Remix.run Logo
__MatrixMan__ 4 hours ago

That's better than nothing, but if you're expecting people to be looking at something before you use it, you should be waiting for a thumbs up from them, not waiting some arbitrary timespan for the absence of a thumbs down.

You should probably also be paying them directly.

woodruffw 4 hours ago | parent | next [-]

I don’t think it makes a ton of sense for individual OSS maintainers to pay companies for security. The point of cooldowns is that they’re free and they trend towards security at no logistical cost to maintainers.

(I agree that companies should pay for security products, of course. The bigger problem there is that so many security products are terrible, and supply chain products appear to be no different as a class.)

mort96 4 hours ago | parent | prev [-]

It's a game of probabilities. Waiting longer means a higher probability that someone found something before you upgrade.

Most of the attacks we have seen lately are from legitimate projects which got compromised. The maintainers of those projects are generally looking out for that.