Pick your battles
Pick your battles
Posted Jun 4, 2026 13:28 UTC (Thu) by spacefrogg (subscriber, #119608)Parent article: Open-source security is not a solo activity
Whenever you are saying to yourself: I have to keep going or people are fucked., notice this: If you are burning out in the process, they're still fucked.
Or, as a russian saying goes: If you have professionals, you don't need heroes.
There will always be the imbalance of numbers of affected users and submitted bugs vs. time to fix things (not to mention develop things). The solution was never to work more, but to acknowledge past mistakes and pick a route forward that leads to less errors in the process. Thus, you have a chance of getting ahead of the bug wave. If your trouble stems from insecure libraries, drop features to be able to avoid those (and to migrate to more secure but less featureful libraries). What good is the argument that your users would lose functionality if it means they would have to pay with security in return?
That is professional attitude. It's never personal but the question: What is the best course forward for your undertaking? You are not your software.
Rule No 1 of user engagement: You don't have to. Learn to be selective in spending your attention.
