|
|
|
|
|
by b112
237 days ago
|
|
You don't owe anyone anything when free. However, your reputation does depend upon treating security seriously. It's 2025, not 2005. So one should indicate "this is a hobby, and I have no time to deal with this" if so. Fair enough! However, if you have people paying for support, or you want them to see your software and become clients, or you do a project to showcase your skills? Security front and centre. My list of helpfuls, in my prior post, actually helps a project maintainer reduce unnecessary queries. Think of a CVE list as a FAQ. |
|
We have a very popular product, lots of use in what is really the foundation of the internet and almost no support contracts.
So you can turn the argument around, if you are not paying for software, consider it a hobby project. Feel free to report and issue and create a ticket. But don't expect anything to happen. And don't complain on mailing lists how your issue is not taken seriously. Just fix the issue yourself or switch to a different product.