As an OSS maintainer, I'd be happy to receive a living wage for my work. But I wouldn't want all the negative externalities that come when money is introduced to the ecosystem. Nor would I want a change in expectations for what I deliver.
> But I wouldn't want all the negative externalities that come when money is introduced...
Even before you get to the broader ecosystem, I wouldn't want daily standups, weekly 1:1s, on-call rotations, weekly business reviews, monthly business reviews, quarterly reports, "emergency" all-hands meetings, mandatory compliance training, constant IT churn, zero-based budgeting, fighting for headcount, constant interviewing, fighting for management buy-in (and against active attempts at management sabotage), managing up, managing down, peer reviews, performance reviews, promotion boards...
I also don't want to spend six months negotiating a contract, sign an NDA, disclose tax records to prove I have other clients, maintain liability insurance, and etc., for one week's worth of work, during which I must track every fraction of an hour and itemize everything I do, followed by two months of dealing with some archaic billing system and another three months wondering if accounts payable will ever actually send the money.
I just want to apply my decades of domain experience in a community of deserved trust and feel like someone actually gives a damn.
The quilt patch series comes from the time when I was basing my work on the Debian version, it was easier for me to follow upstream than rebasing branches.
Most patches are now merged into master, only some unfinished work is still in that series. I should update the docs.
That is an interesting issue (detect differing resource loading based on the document jump) that affects regular fragments as well, but the idea is that particularly sensitive pages would know not to have fragment targets in the page but couldn't prevent text fragments. The solution given (deterministic loading independent of jump target) seems like a good idea to work towards but meanwhile I agree it is a minor concern and pages should not avoid reasonable navigation due to this issue. Particularly since there are often other ways of getting the same information with the same type of network analysis.
> An attacker can use this vulnerability to obtain root on OpenBSD 7.4 and 7.5.
Ouch! And this all due to unsanitized user input. I really would have expected better from OpenBSD in 2023. I mean I would expect better from everyone but especially from OpenBSD.
Thank you for that feedback, I removed a couple important pieces from the repo readme that I think would answer your questions around usage. I'll add them into the main site.
As a maintainer, the biggest major issue is that I don't want their money.