|
|
|
|
|
by phicoh
237 days ago
|
|
As an open source software vendor I can say two things:
1) The CVE system allows vendors to deny CVEs that relate to their product. I don't know the exact rules, so I don't know if it applies in this case. We take anything that can crash our software seriously.
2) For users without a support contract, your priority does not automatically become out priority. If you want your issues fixed then make sure we have the money to do so. Just because you got a free download doesn't give you any rights to support. |
|
However, your reputation does depend upon treating security seriously. It's 2025, not 2005.
So one should indicate "this is a hobby, and I have no time to deal with this" if so. Fair enough!
However, if you have people paying for support, or you want them to see your software and become clients, or you do a project to showcase your skills?
Security front and centre.
My list of helpfuls, in my prior post, actually helps a project maintainer reduce unnecessary queries.
Think of a CVE list as a FAQ.