#HugOps to unpkg and to everyone in #OpenSource who goes through similar stresses — outages like this demonstrate modern digital infrastructure's fundamental fragility: https://www.theverge.com/2024/4/12/24128276/open-source-unpkg-cdn-down
Conversation
Notices
-
Embed this notice
Fastly Devs (devs@fastly.social)'s status on Saturday, 13-Apr-2024 03:17:30 JST Fastly Devs -
Embed this notice
Fastly Devs (devs@fastly.social)'s status on Saturday, 13-Apr-2024 03:18:08 JST Fastly Devs We need to lend a hand by giving back to the projects we use.
Ideas about giving back (and how Fastly does) are in this blog from @anildash https://www.fastly.com/blog/what-can-you-actually-do-to-reduce-the-threat-of-hacks-like-xz
In conversation permalink Attachments
-
Embed this notice
Fastly Devs (devs@fastly.social)'s status on Saturday, 13-Apr-2024 03:18:09 JST Fastly Devs Behind your browser, the #internet is people.
Repeatedly, we see what happens when the humanity and fatigue of people maintaining critical infrastructure are exploited.
Most recently, with the discovery of the #XZ hack.
In conversation permalink Anil Dash repeated this. -
Embed this notice
Anil Dash (anildash@me.dm)'s status on Tuesday, 16-Apr-2024 00:51:26 JST Anil Dash @joshhunt @devs I’m proposing direct structural support in terms of resources and infrastructure from major for-profit tech companies to support open source projects and maintainers. Absolutely the big players could evaluate open source build chains just as they do their own code.
In conversation permalink -
Embed this notice
joshhunt (joshhunt@hachyderm.io)'s status on Tuesday, 16-Apr-2024 00:51:27 JST joshhunt @devs @anildash sorry, but going to have to call BS on this one.
xz is like a seven times removed transitive dependency. What is the actual thing you’re proposing here’s in relation to xz. That everyone should “show up” and contribute back to the Debian and Redhat build processes?
In conversation permalink -
Embed this notice
Anil Dash (anildash@me.dm)'s status on Tuesday, 16-Apr-2024 00:52:19 JST Anil Dash @joshhunt @devs a maintainer having a community he can reach out to before he burns out would change things like this massively.
In conversation permalink
-
Embed this notice