|
|
|
|
|
by nullbio
32 days ago
|
|
> The major short term downside is that open source or personal projects won't be able to afford things like Codex Security. Realistically, all open-source projects should be forced to have automated scans of this nature before their releases can be shipped. This is something the package managers and github need to figure out. It'd stop the supply chain attacks too. |
|
Then open source projects need a McKinsey-like stamp of approval to even be released.
Sounds like there are many parasites in this process.
You know that open source users are free to scan everything if they want to?