If one of those base level things break, everyone who depend on it, will come together and replace/fix it instantly.
If one of those base level things break, everyone who depend on it, will come together and replace/fix it instantly.
Look at the recent security issue with lodash. lodash is a dependency of a huge number of javascript and node projects. For people who would say "don't use tons of random libraries", lodash was a great choice; it was almost the equivalent of a standard library for JS before ES6. Problem was, for all intents and purposes it was abandoned about a year ago. Couple months ago a security issue was reported, it wasn't fixed, and then 'npm audit' started failing builds with lodash as a dependency. It's like all of the sudden half the node ecosystem started failing.
The problem was not that the bug wasn't fixed, it's that the original author wasn't really involved any more, and it took a long while for other people with commit rights to figure out just how to get the build working. But the problem with any reasonably complex JS project is that there could easily be thousands of references to lodash. NPM doesn't make it easy to essentially say "I'm changing the namespace of lodash to mean this instead of that."
Dependencies are pretty unavoidable, and I think the software engineering community will actually start to get better at handling what happens when a widespread dependency needs to go on life support.
I don't see how this is causally related to that dependency being thanklessly maintained by a single person. Maybe I misunderstood what you are trying to say.
https://en.wikipedia.org/wiki/Heartbleed#Root_causes,_possib...
The industry's collective response to the crisis was the Core Infrastructure Initiative, a multimillion-dollar project announced by the Linux Foundation on April 24, 2014 to provide funds to critical elements of the global information infrastructure.[192] The initiative intends to allow lead developers to work full-time on their projects and to pay for security audits, hardware and software infrastructure, travel, and other expenses.[193] OpenSSL is a candidate to become the first recipient of the initiative's funding.[192]
After the discovery Google established Project Zero which is tasked with finding zero-day vulnerabilities to help secure the Web and society.[194]