Post #1434866
2023-01-01 10:58 UTC
Thanks for the thoughtful blog @Di4na (and @kushal). I think there's more to say about quality in OSS.
For sure, licenses say "AS IS", although that doesn't automatically imply the code has been thrown open without some thought to its downstream use. Some projects scrutinise the chain of dependencies and have mature communications channels about security vulnerabilities. And I wonder if this is associated with size, funding or governance structure of the open source project?
Replies (1)
-
@Di4na@hachyderm.io 2023-01-01 19:42
@alexinshandon @kushal Usually it is associated with how much time has been sunk into it. Funding and size both help ofc. In practice, this is more due to people that do it liking doing this work than anything else, or because there is a lot of funding and demands. I advise to read the Road and Bridges report that i linked in the post near the end :)