Hacker News new | ask | show | jobs
Dependency cooldowns turn you into a free-rider (calpaterson.com)
3 points by calpaterson 58 days ago
3 comments

I went into this article thinking, well, I am already a free-rider on open source!

But now I find the idea of an upload quite convincing. I don't think it quite solves the free rider problem, but it does flip it. Cooldowns make security opt-in. Whereas a publish queue makes insecurity opt-in. That seems like a better default.

Let security companies drink from the firehose. Companies can pay for it and subsidize end users through Github etc. Everybody wins.