Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

One dev salary for open source dependencies #59

Open
8 of 19 tasks
abitrolly opened this issue Jan 22, 2020 · 3 comments
Open
8 of 19 tasks

One dev salary for open source dependencies #59

abitrolly opened this issue Jan 22, 2020 · 3 comments

Comments

@abitrolly
Copy link
Member

abitrolly commented Jan 22, 2020

Status

Updates

Intro

"Know Your Maintainers" as in KYC.

To avoid replacing them with bounty hunters, and erasing the spirit and culture of open collaboration. Think about how to preserve it.

"We follow mafia model" in Blender.

Open source culture is definitely about socializing, collaboration and all emotions that fall aside from those pillars.


Dedicate one full time salary to spread among open source project you use, and make it both a gameplay and a social process. They say that giving helps to avoid the burnout. But the link should be "healthy" too whatever that means. Common sense and fun may not work for everyone, because people don't have time to maintain the balance.

@abitrolly
Copy link
Member Author

/spent 30m

@abitrolly
Copy link
Member Author

Zip bomb CVE https://www.cvedetails.com/cve/CVE-2019-9674/ doesn't seem to be fixed in zipfile, because the fix is just a warning in documentation. This seems to be a blocker for merging pypi/warehouse#9972

/spend 30m

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

1 participant