CHAT / IITM ENTREPRENEURS
Amrit Vatsa
·
An enterprise customer wanted security-fix SLAs for every open-source library in an application. The August 2026 question was straightforward: how can the vendor guarantee a fix it may not control? Chainguard had been considered, but the requester said the SLA they encountered began only after an upstream fix became available.
Replies discussed responsibility for embedded components and commitments based on commercially reasonable remediation efforts, with timelines linked to severity. No provider emerged as a confirmed solution. The unresolved issue was the promise itself: responding to a vulnerability, mitigating its impact and delivering an upstream patch are different obligations.
Share this page link - iitmentrepreneurs.com with them.
Join the IITM entrepreneurs WA community
↗
No response within two days? Ping Amrit.