40
Points
12
Comments
dhruv3006
Author

Top Comments

rjzzleepJun 26
I'm extremely concerned about the state of Open Source. The gamification of the whole thing & devstats means that people that are good at gaming metrics are rising up the ranks and people that are genuine high quality contributors and pushed to the sidelines unless they have a very popular profile. Mass generated AI slop and AI content gives people massive devstats boosts.
Brian_K_WhiteJun 26
Anything they "maintainer of last resort" would actually be forks, or collectively a distribution. We already have hundreds of distributions acting as maintainer of last resort many times over, only with actual developers and not presuming to make themselves the new upstream for anyone else.
einpoklumJun 26
> We are joined by Amazon Web Services, Anthropic, Chainguard, Cisco, Citi, Endor Labs, Ericsson, Google, IBM, JPMorganChase, Microsoft and GitHub, NVIDIA, OpenAI, RapidFort, Red Hat, Rust Foundation, Sonatype, Vodafone, and Zscaler

Many of the names on the list makes the initiative rather suspect. Companies who do a lot to undermine free and open-source software, who hide critical software behind their walls, preventing both its scrutiny and its adaptation and improvement, and two of the LLM giants - they'll "defend open source"? I don't know about that.

> Akrites gives critical infrastructure stakeholders a confidential, structured place to coordinate vulnerability discovery, remediation, and disclosure across the open source projects they depend on

So, a bunch of large corporations - some of who are known to be in bed with the US government - will share vulnerabilities among themselves, out of the public eye? Fishy.

charcircuitJun 26
Why only a focus on Open Source? I feel like vulnerabilities in closed source products like Microsoft Office, Microsoft Windows, and Google Chrome to name a few can be just as essentially and foundational as other open source software for many businesses.
dmitrygrJun 26
> Additionally, when a critical package has no one maintaining it, Akrites will stand as the maintainer of last resort so a fix can still reach everyone in a timely fashion.

Ambitious and interesting. I wonder how long this will last and on whose dime and time? Akrites employs no engineers, so who will make the fixes and who'll pay them?

Visit the Original Link

Read the full content on akrites.org

Source
akrites.org
Author
dhruv3006
Posted
June 26, 2026 at 05:40 AM


More Top Stories

om.co Jun 25
Om Malik has died
83893 commentsby minimaxir
Details
scrollprize.org Jun 25
An entire Herculaneum scroll has been read for the first time
1256261 commentsby verditelabs
Details
graphicore.github.io Jun 26
Libre Barcode Project
1199 commentsby luu
Details
jeffgeerling.com Jun 26
Framework's 10G Ethernet module exposes USB-C's complexity
14474 commentsby Alupis
Details
fernandoi.cl Jun 26
What happened after 2k people tried to hack my AI assistant
12448 commentsby cuchoi
Details
expression.fire.org Jun 25
The 'papers, please' era of the internet will decimate your privacy
662305 commentsby bilsbie
Details
👋 Need help with code?