If it has value to a larger community, the larger community should be able to fund its operation.
Up until very recently it seemed perfectly reasonable to fund this sort of thing with taxes, because it benefits everyone even if they’re not directly using the database. An open source developer probably isn’t going to pay to look up vulnerabilities in the open source dependencies they use, so the database being free makes software more secure on average.
What is wrong with having free public services? If someone is abusing it, block them, or charge fees like a library.
JasonDJ@lemmy.zip 3 days ago
Idk about Tenable specifically, but a lot of the major security vendors have their own pool of security researchers who very frequently contribute to CVE. Mostly from finding vulns in their own product, but a lot of those vulns are due to upstream libraries.