DEV Community

Discussion on: The human toll of log4j maintenance

Collapse
 
valeriavg profile image
Valeria

Open source means you can make modifications. Can't code - help with debugging. Can't debug - write documentation. I would understand if said Alibaba engineer would urge to REVIEW and MERGE his urgent fix. But no, someone else must find it, fix it and test it. Open source is not broken, some people are.

Collapse
 
yawaramin profile image
Yawar Amin

Yeah the thing is, if there had been no patch, we would all still be able to do the mitigation of deleting the JndiLookup.class file from production JARs to stop this attack. So what did all this pressure on the maintainers achieve? A bunch of people upgrading, and many complaining. 🤷‍♂️