109
submitted 3 months ago by jackpot@lemmy.ml to c/opensource@lemmy.ml
top 12 comments
sorted by: hot top controversial new old
[-] uninvitedguest@lemmy.ca 8 points 3 months ago

I'm glad they're looking. I quite like Quillpad, it works nicely with my simple set up.

[-] erAck@discuss.tchncs.de 3 points 3 months ago

This is how one attracts and invites Jia Tan and Hans Jansen types.

[-] jackpot@lemmy.ml 3 points 3 months ago

this isnt worth the time, it's not a dependency of a huge piece of software

[-] erAck@discuss.tchncs.de 2 points 3 months ago

Malicious account holders with a long term goal need to build reputation. It doesn't matter much that such an app isn't a dependency of other software.

[-] steeznson@lemmy.world 5 points 3 months ago

Practically every FOSS project is actively looking for volunteers/maintainers all of the time. More contributors are not problematic.

The xz problem was that they socially engineered the main dev into giving them the keys to the kingdom.

[-] erAck@discuss.tchncs.de 3 points 3 months ago

Making one a maintainer (with merge and possibly even direct commit/push permissions) is handing them a key to the kingdom. Recruiting a maintainer out of the blue without them being already contributor and long term participant in the project is questionable.

[-] steeznson@lemmy.world 1 points 3 months ago

I believe that the bad actor was a contributor for several years before becoming a maintainer

[-] erAck@discuss.tchncs.de 2 points 3 months ago

Apparently not, you can check commits in https://git.tukaani.org/?p=xz.git;a=summary the first authored commit was 2022-01-28, then long time nothing until 2022-06-10, the first merge as committer was 2022-12-16.

[-] steeznson@lemmy.world 1 points 3 months ago

Interesting! I'd not realised it was so recent

[-] Vigilante@lemmy.today 2 points 3 months ago

Is Hans you are refering to the guy on fdroid or someone else ?

[-] erAck@discuss.tchncs.de 2 points 3 months ago

Of the xz/liblzma backdoor incident.

[-] Vigilante@lemmy.today 1 points 3 months ago

Oh i only remembered jia tan so thought it was fdroid one.

this post was submitted on 31 Mar 2024
109 points (97.4% liked)

Open Source

29089 readers
997 users here now

All about open source! Feel free to ask questions, and share news, and interesting stuff!

Useful Links

Rules

Related Communities

Community icon from opensource.org, but we are not affiliated with them.

founded 4 years ago
MODERATORS