Sat Aug 31, 2019

There's no problem with nudging, but being nasty about isn't appropriate.  I'll confess that I aimed a comment at you that should have been pointed at the OP.  Sorry about that.

I've been maintaining clamav packages for over a decade through three different companies owning the project and overall I think the Talos/Cisco people are doing a pretty good job.

They are generally responsive.

Also, in terms of being proud of their code, you should compare the code quality when Sourcefire bought clamav to the current code base.  It's night and day different.  Also the rate of security bugs seems to have dropped off (not to mention we actually get bugfix releases now).

So yeah, they could do better, but looking back, I think they're doing pretty good.

In this case, the 'worn cliche' is important, because unlike lots of other FOSS projects, this one doesn't have non-proprietary alternatives, so it'd be pretty awful if the community were to convince Talos that publishing it was more trouble than it was worth.

Scott K

