fosstodon.org is one of the many independent Mastodon servers you can use to participate in the fediverse.
Fosstodon is an invite only Mastodon instance that is open to those who are interested in technology; particularly free & open source software. If you wish to join, contact us for an invite.

Administered by:

Server stats:

10K
active users

Don McCurdy

I've been expecting something like this since the XZ hack, but still ... frustrated/annoyed/sad to see Microsoft and 13 (!) partners jointly announcing that their answer is to “educate” open source maintainers.

It's nice that they're compensating maintainers for the time spent on that training, but ... compliance with corporate security policies is still a whole lot of ongoing, unpaid work after that? Sigh.

github.blog/news-insights/comp

The GitHub Blog · Announcing GitHub Secure Open Source Fund: Help secure the open source ecosystem for everyoneApplications for the new GitHub Secure Open Source Fund are now open! Applications will be reviewed on a rolling basis until they close on January 7 at 11:59 pm PT. Programming and funding will begin in early 2025.

If your company relies on open source software and wants to support maintainers, please don't do it this way.

Better models include:

- Tidelift
- Open Source Pledge
- Sovereign Tech Fund Fellowship for Maintainers

@donmccurdy omg, yes, this.
XZ didn't happen because of a maintainer not having the right training or education, it happened because the maintainer didn't have the bandwidth to support the project. As much is obvious from the postmortem.

@donmccurdy Man, I’d have expected better from a trillion-dollar surveillance capitalist that trains its AI on your code.

@donmccurdy

> Maintainers will get hands-on learning of security principles, tools like GitHub Copilot and Copilot Autofix to help improve security posture, reduce security debt, and improve confidence of downstream users.

🫠

@donmccurdy Copilot training and "3-week program consisting of a 5-10 hour commitment each week" is exactly what community needs to fix cases like XZ with busy maintainer bullied by bad actors.

Microsoft, are you ill? Are you just joking here around or just want to sell your crapy Copilot? This is just an insult to Open Source maintainers.

@martin.social You do not see how inappropriate this is?
martin.socialMartin WoodwardMartin Woodward's Social Links