We all depend on open source. We will defend it together(akrites.org)
452 points by dhruv3006 1 day ago | 221 comments
tl;dr: A consortium of major tech, finance, and telecom companies—including AWS, Google, Microsoft, Anthropic, OpenAI, JPMorganChase, and Red Hat—launched Akrites, a coordinated initiative to find, patch, and responsibly disclose vulnerabilities in critical open source software. The effort responds to AI dramatically accelerating vulnerability discovery (minutes instead of weeks), overwhelming maintainers with duplicate reports and outpacing patch cycles. Akrites promises confidential, upstream-focused remediation through a shared Security Incident Response Team, and will act as "maintainer of last resort" for unmaintained critical packages.
HN Discussion:
  • Skepticism toward the corporate players involved, questioning their credibility and motives
  • This initiative promotes centralization and corporate control, undermining open source ethics
  • Real support means funding maintainers and hardware, not corporate statements
  • Cynical dismissal as empty corporate posturing that won't translate to action
  • ~Open source is already largely corporate-driven with little real community involvement