• Socsa@sh.itjust.works
    link
    fedilink
    arrow-up
    1
    ·
    9 months ago

    This has always been the case. Maybe I work in a unique field but we spend a lot of time duplicating functionality from open source and not linking to it directly for specifically this reason, at least in some cases. It’s a good compromise between rolling your own software and doing a formal security audit. Plus you develop institutional knowledge for that area.

    And yes, we always contribute code back where we can.