Get the latest tech news
Questioning the conventional wisdom on liability and open source software
To improve cybersecurity, open source software should not be completely exempt from software liability.
Should such an effort to define a floor gain steam, there is one practice, sometimes overlooked, that is increasingly getting attention: including end-of-life (EOL) open source software components in an application. [Clarifying liability] ... would encourage further growth in the role played by bigger, well-resourced software vendors in improving the security of commonly used open source packages. Part of this process will require analysts to confront assumptions that have mostly been implicit, such as the claim that placing liability on software companies as “final assemblers” will lead to broad investments across the current open source ecosystem.
Or read this on Hacker News