To be honest I'm a FOSS advocate, but when I recommend software I absolutely mention that getting devs (capable of fixing that software) in a SLA for critical bugs is what the absolutely should do, or accept the security risk or operational risk of insecure software.
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
replies: