6 ms·
How about simply paying the maintainers and then getting stuff done like the classical business does.
by triblemaster 2y ago
How about simply paying the maintainers and then getting stuff done like the classical business does.
- __MatrixMan__ 2y agoWell yes, sounds great, but it doesn't really address the security problem. Now you've just got the bad guys getting two paychecks instead of one and the good guys getting one paycheck instead of zero.
- transpute 2y ago> bad guys getting two paychecks instead of one 1 to 2 paychecks = 100% increase. > good guys getting one paycheck instead of zero 0 to 1 paycheck = infinity increase. With a known baseline of "good paychecks", financial analytics can pursue identification of "bad paychecks".
- armini 2y agoOne of the biggest risks for companies is securing dormant code, it's perfectly fine for a project to be no longer sexy enough to maintain. Platforms like thanks.dev have already proven how reward & recognition can help promote development in an ecosystem https://www.youtube.com/watch?v=e5FV-AnKPlo&t=1s https://www.youtube.com/watch?v=e5FV-AnKPlo&t=1s
- deleted 2y ago[deleted]
- omoikane 2y agoDid you mean: instead of trying to become a maintainer to a trusted open source project, how about bad actors simply bribe the existing maintainer to do their bidding? There would be no maintainer changes in that scenario. Related, the motivation for trying to gain privileged access to open source projects is to leverage the existing trust associated with that project. A different long game that could be played is to create a new project with the intent on backdooring it a few years down the road, after it has gained sufficient trust.