5 ms·
I wondered for a moment if this could incentive developers to introduce bugs for their friends to "find," but then I remembered that hackers are already incenti
by rnprince 9y ago
I wondered for a moment if this could incentive developers to introduce bugs for their friends to "find," but then I remembered that hackers are already incentivized a lot more to sneak vulnerabilities into FOSS.
- ufmace 9y agoIMHO that would be a legitimate use of the award. If your review and merge process is bad enough that somebody can get malicious code into your releases, then that's a serious bug in your process, and whoever proved that it's there deserves the bounty just as much as someone who found an ordinary bug.