4 ms·
This doesnt prevent trusted people from doing stupid things like this https://news.ycombinator.com/item?id=18534392 https://news.ycombinator.com/item?id=1853439
by fearai 8y ago
This doesnt prevent trusted people from doing stupid things like this https://news.ycombinator.com/item?id=18534392 https://news.ycombinator.com/item?id=18534392
We need to trust the code not the programmer
- habitue 8y agoIt doesn't prevent anyone from doing anything. It increases the likelihood that if someone does something like that, that it will be detected. Crev seems interesting because it not only has the web-of-trust mechanic going on, but also because it creates an incentive to actually do code reviews on existing code. There's now a whole open frontier of "code that hasn't been reviewed in crev", which people might feel compelled to jump on. "Hey, my favorite crate isn't reviewed, I'll can do it". etc.
- dbaupp 8y agoI think crev is actually explicitly trying to establish trust for the code, not the programmer. > It protects against compromised dev accounts, intentional malicious code, typesquating, compromised package registries, or just plain poor quality.
- sgeisler 8y agoIt doesn't, but now both the original author and some number of independent reviewers have to do stupid things in order to cause harm. That's an improvement to the current situation where you mainly trust the author in most cases. A review is only valid for a specific version/hash of a set of files, so if you only upgrade your dependencies once they have enough trusted reviews you should be safe.