Slacker News Slacker News logo featuring a lazy sloth with a folded newspaper hat
  • top
  • new
  • show
  • ask
  • jobs
Library
← Back to context

Comment by orlp

10 hours ago

No it doesn't have security implications.

If you are insecure because someone has had one of their otherwise completely innocent PRs merged into your repo... you are insecure, period.

2 comments

orlp

Reply

lgrapenthin  10 hours ago

What you are describing is exactly a security implication.

stavros  10 hours ago

Security isn't a binary "secure/insecure". You can be more or less secure than something.

Slacker News

Product

  • API Reference
  • Hacker News RSS
  • Source on GitHub

Community

  • Support Ukraine
  • Equal Justice Initiative
  • GiveWell Charities