I like the idea behind @github's automated security fixes. But I wonder about it as a vector for phishing - seems like it'd be possible for a malicious party to send pull requests that look like security fixes, but create vulnerabilities. Any idea how this will be avoided?
-
-
Replying to @michael_nielsen @github
To those saying "check the code", I recommend having a look at the "underhanded c" contest entries


http://www.underhanded-c.org/_page_id_2.html 1 reply 0 retweets 4 likes
"Check the code" does not, of course, address the systemic issue. Though it will sometimes be actionable advice for professionals. But only sometimes, in part for the reason you describe.
9:26 AM - 3 Nov 2019
0 replies
0 retweets
2 likes
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.