Live data from Hacker News

An open letter asking NHS England to keep its code open

keepthingsopen.com

11–17 of 17 posts

Re: An open letter asking NHS England to keep its code open

#11

I've been chatting with CISOs, CTOs, maintainers, and other peers for the past few weeks (some of whom are F50s) about this, and their default gameplan now is to pause OSS contribution and usage until AppSec teams reach a point where they can easily validate and fix issues within a day. Traditionally, end-to-end response times were in the 8-10 day range which clearly cannot hold today. I don't think it's the death of…

I like simonw's take that open source should be more valuable [0]

>An interesting result of this is that open source libraries become more valuable, since the tokens spent securing them can be shared across all of their users. This directly counters the idea that the low cost of vibe-coding up a replacement for an open source library makes those open source projects less attractive.

I can understand why the reflexive move to fork the code and move it in-house, but how sustainable will that be when eng teams have MORE code to manage and mitigate vulnerabilities for?

[0] https://simonwillison.net/2026/Apr/14/cybersecurity-proof-of...

Re: An open letter asking NHS England to keep its code open

#13
If you’re reading this thread because you care about the quality of the NHS’s digital services, I encourage you to also sign this petition to block NHS providers from wasting money of “accessibility overlays” that actively harm the experience for people with disabilities and cost money that could be spent on improving the core service: https://petition.parliament.uk/petitions/765480/

Re: An open letter asking NHS England to keep its code open

#15

I've been chatting with CISOs, CTOs, maintainers, and other peers for the past few weeks (some of whom are F50s) about this, and their default gameplan now is to pause OSS contribution and usage until AppSec teams reach a point where they can easily validate and fix issues within a day. Traditionally, end-to-end response times were in the 8-10 day range which clearly cannot hold today. I don't think it's the death of…

I like simonw's take that open source should be more valuable [0] >An interesting result of this is that open source libraries become more valuable, since the tokens spent securing them can be shared across all of their users. This directly counters the idea that the low cost of vibe-coding up a replacement for an open source library makes those open source projects less attractive. I can understand why the reflexive…

I agree. The reflexive move is by a specific F50 that has the size, internal controls, headcount, and liability risk that they are taking such an approach.

Most other places will continue to use OSS, but much more locked down access to third party dependencies will be granted. I personally think it'll be a great time to be in the AppSec and SBOM validation space.

Post reply on HN