How many people make sure all of the open source libraries they're using are bug free?
Anyone besides maybe NASA?
How many people make sure all of the open source libraries they're using are bug free?
Anyone besides maybe NASA?
Usually "fix the original library" wasn't as easy or immediate a fix as "hack around it" which is sad just re: the overall OSS ecosystem but still the person releasing a product's responsibility.
Unfortunately these sorts of bugs are wildly difficult to predict. Yet it's also a wildly common architecture. That's what's sad for all of us as engineers as a whole. But "caching credit card details and home addresses", for instance, is... particularly dicey. That's very sensitive, and you're tossing it into more DBs, without good access control restrictions?
It's a definition most laypeople use. It's developers who tend to use a very narrow definition.
I don't think it should be controversial to say that when you ship a product, you are responsible for how that product behaves.