Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Should the better fix then to have been to revert the bad commit with the malicious commit message, rather than just deleting the dot (as was done)?



The better fix would be to move to proper dependency management and depend on a version range of a dependency instead of hoping you can do a better job of modelling the same with strings hardcoded into a CMakeLists.txt.




Consider applying for YC's Fall 2025 batch! Applications are open till Aug 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: