Hacker News new | ask | show | jobs
by ffacu 1 hour ago
I think that this is becoming increasingly true only for large, well-known repositories, where the maintainers have a lot to lose by doing anything shady. I don't think the React team could get away with doing something like that, for example.