Hacker News new | ask | show | jobs
by dblohm7 1458 days ago
One aspect of these forks that never gets mentioned:

It's great when a fork ensures that it is always taking security patches from upstream. But what about the code unique to the fork? Is that new code following the same security practices as the upstream project? Are enough eyeballs poking at it to get it the same security scrutiny as upstream?