Hacker News new | ask | show | jobs
by gavinhoward 663 days ago
This security theater around supply chain security is getting ridiculous.

What we need is true supply chain security, but no one is willing to pay for that; it would mean paying FOSS projects, and companies don't want to pay for their "free" software.

1 comments

I just want an actual bill of versioned open source software used in each closed source app.