Reply to post:

Four million outdated Log4j downloads were served from Apache Maven Central alone despite vuln publicity blitz

Anonymous Coward
Anonymous Coward

Unlikely to happen. They have hundreds of millions to pay lawyers with.

We can't find enough funding for all the OSS developers and projects to be paid enough to eat based on their labors.

And if you can "meaningfully sue" Microsoft over an OpenSSL vulnerability, you can bet they'll sue the OpenSSL developers and official project organization over it, regardless of the terms of the license. Big organizations don't just eat their court losses; they do their best to pass the buck down the feeding chain.

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon