Hacker News new | ask | show | jobs
by melodyogonna 17 days ago
People are offloading a lot of responsibilities to tools. If you pull a repository from Github without doing due diligence then you can't blame Cursor for getting compromised
2 comments

What’s due diligence? Reading all the code on GitHub?

That’s not a great interface, you probably want to clone it and open in your IDE so you can inspect the code properly...

So I clone a repo from Github and try to do due diligence before compiling and executing the code. I open the project with my IDE/text editor, and boom, I get pwned while doing the due diligence.

Unless it's Cursor's stance that people should use Emacs or whatever to check the repo before opening it, this is "you're holding it wrong" level stupid gaslighting.