5 ms·
If only the author had something to say about this problem... > The Pull Request Hack probably isn't suitable if you're running big projects. > And it is almo
by capableweb 3y ago
If only the author had something to say about this problem...
> The Pull Request Hack probably isn't suitable if you're running big projects.
> And it is almost certainly a stupid idea if you write code which is actively used by multiple downstream projects.
> And if your stuff has even the slightest chance of compromising security then you're better off sticking to trusted members.
- api 3y agoHe did, but the problem is that any package anyone uses for anything could compromise security. So what could you use this with? This sort of openness is an elegant weapon from a more civilized age. These days the net is like a zombie movie where if you leave a crack in the boards covering the windows the arms will reach in.
- imtringued 3y ago>So what could you use this with? Dead projects and projects that are so young they are more likely to be abandoned than finished. It doesn't work for projects that already have enough vetted members.
- capableweb 3y agoOk, lets consider the authors example of SuperTinyIcons (https://github.com/edent/SuperTinyIcons https://github.com/edent/SuperTinyIcons). What are some possible ways you could send a PR, gain commit rights and then use it for compromising security?
- flaviut 3y agoJavascript in the SVGs?
- mynameisvlad 3y agoFor what benefit? Infecting a few dozen probably fairly small sites while ruining the credibility of the contributor’s account? It’s extremely obvious and would pretty quickly get caught, even if the article author doesn’t keep too close a tab on the repo. Doesn’t seem worth it to me.