3 ms·
Two thoughts: 1. It shows that tests are only as good as the thinking that goes into them, i.e., it's up the programmer to think through all the use cases, pos
by bk 17y ago
Two thoughts:
1. It shows that tests are only as good as the thinking that goes into them, i.e., it's up the programmer to think through all the use cases, possibility for breakage, and use the appropriate tools to try a wide range of inputs.
2. This lack of responsiveness to the vulnerability reminds me of the complaints Zed (Shaw) made about the Rails Core back when he announced he was leaving the Ruby community.
Preemptive disclaimer: These are not supposed to be snide remarks in any way, they're just two quick associations of a tired brain. So please no flames.
- tlrobinson 17y agoIndeed, back in January I came across a directory traversal vulnerability in Rack (http://blade.nagaokaut.ac.jp/cgi-bin/scat.rb/ruby/ruby-talk/324389 http://blade.nagaokaut.ac.jp/cgi-bin/scat.rb/ruby/ruby-talk/...). They had lots of unit tests, but none testing that particular case. Unit testing is certainly no magic bullet. On the other hand, the Rack team was incredibly responsive and put out an update within hours.
- ankhmoop 17y agoIt's also an interesting example of where an Option/Maybe monad would save you. Coupled with a type system, the issue would even be caught at compile time (or edit-time, in the case of a type-aware editor/IDE).