Maintainer Gary Gregory shares whether xz changes the way he might vet potential contributors

Поделиться
HTML-код
  • Опубликовано: 13 май 2024
  • Shortly after the xz utils backdoor hack was uncovered, Tidelift gathered together a group of open source maintainers across the Javascript, Java, and Python ecosystems to hear not only how the xz hack impacted their work (spoiler alert: this attack reverberated across ALL ecosystems, not just in the Linux OS!), but also how it made them feel.
    In this clip, we hear from Apache open source maintainer, Gary Gregory. Here he talks about the trouble of wanting to lower the bar of entry to let in more open source contributors, but how instances like the xz hack make that difficult.
    You can watch the entirety of the panel on-demand here: explore.tidelift.com/c/life-a...
    Learn more about xz: tidelift.com/resources/xz-bac...
    Transcript:
    One thing that's interesting to talk about, at least it's a dilemma we have on the Apache projects I work on, is we're trying to lower the bar for committer-ship. We're trying to grow communities, we're trying to manage communities. But when something like this happens, it really makes you hit the brakes.
  • НаукаНаука

Комментарии •