The trend of anonymous bots sending mass contributions to Open Source repositories is guaranteed to lead to reputation farming followed by malicious contributions
Uncategorized
2
Posts
2
Posters
0
Views
-
The trend of anonymous bots sending mass contributions to Open Source repositories is guaranteed to lead to reputation farming followed by malicious contributions.
Either we'll move to a signed system to verify human contributors (GPG style) or the OSS ecosystem is cooked. -
The trend of anonymous bots sending mass contributions to Open Source repositories is guaranteed to lead to reputation farming followed by malicious contributions.
Either we'll move to a signed system to verify human contributors (GPG style) or the OSS ecosystem is cooked.@galdor i think we’ll see more communities practice formal participation requirements and ceremonies like Debian does for its maintainers.
-
R relay@relay.infosec.exchange shared this topic