Hacker News new | ask | show | jobs
by Sacho 18 days ago
> It's like people telling you they will paint your house for free, even though the color of your house is perfectly fine

You are perfectly capable of saying "No, I like the color of my house already". Just pin rsync's version. This isn't some esoteric mechanism, it's standard practice.

If you were actually willing to charitably engage, tidge was working on fixing security bugs - your house had holes in it already! Your choice was to say I'm fine with the existing holes, or yeah please try to fix them. Unfortunately while fixing them he introduced some new ones, but hey, that's the nature of software development - sometimes you introduce new bugs when fixing old ones.

Again, this isn't some esoteric happenstance. It's so banal it must happen thousands of times per day across many other maintained projects.

1 comments

> Just pin rsync's version

Very bad advice these days.

There's a comment on the GitHub thread which also mentions pinning rsync version would be a bad idea. Many of the people affected by reversions are those with workflows vulnerable to the prior CVEs.