@joshbressers@infosec.exchange
Post #1156484
2025-08-28 01:38 UTC
Replies (29)
-
@adriano@lile.cl 2025-08-28 02:05
@joshbressers@infosec.exchange @shauna@social.coop “It’s OK. You’re still in the denial stage. Hopefully you’ll reach anger by the end of this post.” That’s my secret, cap,
-
@skylark13@mastodon.gamedev.place 2025-08-28 02:43
@joshbressers@infosec.exchange I'd also say lots of single maintainer projects are probably abandoned. This is just my impression, but in the last year, the PRs I've sent to single maintainer repos have generally been unanswered. I really wonder how a project can survive that. Sure I can fork it and add my bug fixes and features, but the official web page still points to the old abandoned repo. New users will go there. If the maintainer doesn't even reply to posts about passing maintainership, what can you do?
-
@kevinbowen@hachyderm.io 2025-08-28 02:54
@joshbressers@infosec.exchange Thanks for the article, Josh. It would really suck to be Malinochkin right about now. That is some incredibly shitty, unfounded fearmonging in that article. Shame on the Register.
-
@sethmlarson@mastodon.social 2025-08-28 03:35
@joshbressers@infosec.exchange Really really love the title, thank you for writing this. I'm putting this one in the back pocket for later use.
-
@gonzo_askold@mastodon.social 2025-08-28 04:22
@joshbressers@infosec.exchange being dependent on russian code is a security risk, you can't guarantee freedom of expression in a country known to disappear people with wrong political positions. if everybody does that it doesn't mean that it's safe and "popularity" of single person maintained open source solutions does not in any way hint at their security characteristics if one person can maintain that code why just not embedded it directly in your repository? be a man, manage your f*cking js modules
-
@kushal@toots.dgplug.org 2025-08-28 05:42
@joshbressers@infosec.exchange Thank you for writing this post.
-
@schmidt_fu@mstdn.social 2025-08-28 05:54
@joshbressers@infosec.exchange It would be interesting to see, how many projects are basically the same thing, i.e. "reinventing the wheel". Be it due to lack of findability, or ignorance, or genuine improvement - or due to splitting the same things over and over with every new platform and programming language. I wonder how to match these however (maybe something like alternativeto.net for packages?)
-
@Vrixyz@mastodon.gamedev.place 2025-08-28 05:59
@joshbressers@infosec.exchange that’s why I contribute to a lot of open source projects! But let’s be real, the little compensation there is to open source is rightfully routed to main authors, so such help is hardly financially sustainable!
-
@westonsteimel@hachyderm.io 2025-08-28 06:20
@joshbressers@infosec.exchange And using the excellent @ecosystems@mastodon.social data for it just serves as a further example of how important many of these single maintainer projects can be.
-
@piegames@flausch.social 2025-08-28 06:21
@joshbressers@infosec.exchange "It’s OK. You’re still in the denial stage. Hopefully you’ll reach anger by the end of this post."
-
@jfroehlich@mastodon.social 2025-08-28 06:28
@andrewrk@mastodon.social maybe you want to think about the 1-maintainer-problem for zig. Imho a lot of smaller npm libraries are convenience, performance or security optimizations for repetitive programming tasks needed in every other app. I don’t think the stdlib should be spammed, but a community maintained jetpack lib could be nice @joshbressers@infosec.exchange
-
@anant@social.anantshri.info 2025-08-28 06:31
@joshbressers@infosec.exchange if you participate in scorecard discussions this discussion might be something of your interest https://github.com/ossf/scorecard/discussions/4759 .
