|
|
|
|
|
by pixl97
811 days ago
|
|
> Is there a photo of the person? Does that even matter these days? Especially if we're talking nation state level stuff convincing histories are not hard to create to deflect casual observers. >Be more paranoid. Most people in OSS just want to write some code to do something, not defend the world against evil. |
|
Yes, it would have prevented this attack. It isn’t totally sufficient but it’s quick and easy and would have prevented this attack.
“Most people don’t want …”
I get it. I think the issue is that pushing junk code from malicious contributors into your project causes more hassle in the long run. If you just want to code and make stuff work, you should probably be careful who you pull from. It’s not just for the benefit of others, it’s first and foremost to protect the code base and the time and sanity of other contributors.