A satirical fictional supplier security questionnaire imagines an absurd corporate risk-assessment form sent to an open source maintainer, based on the package manifest's contact address. It parodies real third-party risk practices by escalating each section into absurdity: demanding SOC 2 certificates and background checks from unpaid solo maintainers, life insurance policies on key contributors, residential addresses for legal service, AI training data consent, and 180 days' notice before any licence change, all while noting that non-response is treated as a failing score.

8m read timeFrom nesbitt.io
Post cover image
Table of contents
Section 1: General #Section 2: Security #Section 3: Secure Development #Section 4: Business Continuity & Key-Person Risk #Section 5: Artificial Intelligence #Section 6: Legal & Export #Section 7: Financial #Declaration #
149 Impressions