• jackpotOP
    arrow-up
    5
    arrow-down
    2
    ·
    7 months ago
    link
    fedilink

    this isnt worth the time, it’s not a dependency of a huge piece of software

    • erAck
      arrow-up
      2
      arrow-down
      0
      ·
      7 months ago
      link
      fedilink

      Malicious account holders with a long term goal need to build reputation. It doesn’t matter much that such an app isn’t a dependency of other software.

      • steeznson
        arrow-up
        5
        arrow-down
        0
        ·
        7 months ago
        link
        fedilink

        Practically every FOSS project is actively looking for volunteers/maintainers all of the time. More contributors are not problematic.

        The xz problem was that they socially engineered the main dev into giving them the keys to the kingdom.

        • erAck
          arrow-up
          3
          arrow-down
          0
          ·
          7 months ago
          link
          fedilink

          Making one a maintainer (with merge and possibly even direct commit/push permissions) is handing them a key to the kingdom. Recruiting a maintainer out of the blue without them being already contributor and long term participant in the project is questionable.