| ▲ | hnlmorg a day ago | |||||||||||||||||||||||||
That’s a strawman argument because we aren’t talking about security auditing for trillion dollar companies. We are talking about developers having ethical ownership for communicating their project responsibly. That means being honest about when a pet project is just a pet project rather than talking about every POC as if it’s production ready. And it’s disingenuous to spin this as “only trillion dollar companies use open source” because we all know that isn’t even remotely true. | ||||||||||||||||||||||||||
| ▲ | jjav 13 hours ago | parent | next [-] | |||||||||||||||||||||||||
> That means being honest about when a pet project is just a pet project rather than talking about every POC as if it’s production ready. And who isn't honest about it? Read the contract you have with the provider. There is a way to legitimately expect production-ready libraries: You sign a purchase order for the right to use that code for a year (typically, or multi-year) and pay a quite substantial amount of money for that. Then you have purchased the right to expect a certain level of quality (details can be in the contract and reflected in the price). If you're using something for free without having agreed to such a contract and paid the vendor accordingly, then you can expect exactly as much as you paid for it. | ||||||||||||||||||||||||||
| ||||||||||||||||||||||||||
| ▲ | ForHackernews 19 hours ago | parent | prev [-] | |||||||||||||||||||||||||
Anyone who is making money off my open source work can PAY ME if they want signed, reproducible builds. Anyone who is not paying me can use what I generously give away for free without THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE. Concerned about security? Good for you, build it yourself. | ||||||||||||||||||||||||||
| ||||||||||||||||||||||||||