Skip to content
Discussion options

You must be logged in to vote

This is one of the hardest open-source dilemmas — because everyone benefits from open source, but no one actor is solely responsible. The reality is that sustainable security requires shared responsibility, with different roles for companies, foundations, and communities. Here’s how it breaks down:


1. Companies That Use Open Source

  • Primary responsibility: Since they extract direct business value, companies should contribute proportionally.

  • What they should do:

    • Fund security audits and bug bounties for critical dependencies.
    • Employ engineers to contribute patches upstream instead of only applying fixes downstream.
    • Sponsor maintainers financially (e.g., through Open Collective, GitHub…

Replies: 1 comment

Comment options

You must be logged in to vote
0 replies
Answer selected by Mahmoud9876
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants