Nick Wellnhofer, the maintainer of the libxml2 library, has announced that he will now treat vulnerabilities as regular bugs. Reports of vulnerabilities will no longer be prioritized and will be fixed as time allows. Information about the nature of vulnerabilities will be made publicly available immediately, without waiting for a patch to be created and distributed in distributions and operating systems. Nick has also relinquished his role as the maintainer of the libxslt library and expressed doubts about finding someone willing to take on its support.
A note has been added to the libxml2 project description indicating that the library is written by enthusiasts, maintained by a single volunteer, poorly tested, written in a language that does not handle memory safely, contains numerous vulnerabilities, and is not recommended for processing untrusted data. Reports of security issues are to be submitted through the standard public issue tracking system and will be handled like any other bugs. Vulnerabilities will no longer be hidden behind closed doors, and all information about security issues will be made public immediately, regardless of non-disclosure requirements until a specified date and without postponing information disclosure until release.
It is expected that shifting to treating vulnerabilities as regular bugs will allow Nick to focus on his core work on libxml2 without being interrupted by unexpected tasks. As it stands, Nick has to spend several hours a week dealing with vulnerability reports and preparing patches, which creates a significant workload considering that the maintenance is done out of pure enthusiasm.
It is noted that concealing information about vulnerabilities until updates are published and metrics like the OpenSSF Scorecard are merely attempts by large companies to invoke a sense of guilt in maintainers and force them to work for free. Imposing additional demands on volunteer maintainers, who work without compensation, is described as a harmful practice.
According to Nick, the libxml2 library does not meet the quality standards suitable for use in browsers and operating systems. Nevertheless, major companies like Apple, Google, and Microsoft have started using libxml2 in their operating systems and products. Such actions are deemed irresponsible, and the ongoing work is seen as attempts to eliminate symptoms rather than address the root causes of the problems. In Nick's opinion, it would be better for the mentioned companies to stop using libxml2.
Source: opennet.ru
