5 ms·
> They sell insurance against the maintainer, when the maintainer is the one person in the chain who can actually make the code more secure, and she gets nothin
by jongjong 13d ago
> They sell insurance against the maintainer, when the maintainer is the one person in the chain who can actually make the code more secure, and she gets nothing while a company two layers up gets paid to tell you whether she did.
Damn, this is a really good line. It's the reason why existing tools like Snyk give so many false positives and miss so many actual vulnerabilities. They're kind of useless really.
They create false comfort and busy-work for staff whilst providing a ready-made "Snyk said it was secure" narrative to cover everyone's asses when things inevitably go belly-up.
And Snyk be like "We responded as fast as possible, so we fulfilled our part" yet what really counts is not even in the equation.
Personally, I stopped contributing my code open source. I still write it and I've built a major project I'd love to make public but I'm keeping it for myself. I'm waiting for communism or UBI to arrive, then I may resume publishing as open source.
If it takes too long, I will pass it down to my son and he will wait until communism arrives to make it public.