Open source maintainer Seth Michael Larson on the potential changes to contributions post-xz hack

Поделиться
HTML-код
  • Опубликовано: 13 май 2024
  • Shortly after the xz utils backdoor hack was uncovered, Tidelift gathered together a group of open source maintainers across the Javascript, Java, and Python ecosystems to hear not only how the xz hack impacted their work (spoiler alert: this attack reverberated across ALL ecosystems, not just in the Linux OS!), but also how it made them feel.
    In this clip, we hear from open source maintainer, Seth Michael Larson. Seth is the lead maintainer on urllib3, an HTTP client library that is the most downloaded package on the Python Package Index. Here he talks about
    You can watch the entirety of the panel on-demand here: explore.tidelift.com/c/life-a...
    Learn more about xz: tidelift.com/resources/xz-bac...
    Transcript:
    So one of the primary things that I concern myself with when I'm doing anything in my professional life right now, just because I'm having to make all these decisions for ecosystems, is keeping the flame of open source alive. And that is so easy to stamp out, just by making something that seems like a well intentioned change. Like, okay, we're not going to take contributions from people that are anonymous anymore. And so any one of these, small changes, that seems like something good to some people, would end up just destroying open source as we know it today.
  • НаукаНаука

Комментарии •