It's not the maintenance of the projects the enterprises have to fund (though that is certainly welcome if the mantainers are willing) but the slow, painful work of vetting the code.
Google does that with Project Zero but few companies are wealthy enough to afford that. The way out is economic, not technical: insurance, and mutualizing the cost of security audits. I wrote up my ideas on the subject here:
Google does that with Project Zero but few companies are wealthy enough to afford that. The way out is economic, not technical: insurance, and mutualizing the cost of security audits. I wrote up my ideas on the subject here:
https://blog.majid.info/supply-chain-vetting/