Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

So what is Google gonna do if security fixes don't happen in time and the project takes a "reputational hit"? Fork it and maintain it themselves? Why not send in patches instead?

Maintaining a reputation might be enough reward for you, but not everyone is happy to work for free for a billion dollars corporation breathing down their necks. It's puzzling to me why people keep defending their free lunch.



If ffmpeg maintainers cannot keep up, downstream customers should know so they can help.


FFmpeg is developed almost entirely by volunteers. We have no "customers".


There are people who use and depend on ffmpeg. Maintainers seem to go out of their way to solve issues these folks face. If you don't care, then ignore the bug reports and force them to solve their own problems by contributing.


These people are not customers though. The maintainers do their best, but overall the project seems to be understaffed though, so customers (for example Google, as it seems they occasionally chip in) get priority.


Then you and your security friends will create lots of FUD about FFmpeg being "insecure" with lots of red and the word "critical" everywhere.


Why complain about pressure from customers then?




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: