4 ms·
For those who can’t see the tweet: “Automattic has responsibly disclosed a vulnerability in ACF but breached the @Intigriti Code of Conduct by irresponsibly an
by demetris 2y ago
For those who can’t see the tweet:
“Automattic has responsibly disclosed a vulnerability in ACF but breached the @Intigriti Code of Conduct by irresponsibly announcing it publicly. I am going to work my damned hardest to ensure that the fix gets shipped to dotorg if it affects the free version of ACF.”
The tweet author is @johnbillion who, among other things, is a member of the WordPress core team and lead of the WordPress core security team.
Context for the “I am going to work my damned hardest...”: WP Engine, who own ACF (Advanced Custom Fields) are currently blocked from the official plugin repo so, I would imagine, they would not be able to push the update on their own.
- deleted 2y ago[deleted]
- demetris 2y agoUpdate: The Automattic tweet (the one announcing that Automattic “responsibly disclosed” a vulnerability to WP Engine) has now disappeared.
- ValentineC 2y ago> The tweet author is @johnbillion who, among other things, is a member of the WordPress core team and lead of the WordPress core security team. What's good about this scenario is that @johnbillion isn't employed by Automattic/Audrey, and wouldn't face financial consequences if he went against Matt's wishes.
- lolinder 2y agoUntil Matt decides to block any IP addresses he's using to access WordPress.org...
- yurishimo 2y agoJohn is one guy. A vpn will get around any blocks unless Matt nukes his WP.org account (extremely unlikely). The only reason WP Engine is blocked is due to corporate security rules and accounts all using a @wpengine email address