Closing the door to open source supply chain attacks

While the OSS community has made waves in the past with news of vulnerabilities, the wide use of the open source Java logging library Log4j meant that when that vulnerability was discovered, the floodgates opened. Almost overnight, open source went from a conversation reserved for the depths of Discord channels to something your mother might ask you about at the breakfast table.

This renewed attention highlighted the crucial interconnectedness between open source and closed source software components, giving rise to many misconceptions about the open source community.

Brian Fox

It’s not amateur hour here