Earlier quoted context omitted.
You are absolutely welcome to start a project and exclude anyone who you think is unworthy of contributing. Software is not and never was a public good.
No, what I would rather do (read as am actively doing) is help elect people into congress that want to rightfully destroy Silicon Valley and bring the benefit of public software to the masses.
We all depend on open source. We will defend it together
251–257 of 257 posts
Re: We all depend on open source. We will defend it together
#252Earlier quoted context omitted.
It doesn't help that "Akrides" sound like a Bond villain EvilCorp run by Dr Ambergris whose face is horribly disfigured from a series botched face lifts that's plotting to populate Mars with big boobed clones running around dressed only in brassieres, just like his lead concubine, Dorothy "Dirty" Sanchez (Don't blame me for Kam Fleming's knack for double entendres...) who leads his team of equally big boobed secret h…
The name is of Greek origin https://en.wikipedia.org/wiki/Akritai from frontier soldiers guarding the Byzantine empire's borders.
> Byzantine
Not the connotations I would aim for, but after looking at the organisations involved it's probably apt.
Re: We all depend on open source. We will defend it together
#253Earlier quoted context omitted.
Do you have any examples of Google submitting vulnerabilities and refusing to assist maintainers create a patch when asked to do so?
https://linuxiac.com/libxml2-becomes-officially-unmaintained...
Re: We all depend on open source. We will defend it together
#254Earlier quoted context omitted.
Do you have any examples of Google submitting vulnerabilities and refusing to assist maintainers create a patch when asked to do so?
Wasn’t that a story with ffmpeg a few months ago? And people were getting roasted for even the suggestion that google should contribute patches?
Sounds like Google has been very helpful and nice.
Re: We all depend on open source. We will defend it together
#255> We are joined by Amazon Web Services, Anthropic, Chainguard, Cisco, Citi, Endor Labs, Ericsson, Google, IBM, JPMorganChase, Microsoft and GitHub, NVIDIA, OpenAI, RapidFort, Red Hat, Rust Foundation, Sonatype, Vodafone, and Zscaler A lot of open source folks are going to be very skeptical, rightly so, of this group of players. > ... to find, fix, and responsibly disclose vulnerabilities in critical open source softw…
You realize that the companies listed employ many of the core open source maintainers for large projects? It is project-specific, but 80% of Linux kernel development is from paid corporate employees. Similar for kubernetes. All the load bearing infrastructure is already handled by these companies... literally no one else is going to have the resources or experience to redirect large efforts on securing F/OSS. What wo…
Re: We all depend on open source. We will defend it together
#256Nonsensical corporate posturing. "Microsoft will contribute expertise, resources, and AI technologies to help responsibly identify and fix vulnerabilities" As a reminder, Microsoft runs NPM and GitHub. Microsoft has access to the best AI models and massive data centers. Despite that, their own products are rapidly getting worse at security and their services are central hubs through which various exploits are propaga…
> a version of SQLite that has a severe vulnerability Calling CVE-2025-70873 a severe vulnerability is a bit overplaying it imo. The vulnerability requires that you allow an attacker to import an arbitrary ZIP file I looked at the vulnerability in question by the way, CVE-2025-70873, and it really is not that severe unless you're allowing users to import arbitrary ZIP files