Conan_Kudo,
@Conan_Kudo@fosstodon.org avatar

All this talk about over the weekend, I want to also point out that it's important to remember that the "software supply chain" largely does not exist in regards to open source, because most people have no real relationship other than parasitic consumption with the project.

@Di4na's great blog post on this topic explains it quite well: https://www.softwaremaxims.com/blog/not-a-supplier

wrog,
@wrog@mastodon.murkworks.net avatar

@Conan_Kudo @Di4na

"You are not buying from a supplier; you are a raccoon digging through dumpsters for free code."

matk,
@matk@mastodon.social avatar

@Conan_Kudo @Di4na That "I am not a supplier" blog post is spot on!

Conan_Kudo,
@Conan_Kudo@fosstodon.org avatar

@matk @Di4na I'm getting very tired of the "software supply chain" talk because it's all wrong. This blog post crystallizes my feelings about it very well.

It's also fundamentally why I have such a problem with OpenSSF, SLSA, and SPDX. They've started imposing and normalizing this psuedo-relationship around open source consumption that I believe fundamentally damages the commons and the community.

  • All
  • Subscribed
  • Moderated
  • Favorites
  • random
  • ethstaker
  • DreamBathrooms
  • InstantRegret
  • magazineikmin
  • ngwrru68w68
  • Durango
  • thenastyranch
  • Youngstown
  • rosin
  • slotface
  • tacticalgear
  • mdbf
  • kavyap
  • khanakhh
  • provamag3
  • osvaldo12
  • GTA5RPClips
  • cubers
  • cisconetworking
  • everett
  • tester
  • modclub
  • megavids
  • Leos
  • normalnudes
  • anitta
  • JUstTest
  • lostlight
  • All magazines