|
|
|
|
|
by artjomb
1118 days ago
|
|
Exactly, as a user you need to be aware of this addition of risk. Anonymous OSS maintainers are the issue here. When I want to use a project and want to reduce the risk here, I need to vet the maintainers in a similar way I would vet a company I want to invest in. |
|
There are plenty of pieces of open source software running on operating systems that were contributed by people who are effectively anonymous.
Also, it doesn't seem like a contributor's overall character would be a great measure of how malicious their contriubtions are, as evidenced by plenty of examples of assumed good people eventually doing bad things.