I've been chatting with CISOs, CTOs, maintainers, and other peers for the past few weeks (some of whom are F50s) about this, and their default gameplan now is to pause OSS contribution and usage until AppSec teams reach a point where they can easily validate and fix issues within a day. Traditionally, end-to-end response times were in the 8-10 day range which clearly cannot hold today. I don't think it's the death of…
>An interesting result of this is that open source libraries become more valuable, since the tokens spent securing them can be shared across all of their users. This directly counters the idea that the low cost of vibe-coding up a replacement for an open source library makes those open source projects less attractive.
I can understand why the reflexive move to fork the code and move it in-house, but how sustainable will that be when eng teams have MORE code to manage and mitigate vulnerabilities for?
[0] https://simonwillison.net/2026/Apr/14/cybersecurity-proof-of...