Hacker News new | ask | show | jobs
by kube-system 294 days ago
You're missing the point of a supply chain risk assessment. Yes, you can fork a project to maintain it yourself. But, for an organization to do this, they need to allocate resources, e.g. time and money. This is part of the risk you are assessing for in a supply chain risk assessment.
1 comments

The risk quintuples with no lock files. And the number of maintainers is often not as important as the number of other users who are also putting eyes on the code