by love2read on 5/30/23, 3:55 AM with 159 comments
by faitswulff on 5/30/23, 1:20 PM
This reddit comment covers it pretty well: https://reddit.com/r/ublock/comments/32mos6/_/cte0a3n/?conte...
by bbbobbb on 5/30/23, 6:09 AM
> The PR was bigger than what I felt I could sensibly review and, in honesty, my desire to go through the hours of work I could tell this would take for a project I no longer used was not stellar.
The PR: https://github.com/django-money/django-money/pull/2/files?di...
Do others share this sentiment?
This doesn't look like a particularly big PR to me, judging solely by the amount of code changed and the nature of the changes at first glance.
Are most of your PRs at work tiny, couple lines of code at most? Am I sloppy for not even consider reviewing this for "hours"? Are all code bases I have worked on sloppy because features often require changing more code than this?
by sedatk on 5/30/23, 5:37 AM
by psacawa on 5/30/23, 5:07 AM
by CapsAdmin on 5/30/23, 7:09 AM
My criteria is usually just a willingness to improve the situation. I can observe this over time via pull requests, forks and general community participation.
I'm very reluctant to give access to someone asking for it. I firmly believe this is something that should be given and not to be expected.
by kemenaran on 5/30/23, 5:47 AM
I did wonders to foster a community of contributors, and get more patches coming. The CI ensures nothing breaks, and there never was any trust incident.
by kqr on 5/30/23, 5:58 AM
(The notable exception are people who specifically seek power. Somehow they seem to be the least responsible with it.)
by verhovsky on 5/30/23, 11:20 AM
by teekert on 5/30/23, 11:28 AM
[0] https://en.wikipedia.org/wiki/Humankind:_A_Hopeful_History
by dang on 5/30/23, 4:50 AM
I gave commit rights to someone I didn't know - https://news.ycombinator.com/item?id=12522654 - Sept 2016 (100 comments)
by boxed on 5/30/23, 11:08 AM
- instar. I had two guys basically rewrite the entire thing and make it WAY better. I had a good vision for the API but my implementation was pretty bad.
- mutmut. I would never have gotten windows support going without help. (Although I am thinking of abandoning windows anyway soon...)
- iommi. This project is much more complex and has a certain philosophy, but we gave commit access to one developer pretty fast as it was super obvious from the first PR what kind of deep thinking he did.
All in all, great success.
by jrochkind1 on 5/30/23, 1:31 PM
In 2016 I think it wasn't yet/wasn't recognized.
I am very sympathetic to the suggestion in OP prior to recognizing that there may be people actually actively trying to abuse your trust to intentionally inject malware.
by londons_explore on 5/30/23, 7:29 AM
And if it did, sorting out the mess and reverting a malicious commit wouldn't be the end of the world.
by griffinmb on 5/30/23, 5:27 AM
by VBprogrammer on 5/30/23, 12:23 PM
by BehindTheMath on 5/30/23, 5:37 AM
https://twitter.com/MoOx/status/955903710617620482?t=BvPIWQ-...
by mizzao on 5/30/23, 5:14 PM
by rorykirchner on 5/30/23, 10:46 AM
by ptx on 5/30/23, 3:59 PM
Maybe we need a way to declare in the package and repository metadata that the maintainer considers it world-writable and it shouldn't be installed or updated without very carefully reviewing the code of every new version.
by ranting-moth on 5/30/23, 6:12 AM
I'm glad it worked for him, but just want to remind people of survivorship bias: https://xkcd.com/1827/
by riffraff on 5/30/23, 5:53 AM
I am not sure you'd want this for everything, but for quick paced experimental work it seemed to be incredibly effective.
by amelius on 5/30/23, 10:58 AM
by sergioisidoro on 5/30/23, 8:35 AM
So I really appreciate projects like JazzBand [1], that gather likeminded contributors and individuals that want to harbour open source repos around an ecosystem (Eg. Django), while giving some assurance on governance. If JazzBand would be around in 2016, django money would be a very good candidate to be harboured by the org.
On a meta level, I really would love that more OSS devs would user orgs, rather than personal accounts and repos, so that they can grow their projects with a team, rather than becoming the bottleneck and gatekeeper for development.
[1]- https://jazzband.co/
by klntsky on 5/30/23, 9:32 AM
by langsoul-com on 5/30/23, 6:10 AM
by cat_plus_plus on 5/30/23, 4:40 PM
by IYasha on 5/30/23, 5:59 PM
by wly_cdgr on 5/30/23, 6:38 AM
by rvba on 5/30/23, 3:40 PM