Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

To be clear, I think Google (Apple, Microsoft, etc.) can and should fund more of the OSS they depend on. But this doesn’t change the fact that vulnerability reports don’t create work per se, they just reveal work that the project can choose to act on or not.


Hopefully, until that changes, more people with influence will keep saying it, and always say it until it stops being true, and important.

So thank you for saying the important thing too! :)




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: