4 ms·
> As a maintainer of a security-oriented open source library, the paranoia of "is this person trying to help or to exploit?" That's an excellent mind set when
by barcist 3y ago
> As a maintainer of a security-oriented open source library, the paranoia of "is this person trying to help or to exploit?"
That's an excellent mind set when reviewing code, no matter security or not. But especially for security. How could this be wrong? What are the corner cases? How could anyboy break this? What do we need to test? That kind of scrutiny is crucial for keeping the quality of your code base high, no matter who posts the PR.
- saulpw 3y agoYes but that's a huge amount of work, and is not the 'fun' part of coding. It's one thing to have to spend those cycles looking for errors or incompetence, and hopefully helping the contributor improve their skills so they can in turn help the project more in the future. It's quite another to spend even more energy being suspicious and looking for subterfuge from someone that has been one of your most helpful contributors.