|
|
|
|
|
by thayne
1067 days ago
|
|
> We can't have our most essential systems be vulnerable just because they are maintained by an unpaid dev in Nebraska I don't disagree with that. But I don't think saying that one dev in Nebraska has to pay for security audits, or at least convince companies who use their project to pay for it and take charge of coordinating that effort, is the right way to solve the problem. I suspect that this will result in some projects distancing themselves from the EU, and have a chilling effect on new OSS projects in these areas, especially inside the EU. |
|