Hacker News new | ask | show | jobs
by chii 28 days ago
> work of running an open-source project (issue triage, security disclosures, contribution guidelines, CI, release cadence, dependency maintenance)

so why not just simply dont do any of that? Ignore issues, ignore security disclosures, etc. The end user is responsible for auditing their own security needs, and does not have a right to free audits from an open source tool.