Comment on FFmpeg to Google: Fund Us or Stop Sending Bugs

<- View Parent
nandeEbisu@lemmy.world ⁨1⁩ ⁨week⁩ ago

Security vulnerabilities are different, especially when they also put a 90 day disclosure period in it which is more severe for a security exploit.

That disclosure bit, not in the article, is really what tipped this all over the edge. If it was just hey, here’s a bug then its really just flooding the backlog for the maintainers who need to triage that. Disclosures are often used so people are aware that they’re using libraries that the maintainer has refused to patch, but in this case its really just holding the maintainers hostage so they end up wasting their time going through irrelevant issues.

Ideally, they would either use their supposedly capable and powerful AI code gen to just make a fix and send over a patch, or at least use LLMs on their own end to triage the issues and only send over the most sever X periodically.

source
Sort:hotnewtop