flaw - that can be healed if acknowledged. There is very large spectrum between "trying not to dissapoint anyone" and doing what you know is the right thing.
- vincnetas 2mo agoNot everyone acts rationally even when knowing that they act irrationally.
- pdimitar 2mo agoSounds like their problem, not something a SaaS product should dance around. Yet they kind of did. I've limited participation in my libraries with GitHub's setting that nobody who made an account in the last 6 months can do anything in my repos (after some misguided hustler thought they're an easy target and posted an ad).lp Time's marching forward though. Wonder what will happen after a few more months. We'll have bot spam accounts that are no longer as fresh.
- centuryfall 2mo agohttps://xkcd.com/2347/ https://xkcd.com/2347/ A great majority of business applications do run on open source projects, and in turn, are affected by them if things go awry. It’s a prisoner’s dilemma in this case.
- _zoltan_ 2mo agousual crying from the usual people. AI slop, blahblahb, ... (I don't mean you. just these so called open source developers.)
- yread 2mo agoI'm not sure if it's going to persuade you but here is an example: https://github.com/uclouvain/openjpeg https://github.com/uclouvain/openjpeg Basically the only library for reading jp2k data (complicated specs, ask your AI to one shot an implementation, mine said "it's 3000 lines of fiddly spec, too complicated"). Issues full of buffer-overflows. Recently unmaintained. Used in tons of projects, now all possibly vulnerable.
- _zoltan_ 2mo agoand? don't use it. switch. abandon. did we lose anything of value? probably not.