Earlier quoted context omitted.
> Linux kernel developers are entirely capable of assessing this. They're just refusing to do it for someone else's definition of a "security bug". Then instead of this, don't? It's utterly childish. > How would they get burnt by this? Social pressure from other kernel developers (or even outside) isn't going to have that effect. Fewer organisations willing to cooperate with them, for one? Social pressure comes in ma…
> They're going to be paying someone else […] And that's perfectly fine, it's open source software . Either way someone gets paid to look at the patches, which is my point . If you want to do it in a cost-effective manner, you'll find other people with the same requirements, since the work result is "shareable". > […] instead of the organization that deliberately hinders these efforts. There is no such organization,…
> There is no such organization
There is such an organization, the Linux Foundation is the CNA being the hindrance to these efforts. And yes, they won't perform the role, someone else will and they will be paid for it.
For some that's fine, I find it a significant amount of wasted effort, confusion and potential issues.