Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Kind of funny that stalebots are the new "won't fix" methodology to ignore security issues with plausible deniability.


Yeah I got a kick out of that. "We might have fixed your issue, if we didn't, open a new one because we took so long acknowledging this one".


Or 3 years later: can you verify this is still needed.

Why on earth did I spend time in creating a reproducible example?


People move on from issues. You apply a workaround, and the fix is no longer needed. Not every issue opened needs a fix. We all have limited resources, and prioritize the most important stuff to fix.


A stalebot marks it as inactive because you didn't take 2mins of your time to write a thank you, it's been fixed with commit xyz.

That's what the critique is about, lack of communication and lack of acknowledgement. Ghosting people when they took the time to file an issue/bug report, with providing a PoC and test case is just rude behavior.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: