Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Would you maybe consider making a distinction between security releases and regular run-of-the-mill update releases?

I see a real value in a service to let me know that there's a new version of one of the dozens of things I depend on. But like I said, it seems janky to rely on a for-pay service to find out about security vulnerabilities. So what about making the security notification free to all users, with the non-security update notifications a for-pay addon? Seems like a good way to strike a balance between developing a self-sustaining business and helping out a community.



Consider it? Definitely. But semver doesn't make a distinction, either, so it's a hard problem.

If you don't mind, we'd love to get your thoughts more via email--don't want to hijack this thread too much.




Consider applying for YC's Summer 2026 batch! Applications are open till May 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: