Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I suspect this is why when many companies decide they want to use open source stuff they contract with companies like GitHub, who absorb the risk of using git, etc, rather than trying to vet the code themselves. I still have a hard time envisioning anyone in any position of authority in any credible company accepting the idea of installing open source software without vetting it one way or the other. If the shit did hit the fan their career would be pretty much over.


companies like GitHub, who absorb the risk of using git

Except they don't do that at all?

If a bug in git would cost your company a lot of money, why do you think GitHub would be accountable if you have some enterprise deal there?

I still have a hard time envisioning anyone in any position of authority in any credible company accepting the idea of installing open source software without vetting it one way or the other.

Well, that is an entirely different thing. People TEST stuff before deploying it. But that has little to do with code reading or mandatory support contracts.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: