@jrdepriest @phnt @sjvn @lanodan
I guess I went on a tangent without making it clear:
We all know the situation for small open-source projects with large corporate userbase is rough.
But at least it's not the FOSS projects that'll get pwned if they miss something - the large corpos will.
Then we started talking about how companies manage vulns, and whether they're doing it wrong.
1/