Hacker News new | ask | show | jobs
by plange 3345 days ago
Sorry, i wasn't trying to imply they shifted blame. But atlassian does bare the legal&moral burden of securing their product here.
1 comments

I agree with you. I don't agree that they have a moral obligation to make pull requests to the open source library that had the issue. Hopefully they will, but there is no obligation there in my mind.