-
@deer@gts.pia309.com 2025-08-28 06:58
@joshbressers@infosec.exchange this is interesting Weirdly enough this gives me a lot of hope that my stupid little projects that nobody uses would actually be popular and useful if I just gave them a little more polish and showed them off So thanks
-
@quantenzitrone@corteximplant.net 2025-08-28 07:03
@joshbressers@infosec.exchange imo that register article is pretty trash. “Open source software doesn’t need a CVE to be dangerous, It only needs access, obscurity, and complacency” bruh thats true for any software, not just open source
-
@Kerplunk@mastodon.scot 2025-08-28 07:15
@joshbressers@infosec.exchange Maybe an interesting article, very well protected information. opensourcesecurity.io All I see is looping Verifying you are human. This may take a few seconds. opensourcesecurity.io needs to review the security of your connection before proceeding. I think I am Human, do I need a doctors statement to read the article???
-
@AlanHicksLondon@fosstodon.org 2025-08-28 07:19
@joshbressers@infosec.exchange knowing you're one of those developers and not alone isn't much comfort.
-
@WhyNotZoidberg@topspicy.social 2025-08-28 07:27
@joshbressers@infosec.exchange Obligatory:
-
@TheTomas@social.toot9.de 2025-08-28 08:13
@joshbressers@infosec.exchange just some thoughts on that: The Open Source Universe is quite a bit larger than NPM (in fact I avoid all software on NPM in my stacks). Nothing about Debian Repo there, when checking what Apache ressources they use, I only see a fraction of projects included. So the data of this Website is quite misleading. It even did not work properly (see screenie)
-
@bexelbie@toot.io 2025-08-28 08:16
The maintainer being discussed said, “I maintain the project alone, as over the years the community has not expressed a need for more active participation.” This is the politest “no one wants to help,” I’ve read in a while. This is not the time to discuss a new funding model or how the maintainer should form a legal entity and offer support. This is where you roll up your sleeves and find time to review patches and write new ones. @joshbressers@infosec.exchange
-
@khleedril@cyberplace.social 2025-08-28 08:54
@joshbressers@infosec.exchange I'm not seeing a problem here. It is open source, and professional people, such as government employees and security researchers, do scrutinize it.
-
@gkrnours@mastodon.gamedev.place 2025-08-28 10:42
@joshbressers@infosec.exchange there is an easy solution, giving a living wage to everyone, no question asked
-
@fishidwardrobe@mastodon.me.uk 2025-08-28 10:44
@joshbressers@infosec.exchange > But it also could be the software running THE WHOLE F*CKING PLANET is written by one person. linux time zone database. if that goes, so does the whole internet. I remember reading a few years ago that it was maintained by a schoolteacher in the american midwest somewhere.
-
@pulkomandy@mastodon.tetaneutral.net 2025-08-28 12:31
@joshbressers@infosec.exchange how many projects have zero maintainers?
-
@simulo@hci.social 2025-08-28 12:41
@joshbressers@infosec.exchange It is fascinating to me that much of the open source tooling (e.g. git) and practices are shaped by the large scale collaboration in Linux Kernel development when most projects are created in a very, very different context.
-
@diffrentcolours@tech.lgbt 2025-08-28 13:18
@joshbressers@infosec.exchange I believe Tidelift was working on this - fundraising from big corps to direct towards critical components. Not sure what's happening since they got bought by Sonar though.
-
@greg@icosahedron.website 2025-08-28 14:36
@joshbressers@infosec.exchange curious how many of those "more than 1 maintainer" projects is actually just "one maintainer, plus a guy who sent in one commit to fix his build problem 9 years ago"
-
@openfly@milliways.social 2025-08-28 15:35
@joshbressers@infosec.exchange gitlab relied on a ruby framework for their aws integrations written by a single engine yard employee who abandoned the project after a few years. Meanwhile gitlab is a hundred million a year plus company. Guy never saw a fraction of that income... Gitlab still keeping his code on life support though
-
@adamsaidsomething@mastodon.social 2025-08-28 16:07
@joshbressers@infosec.exchange Access to the blog post blocked by Cloudflare ☹️
-
@fuzzyfuzzyfungus@cyberplace.social 2025-08-28 19:44
@joshbressers@infosec.exchange The "Request a demo of Entercept, the first and only platform designed to identify and track foreign influence in your software." at the bottom of the 'analysis' tells you most of what you need to know.