if you address a security problem by simply making your package make a noise about it, so that absolutely everything downstream of your package gets people filing security reports on the public issue tracker: you have entered the cool zone
As someone who made their package (repository) make noise in response to a security issue (after also fixing it) today, I hope you're not mad at me lol
-
-
ah no the thing I'm talking about hasn't actually fixed the problem, they have simply made it their users' problem
-
So... A zero day
- 2 more replies
New conversation -
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.