•  smeg   ( @smeg@feddit.uk ) 
    link
    fedilink
    English
    56 months ago

    Hopefully this xz scandal will give the kind of big corps which already pay OSS maintainers the kick up the arse required to treat their entire supply chain as a potential attack vector that should be audited and supported. Or maybe I’ve just asked the monkey’s paw for increased corpo control over OSS projects…

      •  smeg   ( @smeg@feddit.uk ) 
        link
        fedilink
        English
        16 months ago

        I think the real old big dogs like Microsoft, Google, and IBM still have a lot of dedicated developers for big projects like the Linux kernel. I doubt they bother that much with smaller projects though.