Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> What are you actually proposing here? Any Ubuntu/Debian distribution contains hundreds or thousands of packages and transitive dependencies - it's unreasonable to expect corporations to contribute, even financially, to all of these.

Why is it unreasonable?

I actually see it as very reasonable. You use a package in a commercial distribution, you use aggregators like Github sponsors to pay the maintainer (a subscription, not a one-off payment!). What's unreasonable about that?



I don't really see how paying the maintainers helps against insider threats. The users still has to ensure that the software is safe.

Paying the maintainers is nice, but I think the megacorps and governments has to fund an organization that does security audits of all the sensitive packages, instead of heaping yet another job on the shoulders of the maintainers. It's especially important to not saddle the developers of open source with red tape, most of them would think that getting paid is poor compensation for the lost freedom.


See the rest of my comment, where I propose using an aggregator. I think it's unreasonable to expect everyone to engage in support contracts individually with every maintainer.




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: