It has to be 100% open source public code or we will have no way of proving this is not malware, or secretly swapped out for malware later when your CI/CD system or laptop is compromised. Supply chain attacks happen all the time and with closed code no one will be equipped to spot it when it happens.
Also, security aside, engineers want the freedom to modify and experiment with the tools we rely on.
Tools like this are too important to be closed. Do you want to be Internet Explorer or Firefox?
It has to be 100% open source public code or we will have no way of proving this is not malware, or secretly swapped out for malware later when your CI/CD system or laptop is compromised. Supply chain attacks happen all the time and with closed code no one will be equipped to spot it when it happens.
Also, security aside, engineers want the freedom to modify and experiment with the tools we rely on.
Tools like this are too important to be closed. Do you want to be Internet Explorer or Firefox?