The title seems like a stupid attack on open source.. Because closed source abandonware is not a security issue??
At least open source projects can be forked and updated, a closed source system would leave you with only the option of choosing between the software or security.
3 Comments
magikmw@piefed.social · 2 pts · 324d
Honestly, cargo could flag crates with known CVEs, be a better package manager.
mandatstory@lemmy.world · 1 pts · 324d
DeltaWingDragon@sh.itjust.works · 2 pts · 324d
Does this affect GNU tar, or Busybox tar, or BSD tar?
MTK@lemmy.world · 1 pts · 322d
The title seems like a stupid attack on open source.. Because closed source abandonware is not a security issue??
At least open source projects can be forked and updated, a closed source system would leave you with only the option of choosing between the software or security.