Comment Re:Useful for small projects (Score 1) 274
>Exactly the kind of projects that are likely not to release a new snap for every vulnerable library they are using.
You're conflating two separate problems. Just because a project doesn't have the resources to support all of the different packaging schemes doesn't mean it's not maintained. Rebuilding a snap or Docker container is a trivial exercise. As long as the project isn't abandoned it would take minimal effort to keep it up to date. If these small projects can get out to the wider world then they have a chance of developing a community of users. It's that community that will motivate the developers to maintain and update their work. Should a project be abandoned, any vulnerabilities exposed over time are isolated from the larger system. That isolation is one of the main selling points of these things so, if that fails, we've got bigger problems.