Comment Re: How is it different for closed source software (Score 1) 132
Except in the Equifax case the patch was to struts, so the issue is likely with the development team not the sys admins.
I'm on the process of documenting all opensource components being utilised in a software project I've inherited. One of the first things I did was to inventory all the components, and create an archive of all the packages required to build. However this is rarely done in many companies which was one of the points of the article.
The jibe about companies contributing is a bit of though. What is worrying about companies contributing, if the code is good that's a great thing.