4 ms·
"Patches were sent to many projects, avoiding threats to public security for years to come." Are these pull requests that the project would still need to appro
by markcerqueira 10y ago
"Patches were sent to many projects, avoiding threats to public security for years to come."
Are these pull requests that the project would still need to approve/merge or were they just pushed in?
- edutechnion 10y agoThey were PRs that required approval and merge from the Github project maintainers. Here is a search to see some of their work: https://github.com/search?q=%22Upgrade+Apache+Commons+Collections%22&type=Issues&utf8=%E2%9C%93 https://github.com/search?q=%22Upgrade+Apache+Commons+Collec...
- deleted 10y ago[deleted]
- fudged71 10y agoIt's actually incredibly interesting to read how the developers individually responded to each of these PRs. It would have been great to see a count of how many PRs have been accepted.
- cpeterso 10y agoedutechnion's link says 1108 open PRs and 999 closed. Interesting that 2100 of the PRs are "Upgrade Apache Commons Collections to v3.2.2" and just 7 were "Upgrade Apache Commons Collections to v4.1".
- therealdrag0 10y agoProbably v3.2.2 was lower hanging fruit for most projects. Instead of having to make code changes.
- unityByFreedom 10y agoI'm sure they're requests.. They'd need to be deployed to production too. Still pretty awesome.
- hinkley 10y agoFor me, if a project had a bunch of open PRs for security issues, it would discourage me from using it for new work. It would also help break a tie in my head between keeping an old library and replacing it with something that has legs. So even if they don't get merged, they still serve a purpose, even if it's just for a few people who behave like I do.