logoalt Hacker News

ImPostingOnHNyesterday at 7:20 PM1 replyview on HN

If you look at the issue list for any significant open source project, it's probably of nonzero size. That's a way of saying "no": just don't do it.

Maybe you're overloaded, maybe you just don't feel like it. It's totally normal, and different projects have different levels of resources, some with none anymore.


Replies

securesamlyesterday at 7:28 PM

I have seen small utility libraries like tj-actions get compromised because there aren't any security specialists looking at the library.

My main concern is supply chain compromise.

show 1 reply