logoalt Hacker News

estimator7292last Sunday at 2:53 PM2 repliesview on HN

You're completely missing the point.

The problem isn't that volunteer devs are harassed into work.

The problem is being harassed.

Whether or not you "care" or feel the need to do any work or accept responsibility, constant harassment will destroy anyone, even you.


Replies

ndiddylast Sunday at 5:39 PM

My hope is that if they started responding to CVE bug reports for hobby codecs with something like “This is a codec written by someone in his free time and intended to be used for preservation purposes. We do not support using this codec with untrusted input and may not implement a fix for this bug within the 90 day CVE timeline”, it would stop the harassment. The companies doing the CVE spam would either have to start fixing things themselves, contract someone to do so, or stop using ffmpeg due to all the scary CVEs getting flagged in whatever bullshit security compliance standard they use.

show 1 reply
bawolfflast Sunday at 8:42 PM

Getting a polite bug report is not being harrased.

show 2 replies