4 ms·
Other projects get unmaintained with maintainers burnt out by a torrent of vulberability reports
by yread 27d ago
Other projects get unmaintained with maintainers burnt out by a torrent of vulberability reports
- fsloth 27d agoThis I don't understand. If it's not your job, then just ignore the reports. If it's actually critical, someone will put money on the table and then it's a business. And then it's about scheduling and resourcing - also should not burn anyone out. Just because many people have false sense of entitlement as soon as they get a free offering, it does not mean anyone needs to accommodate them.
- okeuro49 27d ago> If it's not your job, then just ignore the reports. If you have a highly conscientious personality, this is easier said than done.
- pdimitar 27d agoIt's also a great opportunity for character development. Use it for that, and not for trying to overbook yourself to 300%. You don't owe the world anything at all. If you're conscientious, then give a little -- here and there. Don't turn it into an unpaid job.
- fsloth 27d ago" highly conscientious " Just doing what others wish is not conscientous in itself! It _may_ be depdending on situation but it can be just pathological towards the self. When it's psyhocologically hard to do things you imagine will dissapoint someone that's probably not concientousness. It's more like low self-esteem or codependency. It's very hard for someone to tell these apart themselves. Hence when this topic pops out it's good idea to remind that being super-accomodating may in fact be a personality flaw - that can be healed if acknowledged. There is very large spectrum between "trying not to dissapoint anyone" and doing what you know is the right thing.
- vincnetas 27d agoNot everyone acts rationally even when knowing that they act irrationally.
- pdimitar 27d agoSounds like their problem, not something a SaaS product should dance around. Yet they kind of did. I've limited participation in my libraries with GitHub's setting that nobody who made an account in the last 6 months can do anything in my repos (after some misguided hustler thought they're an easy target and posted an ad).lp Time's marching forward though. Wonder what will happen after a few more months. We'll have bot spam accounts that are no longer as fresh.
- centuryfall 26d agohttps://xkcd.com/2347/ https://xkcd.com/2347/ A great majority of business applications do run on open source projects, and in turn, are affected by them if things go awry. It’s a prisoner’s dilemma in this case.
- _zoltan_ 27d agousual crying from the usual people. AI slop, blahblahb, ... (I don't mean you. just these so called open source developers.)
- yread 26d agoI'm not sure if it's going to persuade you but here is an example: https://github.com/uclouvain/openjpeg https://github.com/uclouvain/openjpeg Basically the only library for reading jp2k data (complicated specs, ask your AI to one shot an implementation, mine said "it's 3000 lines of fiddly spec, too complicated"). Issues full of buffer-overflows. Recently unmaintained. Used in tons of projects, now all possibly vulnerable.
- _zoltan_ 26d agoand? don't use it. switch. abandon. did we lose anything of value? probably not.