oss-sec mailing list archives

Re: Some Changes to GNOME Security Tracking


From: Solar Designer <solar () openwall com>
Date: Sun, 2 Aug 2026 17:22:26 +0200

Hi,

On Sun, Aug 02, 2026 at 07:39:04AM -0700, Russ Allbery wrote:
Peter Gutmann <pgut001 () cs auckland ac nz> writes:
Russ Allbery <eagle () eyrie org> writes:

One solution that anyone in open source software communities has heard
about for decades now is to turn open source software maintenance into
a job with a paycheck. Then it doesn't necessarily have to be fun

It can still be fun, and in some cases more fun than pure open-source.
Consider the difference between "we have a practical real-world problem
that we need solved, there's real-world demand for it, we can describe
it in detail, and we'll pay you to solve it" (commercial user) vs "i
have some me-only feature that I want you to add to your code just for
me and I'll whine endlessly on Github/Discord/whatever if you don't"
(open-source).

Speaking as someone who has structured his entire career to be in the
first position that you describe, you're preaching to the choir on this. I
completely agree; part of the reason why I do less open source software
work in my free time these days is because I get paid to do it as part of
my day job and that comes with a much more satisfying and meaningful
problem stream to solve.
[...]

This thread and the "33 Vulnerabilities in cJSON" one are becoming
increasingly difficult to moderate.  While I understand that incentives
for open source development matter a lot and are related to fixing
security issues, the most recent postings by Peter and Russ do not
mention security at all, so this is becoming off-topic.  I think this is
fine so far, but let's please refocus it back on topic or stop it here.

As a result of these two threads wandering borderline off-topic, another
long-time subscriber tried to bring up and wanted to discuss in here a
Net Neutrality and free speech angle, which is even further off topic,
so I'm not letting it through.  I mention this to give you all an idea
of where else and how far this may be heading if left unmoderated.

I would much rather see constructive contributions on topic of the list.
For example, "here's a new maintained fork of cJSON with the 33 issues
fixed, and functional and regression tests added" (in the other thread,
not here), or something else like that.  This isn't rocket science.

Thanks,

Alexander


Current thread: