←back to thread

272 points twelvenmonkeys | 1 comments | | HN request time: 0.209s | source
Show context
RcouF1uZ4gsC ◴[] No.42139605[source]
Reading about Keycloak and how long it is taking to patch critical vulnerabilities, I wonder is CNCF becoming how Apache was - where abandoned open source software goes to die.
replies(4): >>42140022 #>>42140506 #>>42142224 #>>42142912 #
1. caniszczyk ◴[] No.42142912[source]
Last I checked, Keycloak has increased in activity since joining CNCF...

https://keycloak.devstats.cncf.io/d/1/activity-repository-gr...

CNCF has probably 20x the funding of the ASF and is a different organization that spends millions of dollars on security audits, events and more, you can read about it in our annual report: https://www.cncf.io/reports/cncf-annual-report-2023/

Also we actively remove/prune projects that aren't active... we will probably archive ~10 this year https://www.cncf.io/project-metrics/