Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

It's not so much about who made what. It's about knowing what versions where used and which CVEs are attached.


CVEs are very important, of course, especially nowadays, but...

Many licenses, such as the MIT license, are very open. All you have to do is include the license text and the names of the software creators, because they want attribution. In other words, it really is about who made what, even with some of the most open licenses.

Licenses matter, a lot. After all, some licenses are share-alike/viral: if you "use" code with such a license, your code might inherit that license. (I put "use" in scare quotes because this is where the lawyers get involved. It depends how exactly you use the code.)




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: