|
|
|
|
|
by kashyapc
812 days ago
|
|
While "open source" fundamentally doesn't work that way, the point here is about maintainers, not regular contributors. Identity of new maintainers must be vetted (via in-person meetups and whatever other mechanisms) by other "trusted" maintainers whose identities are "verified". I realize, it's a hard problem. (And, thanks for the link to the "Know, Prevent, Fix" post.) PS: FWIW, I "win my bread" by working for a company that "does" open source. Edit: Some projects I know use in-person GPG key signing, or maintainer summits (Linux kernel), etc. None of them are perfect, but raises the bar for motivated anonymous contributors with malicious intent, wanting to become maintainers. |
|