Sometimes I wonder what would happen if
oss developers simply list out every single bug report they receive on their website and clearly note we don’t have resources to fix it.
And then list every single mega corp that uses that OSS library and clearly send out message informing the world we don’t fix bugs and since all of these orgs don’t like helping anyone using them is vulnerable.
May be just may be that would give people an idea about putting pressure on wrong set of individuals.
But most importantly it will make it clear for people where the responsibility of security for your customers lie with you or with third party.
#softwaresupplychainsecurity #supplychaincompromise #opensource

decio