Firmware guy!

  • 0 Posts
  • 1 Comment
Joined 2Y ago
cake
Cake day: Jun 08, 2023

help-circle
rss

As a packager, I totally relate to this: we generally don’t have the resources to follow the upstream development of the projects we rely on, let alone audit all the changes they make between releases. Open source software still has security advantages — we can communicate directly with the maintainers, backport security fixes and immediately release them to users, fix bugs that affect the distribution, etc. — but I agree that it’s not a silver bullet.