• Sources: primary, discussion
  • Summary: The libexpat maintainer reports that the City of Munich is funding an open-source sabbatical of up to six months for work on the library. The post states that libexpat entered the arrangement carrying five known unfixed vulnerabilities.
  • Why it matters: Expat is one of the two C XML parsers under most of the software stack, and the five open vulnerabilities are what a decade of part-time maintenance on a critical library actually costs.
  • Follow-up: Track whether the five open vulnerabilities are closed inside the funded period.

send feedback on this story