oss-sec mailing list archives
Re: Some Changes to GNOME Security Tracking
From: Solar Designer <solar () openwall com>
Date: Sun, 2 Aug 2026 17:22:26 +0200
Hi, On Sun, Aug 02, 2026 at 07:39:04AM -0700, Russ Allbery wrote:
Peter Gutmann <pgut001 () cs auckland ac nz> writes:Russ Allbery <eagle () eyrie org> writes:One solution that anyone in open source software communities has heard about for decades now is to turn open source software maintenance into a job with a paycheck. Then it doesn't necessarily have to be funIt can still be fun, and in some cases more fun than pure open-source. Consider the difference between "we have a practical real-world problem that we need solved, there's real-world demand for it, we can describe it in detail, and we'll pay you to solve it" (commercial user) vs "i have some me-only feature that I want you to add to your code just for me and I'll whine endlessly on Github/Discord/whatever if you don't" (open-source).Speaking as someone who has structured his entire career to be in the first position that you describe, you're preaching to the choir on this. I completely agree; part of the reason why I do less open source software work in my free time these days is because I get paid to do it as part of my day job and that comes with a much more satisfying and meaningful problem stream to solve.
[...] This thread and the "33 Vulnerabilities in cJSON" one are becoming increasingly difficult to moderate. While I understand that incentives for open source development matter a lot and are related to fixing security issues, the most recent postings by Peter and Russ do not mention security at all, so this is becoming off-topic. I think this is fine so far, but let's please refocus it back on topic or stop it here. As a result of these two threads wandering borderline off-topic, another long-time subscriber tried to bring up and wanted to discuss in here a Net Neutrality and free speech angle, which is even further off topic, so I'm not letting it through. I mention this to give you all an idea of where else and how far this may be heading if left unmoderated. I would much rather see constructive contributions on topic of the list. For example, "here's a new maintained fork of cJSON with the 33 issues fixed, and functional and regression tests added" (in the other thread, not here), or something else like that. This isn't rocket science. Thanks, Alexander
Current thread:
- Re: Some Changes to GNOME Security Tracking, (continued)
- Re: Some Changes to GNOME Security Tracking Alan Coopersmith (Aug 04)
- Re: Some Changes to GNOME Security Tracking Francis Perron (Aug 04)
- Re: Some Changes to GNOME Security Tracking Jan Schaumann (Aug 06)
- Re: Some Changes to GNOME Security Tracking Collin Funk (Jul 31)
- Re: Some Changes to GNOME Security Tracking Jeremy Stanley (Jul 31)
- Re: Some Changes to GNOME Security Tracking Russ Allbery (Jul 31)
- Re: Some Changes to GNOME Security Tracking Jeremy Stanley (Jul 31)
- Re: Some Changes to GNOME Security Tracking Demi Marie Obenour (Jul 31)
- Re: Some Changes to GNOME Security Tracking Peter Gutmann (Aug 02)
- Re: Some Changes to GNOME Security Tracking Russ Allbery (Aug 02)
- Re: Some Changes to GNOME Security Tracking Solar Designer (Aug 02)
- Re: Some Changes to GNOME Security Tracking Peter Gutmann (Jul 31)
- Re: Some Changes to GNOME Security Tracking Alan Coopersmith (Jul 31)
- Re: Some Changes to GNOME Security Tracking Jacob Bachmeyer (Aug 02)
