Debian discusses vendoring—again
Debian discusses vendoring—again
Posted Jan 13, 2021 13:45 UTC (Wed) by dottedmag (subscriber, #18590)In reply to: Debian discusses vendoring—again by pizza
Parent article: Debian discusses vendoring—again
«This critical-and-not easy-to-replace library has N 0-day exploits with RCE per year. The choices are: 1) use it as is and sustain M break-ins, each conservatively estimated to cost $X / year in lost revenue, cleanups, damage control etc plus $Q for initial use of this library; 2) proactively monitor and patch vulnerabilities, estimated cost is $Y / year plus $Q for initial use of this library; 3) develop a replacement in-house, estimated cost is one-time $Z and $W / year maintenance»
Sure it takes some experience and data to start making these decisions, but once the data is there it becomes much easier to decide. Also over time (3) becomes cheaper as problems don't tend to be unique every time.