Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

As always, hundreds watch the open repositories, maybe one watches a company's build servers, if they're lucky. :-)


Hundreds watch, but how closely?

Plenty of stories of fairly major projects having evil commits snuck in that remain for months.


Name a few.



Only two of these were actual malicious commits. Two others were malware inserted into the repositories (if Twitter could be thought of as a meta-repo), which is bad but not on the same scale.


I wonder why nowhere talked about who Jia Tan was. In my understanding, a few people already talked to that person. Now, does Jia Tan really vanish?




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: